Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

card.io is pretty cool—I wasn't aware of it until now.

I’m just shocked at how poor the security of the entire consumer finance system is, if you can accept payment just by taking a photo of someone’s card. I wouldn’t be surprised if professional credit card fraudsters had implemented this technology years ago (except with covert cameras).

A sincere question: what would stop you from photocopying someone’s card and using it to buy goods with this system? At least with Square you need a magnetic barcode, which might act as a very mild deterrent.

EDIT: FYI, I live in Europe, where we’ve had Chip & PIN-verified PoS transactions for a while now. Still not the best security, but at least it’s no longer trivial.



AFAIK, cards processed with card.io are processed as if they were "card not present" transactions, which have a different risk profile (and thereby different fee structure) than "card present" transactions (that requires some information that is on the magnetic strip that you can't just read off the card itself).


At least in Australia, all you need to make a purchase with a credit card is the numbers and dates on the front, and the 3 digit security code on the back. Having a program extract these values automatically wouldn't make this any less secure.


Card.io essentially just types in the information on the front of the card for you (card number, cardholder name, expiration date). For most applications, you probably still need to type in the billing zip code and CVV (https://en.wikipedia.org/wiki/Card_security_code) found on the back of the card.


The actual scan technology is very specific and hard if not impossible (with current tech) to implement on things like a photocopied card. A real card needs to be used.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: