Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Cloudflare Quick Tunnels(cloudflare.com ↗)
    163comments
  2. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    20comments
  3. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    38comments
  4. North Korean nuclear test sets off years of earthquakes(science.org ↗)
    101comments
  5. US Military had close call after using AI for hallucinated intelligence report(cnn.com ↗)
    59comments
  6. OpenJev(openjev.com ↗)
    225comments
  7. C++26: Trivial infinite loops are no longer undefined behaviour(sandordargo.com ↗)
    128comments
  8. Systemd is a suite of basic building blocks(systemd.io ↗)
    13comments
  9. Show HN: Ax-check.com – Can agents use your product?(ax-check.com ↗)
    10comments
  10. I vibed a proof of Conway's conjecture(overreacted.io ↗)
    129comments
  11. A heap overflow and SSO misconfiguration to compromise OpenAI internal repos(hacktron.ai ↗)
    189comments
  12. Mathematicians Build Long-Awaited Graph Sandwich(quantamagazine.org ↗)
    10comments
  13. I don't like passkeys(hawksley.dev ↗)
    602comments
  14. Jemalloc 5.4.0(github.com/jemalloc ↗)
    77comments
  15. Border agents can search cellphones without a warrant or reasonable suspicion(lawandcrime.com ↗)
    11comments
  16. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss
  17. NATS publishes preliminary report on technical incident of 8 September(nats.aero ↗)
    24comments
  18. The scourge of x86 emulation(fex-emu.com ↗)
    71comments
  19. Show HN: Scry, programmable internet search w/ congestion pricing(scry.io ↗)
    8comments
  20. The Shadows Lurking in the Equations – Underwater Islands(gods.art ↗)
    13comments
  21. Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him(nytimes.com ↗)
    171comments
  22. GrassLobster: AI Agentic Generation of Parametric Geometry Workflows(miro.vision ↗)
    5comments
  23. BeanShell3 in Development(beanshell.github.io ↗)
    18comments
  24. Replacing Pull Requests with Delta(zed.dev ↗)
    80comments
  25. AI chatbots are becoming experts at changing people's minds(science.org ↗)
    81comments
  26. An empirical study of harness design for coding agents(arxiv.org ↗)
    49comments
  27. Bend 2 and the Vibe-Coding Trap(liampwll.com ↗)
    224comments
  28. Build Faster Feedback Loops Using Qualitative User Research(nseldeib.com ↗)
    2comments
  29. Pre-Greek: The lost language hidden within Ancient Greek(linguisticdiscovery.com ↗)
    63comments
  30. Microsoft exec called AI scraping 'the largest theft of labor in human history'(techcrunch.com ↗)
    684comments

Apply HN: PaySQR – the new secure way to pay

7 pointsby 10y ago
16 comments
Problem – Credit card processing is becoming increasingly complicated for merchants due to PCI compliance regulation and criminals compromising systems with sophisticated malware or physical credit card skimmers. Merchants don’t have the time or expertise to secure systems properly to combat these threats and generally just want an easy way to accept payments from customers without worry.

Solution – using the SQRL protocol which was designed as a password replacement for website authentication see - https://www.grc.com/sqrl/sqrl.htm and turn it into a new secure payment system where authentication/authorizations are done on the customer’s device. Since the merchant never has access to the credit card information this will remove the merchant as a target for fraud and eliminate the need for expensive PCI compliance. For brick and mortar merchants since authorizations are performed on the customer side no internet access would be needed on the point of sales reducing monthly expense and system complexity. This system would also enable digital payments that have so far been out of reach of most for things like vending machines and laundromats that currently have high threshold to entry and being unmonitored can be easily compromised by credit card skimmers.

10y agoHN ↗

a new secure payment system where authentication/authorizations are done on the customer’s device

How does this differ from Apple Pay/Android Pay, which is already making headway in this space?

10y agoHN ↗

It is a similar concept but Apple Pay requires your bank to opt-in which increases the banks per transaction cost because it utilizes the Visa Token Service. This system wouldn't require the banks to opt-in you would just be adding your credit card number to your PaySQR account.

10y agoHN ↗

Can you provide more information about how fraud prevention would work? One specific example, a fraudster using a stolen credit card.

10y agoHN ↗

I think one way to prevent the use of stolen credit cards in the system is through validating the card with two small test transactions on account creation. You could also allow the linking of checking accounts as a secondary method of verification and to reduce per transaction fee's through the use ach deposits i.e put $20 in your paysqr account for vending machine use.

10y agoHN ↗

This seems like an interesting idea

So the user will install your app and link their credit card, and every site that uses your service will just show a QR code?

It sounds like you suffer from a pretty bad chicken-and-egg problem. A merchant would have to accept both SQRL payments and regular payments if they wanted to make money. Merchants are not in the business of pushing a preferred payment method if it means they don't get paid. Every step between a shopping cart and a payment decreases the likelihood of a successful conversion. How will you address this?

10y agoHN ↗

I would start by targeting under served merchants that currently don't offer the credit card option like vending, laundromats, etc. I could also see this working to give websites another way to monetize ad blocked sites with micropayments(i.e wired throws the hey stop using adblock banner or click this qrcode and give us $.25) Another benefit to the customer would be privacy since the merchant would never see their personal info this could fuel adoption,

10y agoHN ↗

Who would pay the fees in this system, the vendor or the customer? And what kind of fees are we looking at, ~2% like other payment processors?

10y agoHN ↗

I would shoot to be the lowest cost option starting with freemium to tiered monthly fee paid by the merchants. Banks are getting hammered with constant card reissues costs due to merchant compromises and along with the savings from not having to use visas tokenization(apple/android pay) which increases per transaction fees think we could score some pricing concessions from banks.

10y agoHN ↗

Can you talk about your team? How many people are working on this full time, what are their skill sets, how long have they been working together, and previous accomplishments and work experience?

10y agoHN ↗

We are not the typical startup group the 3 of us are in our mid 30's senior level information security consultants for banks and other financial institutions. While we don’t have any startup experience we all have been in IT working together for the past 15 years and implemented multiple complex payment systems used by many Fortune 500 companies.

10y agoHN ↗

1. Do you have any competitors? Doing something very similar?

2. There is an insane amount of startups in this space. who would be your first customers, and why them?

10y agoHN ↗

There are no shortage of competitors in the payments space because most are profitable very early. My first customers would probably be in the vending machine space the few companies that provide this service overcharge and require expensive cellular internet connections per machine. I believe that lowering fees, dropping internet connection requirement and possibly adding value by capturing vending inventory stats will convince a large regional vending company that we have an existing relationship with to pilot and eventually switch it's entire fleet to our system.

10y agoHN ↗

For what it's worth, I don't know a lot of practitioners in software security, the payments industry, or cryptography who take SQR particularly seriously.

Since getting adoption for yet another payments system is a boil-the-ocean problem at this point, if you're going to go down that road, you might want to pick a more conventional cryptosystem to do it with.

10y agoHN ↗

Most people in the groups you mention are not known to be early adopters of anything. SQRL is still early days and is not rolling its own encryption its just a novel implementation of and existing one EdDSA. One notable innovative payment network uses the same encryption standard is Bitcoin and to my knowledge has never been successfully compromised. The reason there are so many different payment systems out there is because they all make money from the first day even the crappy ones which most are.

10y agoHN ↗

I consider EdDSA to meet the TLS 1.1 or higher requirement in PCI-DSS besides the lack of industry adoption do you see any potential problems with it?