Hacker News new | past | comments | ask | show | jobs | submit login

"Powered by Stripe" doesn't help; I mean, in the end, you are "powered by Visa", and if you are using a Visa card, you hopefully trust Visa. Instead, the question is whether we trust your website to handle the credit card data in a sane and safe manner before it is ever sent to these backend providers.

Specifically, we do not know whether the credit card ends up on your server (possibly stored poorly), and just knowing you use Stripe (which allows for that not to happen) doesn't guarantee that your server has the requisite security required to not have been modified to send the things we enter to a third party.

(That said, I will say that I am not actually the kind of person who fears using my credit card online, so I may be simulating this argument train incorrectly; these thoughts go through my head, but my reasons for often using PayPal when provided the option have more to do with liking the kinds of reporting I can easily do using their APIs.)




Aah - I need to add the line that we do not store your credit card info to the order form - thanks for that! It's on the thank you page but you are right - I could add it to the form.

One thing I absolutely wanted in our new system was that we were never going to store the cc# - that's one of the reasons I liked Paypal/GC because we never stored the cc number. I read something about a wine store being hacked and the hackers getting all of the credit card numbers recently.


One of my points, however, is that I have to take your word on that, and even if I know that you are using Stripe, I have to trust that your webserver wasn't compromised and is now running a few lines of "extra" JavaScript that also skim my credit card to a third party site.

(Honestly, and I realize this is a stupid bias on my part, I'd trust your site more if the labels on the text boxes lined up with text boxes. I think it is fair to say, however, that a lot of people have silly biases like that, as a lot of time you are just fighting with some gut feeling someone is getting about your site as they are about to convert, and not any appeal to rational argument.)

(Again, though: I am actually the kind of person who tends to just use their credit card willy nilly. I, personally, would have no serious problem signing up for your site as is. However, if you had PayPal as a payment option, I'd use it, and in the end it could actually save you money. If you had Amazon Flexible Payments as a payment option I'd definitely use it, and it would almost certainly save you money.)


We do have paypal option - I think I see I need to add a link to it on the order page, right now the link is on the order options page.

As for Amazon, I spoke with them at length - their FPS service won't work for us they said.

Thanks so much for your feedback


Don't think it's a CloudContacts problem, but rather just any service that doesn't send you off to Google, PayPal or Amazon to fill out your credit card.


Obviously. That said, it is also a trust to specific site problem: I might trust Apple, but not trust Flowroute. Honestly, many people might trust a website that looks "corporate", and not one that looks "Web 2.0", or trust websites that use blue on white, but not ones that uses yellow on black. Having PayPal (or an alternative, such as Amazon Flexible Payments, which is epic in many ways, although lacking in international support) as a fallback option is great as anyone who doesn't trust your website has a fallback option.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: