Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you forget that the payment systems are designed to tolerate failure and still work. For instance, you may be able to use your credit card at a store even if their phone line or internet connection breaks down.

So it's possible to scam the system, but the banks probably figure that they would lose more money in lost transaction fees by implementing a 100% secure, ACID-compliant 2-phase commit payment protocol, than by keeping the current best effort authorization + batch processing system in place.



>For instance, you may be able to use your credit card at a store even if their phone line or internet connection breaks down.

Actually, no. No approval code (which is obtained from the network), there is no purchase.


Actually, yes.

The transaction is stored, and fowarded later. It's a variant on the Card Number + Impression that used to be common place 20 years ago, and Card Number + CCV that is still common place in locations with intermittent/no connectivity.

The prime example of this being done electronically is on planes, they have been accepting credit cards a large number of years before connectivity was possible.


Any merchant that would release goods or services without an approval code exposes themselves to a loss. Of course it's possible for a merchant to store the card information and post it later, but it's far from a good idea.


The ATMs can be configured for both cases. If the ATM is in a well-trafficked area, with a (normally!) low degree of crime, the bank may set it for high-availability vs. hard-transactional to avoid inconveniencing their customers.

Don't forget that the banks make their money from ATMs off the transaction fees, so if a foreign customer's bank is unreachable at that moment, they may still take a chance and give them their money (plus charge them the $4).


Well, I'm not talking about the merchant writing down the credit card number. This happens through the terminal.

Do you work in banking and know about this, or are you making assumptions about how payment terminals work?


Most larger chains have a limit up to which they'll accept that risk. For obvious reasons what those limits actually are is very closely held information.


Well, at least where I live I've encountered this a few times. The payment terminal shows "connecting" for some time, and eventually prints out an extra receipt that I have to sign (whereas usually entering the PIN is sufficient). Can you tell me what goes on in that case?


Sounds like debit failing and falling back to a CC transaction, but I am not a payments expert.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: