3 ms·
Based on our history, Thomas, I believe this represents the kind of behavior that reduces the quality of debate on-line or off. To argue that $20 million is a
by thinkcomp 15y ago
Based on our history, Thomas, I believe this represents the kind of behavior that reduces the quality of debate on-line or off.
To argue that $20 million is a small amount relative to Visa's total transaction volume, and consequently too little (!) as an arbitrary barrier to entry for startup companies, is puzzling. I don't know of any license fees that are calculated based on what the largest market participant could afford to pay as a percentage of revenue.
- pg 15y agoPlease stop making this personal.
- tptacek 15y agoI don't understand this argument. We're commenting on a thread where lax regulation of a payment processor appears to have resulting in a breach that disclosed 10 million credit cards. I'm not sure how that story admits to a pivot about over-regulation of payment processing. Different people have different value schemes. For instance, personal liberty is far more important to me than airport security. But in my value scheme, which I think is probably widely shared, the safety of consumer financial data is more important than whether it costs $500,000 or $20,000,000 to operate a payment processor at scale. (I don't, for what it's worth, really believe that all new market entrants to payment processing have to pay 8 figure sums to launch). Also: in case anyone's wondering, I've never worked for or with Greenspan, or even met him in person. I assume the history he's referring to is on HN.
- thinkcomp 15y agoEveryone is entitled to their value scheme. Unfortunately, the regulatory requirements here have nothing to do with data security; they are imposed to nominally insure the security of funds. I think it is possible that where you see a pure regulatory failure, I see a technological failure that is being exacerbated by regulation.
- tptacek 15y agoI'd be interested in hearing how regulation is impeding data security. From my vantage point, we have the opposite problem; for instance, credit card processing as an industry has opted for self-regulation, and the resulting PCI standard is ineffective and provides cover for a cottage industry of superficial and inadequate testing. Just to set the stage here, though: you're someone who wants it to be cheaper and easier to start payment processors, and I'm someone who gets paid to find vulnerabilities in complicated applications. Before you write a lot of paragraphs, know that I'm going to drive into specifics, and that I'm decently familiar with data security issues at transaction processors.
- deleted 15y ago[deleted]