Hacker News new | ask | show | jobs
by posguy 1835 days ago
Neither Square or Toast support PIN entry, whereas a Clover (made by First Data, the largest processing platform) and Ingenico/Verifone equipment have the proper hardware to ensure physical security while they encrypt the PIN in transit back to the bank your platform uses to process the transaction.

PIN Debit transactions are less expensive to process since there is less risk, but it adds complexity (First Data has many different bank keyloads like Carlton 500, Wells 350, etc depending on the bank that is underwriting the chargeback risk for your account if your company folds).

2 comments

Square does support PIN entry: you just enter the PIN into the touchscreen of the mobile device. Square developed a way of securing the PIN that doesn't require dedicated hardware. (It's now a PCI security standard: "Software-based PIN Entry on COTS".)
Square does not support PIN entry for US Debit or EBT Cash/Food cards, this appears to only be a feature in countries where Chip & PIN are mandatory: https://squareup.com/ca/en/townsquare/debit-is-here
Yes, there may be some markets where Square doesn't support PINs. I took your comment to mean that Square doesn't support PINs at all, and that it's because of a physical security requirement. I couldn't resist responding to that, since neither of those has been true for a while.
I'm not going to enter my PIN into someones mobile unless I have a way of verifying the app they are using is really the app it says it is. I can't see how that could possibly work.
Meh. With credit cards it's the banks problem if something goes wrong (and their fault for push a horrible authentication method.)
username checks out with knowledge haha - thanks!