3 ms·
The Senate Banking Committee held hearings yesterday on mobile payments. Unfortunately they're totally unaware that it's possible to initiate a mobile financial
by thinkcomp 15y ago
The Senate Banking Committee held hearings yesterday on mobile payments. Unfortunately they're totally unaware that it's possible to initiate a mobile financial transaction that doesn't make use of a credit card or cell phone carrier's billing system, and that it's basically impossible for startups to compete with the card networks (possibly by offering new anti-fraud technology, for example) when the cost of regulatory compliance nationwide is $20 million. So we'll probably keep on seeing a lot of stories like this one...
- tptacek 15y agoThat suggests a regulatory cost of under 0.0001% of the dollar volume of a large credit card processor. Given the high cost of securing transaction processors and the regularity with which these companies --- all of whom pay millions to staff security teams --- manage to cough up customer data to transactions, I'd suggest the problem is in the other direction: it may not cost enough to be a transaction processor.
- thinkcomp 15y agoBased on our history, Thomas, I believe this represents the kind of behavior that reduces the quality of debate on-line or off. To argue that $20 million is a small amount relative to Visa's total transaction volume, and consequently too little (!) as an arbitrary barrier to entry for startup companies, is puzzling. I don't know of any license fees that are calculated based on what the largest market participant could afford to pay as a percentage of revenue.
- pg 15y agoPlease stop making this personal.
- tptacek 15y agoI don't understand this argument. We're commenting on a thread where lax regulation of a payment processor appears to have resulting in a breach that disclosed 10 million credit cards. I'm not sure how that story admits to a pivot about over-regulation of payment processing. Different people have different value schemes. For instance, personal liberty is far more important to me than airport security. But in my value scheme, which I think is probably widely shared, the safety of consumer financial data is more important than whether it costs $500,000 or $20,000,000 to operate a payment processor at scale. (I don't, for what it's worth, really believe that all new market entrants to payment processing have to pay 8 figure sums to launch). Also: in case anyone's wondering, I've never worked for or with Greenspan, or even met him in person. I assume the history he's referring to is on HN.
- thinkcomp 15y agoEveryone is entitled to their value scheme. Unfortunately, the regulatory requirements here have nothing to do with data security; they are imposed to nominally insure the security of funds. I think it is possible that where you see a pure regulatory failure, I see a technological failure that is being exacerbated by regulation.
- tptacek 15y agoI'd be interested in hearing how regulation is impeding data security. From my vantage point, we have the opposite problem; for instance, credit card processing as an industry has opted for self-regulation, and the resulting PCI standard is ineffective and provides cover for a cottage industry of superficial and inadequate testing. Just to set the stage here, though: you're someone who wants it to be cheaper and easier to start payment processors, and I'm someone who gets paid to find vulnerabilities in complicated applications. Before you write a lot of paragraphs, know that I'm going to drive into specifics, and that I'm decently familiar with data security issues at transaction processors.
- deleted 15y ago[deleted]
- kylebrown 15y agoIt seems to me that the cost of regulatory/license fees could act as a barrier to competiton, permitting the incumbent to coast while maintaining its monopoly. The cost of fees/licenses is just a tax, which is less money a company or start-up could spend on meeting regulations (eg PCI-DSS) or other things that would actually protect customer data. Why is chip-and-pin (which from what I understand would render ineffective this type of breach - track 1 + 2 card data) already common in Europe, but not the U.S.? [sincere question]
- tptacek 15y agoThe regulation and fee structure we're talking about is chump change compared to the transaction volume of even some of the newer payment processors. Meanwhile: PCI-DSS is an industry self-regulation scheme that I'd argue is an example of a failed security standard; to support that argument, I'd just go down the list of "PCI Certified" companies who had terrible breaches subsequent to their certification. (It's funny that this comment was downmodded to grey on a thread about a breach at a giant payment processor who had one of the industry's best known firms as their QSA).
- kylebrown 15y agoDwolla, to take a popular payments company as an example, processes an average $1m/day with an average transaction of $500 at a fee of $0.25. An annual revenue of $182,500 hasn't prevented them from (so far) securely and compliantly processing transactions (arguably). And yet companies that charge and spend far more (ostensibly on security) are the ones making news for their data breaches. So why suppose that an arbitrary regulatory cost, whether a nominal fee or a more productive expense, would enhance security?
- tptacek 15y agoWhat this argument does is look at a profound failure of regulation (payment processors are overseen by PCI QSAs, who in this case signed off on a site that experienced a monumental breach), and then points to a site at random that has not yet experienced a breach to argue that less regulation is needed.
- runako 15y agoIn the context of finance and banking, $20 million is not at all a large number. Even in tech, companies don't have trouble raising sums much larger than this for even relatively unambitious goals. The money is there for teams tackling big financial problems: http://www.bloomberg.com/news/2012-02-09/stripe-said-to-get-funding-valuing-online-payment-startup-at-100-million.html http://www.bloomberg.com/news/2012-02-09/stripe-said-to-get-.... If you need $20mm to start, you're not likely to bootstrap your way into building a nationwide payment network that you run on rented VPS, but I'd argue that might not be such a bad thing.