Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yet another person finding out that Paypal is sh*t. What a world where you have to worry about four random letters in your messages that may just happen to coincidentally have terrorist connotations "Alep" ffs. When I ran a company >10 years ago we swept our Paypal account daily to mitigate this risk.


This is not an option for the majority of businesses now as PayPal requires mandatory funds hold which may routinely be on the order of 90 days. So even if you sweep it daily, you still have 1-3 months of your MRR sitting in flight and at risk indefinitely.


I do all my business via PayPal, and have done so for 20 years. No mandatory funds hold. My account is cleared monthly, but I could have chosen daily (that screws with my own personally accounting). $200k/year transaction volume.

Too many people generalize specific stories or their own PP experience to all of PP.


This is such a terrible business risk, why are their customers not fleeing them like clients fled SVB?


PayPal offers the only viable micropayments service on the planet. Ardour.org saves 23c on every US$1 transaction we make (and there are a lot of them). There are no alternatives to this at the present time (and if there are, tell me about them).


PayPal is an enormous percent of total sales at my company. We accept all sorts of other payments types. So we drop PayPal and then what exactly? Suffer the loss of customers?


If using Paypal imposes additional operational risk, it's entirely reasonable to charge users extra for using Paypal. Offer them lower prices for using a payment method that isn't 100% shite.


As a seller, you are going against paypal TOS if you charge a fee to use it, the same way a credit card carries the risk of chargebacks but you aren't alowed to charge a credit card fee. I agree that this would be an effective risk-management tactic (less the fact that the fee you charge to mitigate the risk still gets processed by the risk factor) but it would also worsen your chances of getting banned.


Gas stations get around this by advertising the credit card price as the full price, and then offering you a discounted price for paying with cash.


Right, iirc the newer agreement is that they can't tack on a fee greater than the credit card fee.


This is indeed what I would do if I'd absolutely have to use PayPal. Customers can use it if they really want to, but they're the ones paying for the risk.


I pay a few companies by PayPal. I even switch to competitors if they are very similar (reputational-wise too) and one accepts PayPal while the other requires my credit card; but that doesn't happen very often.

The issue is that the credit card system is broken. PayPal is a bit less broken from the customer POV. (At least in my country, where if they just removed money from my bank account, I'd go to the police and somebody would likely be arrested - or rather, I'd report to my bank, confident they would go to the police.)

I have no good solution to this either. Fixing the credit card system requires replacing credit cards, and the US will be an enemy of anybody that tries that.


  > The issue is that the credit card system is broken
in what way, is it the fees?


For me, it's the extra security and convenience. If the website doesn't use Shopify/PayPal, I'm trusting them with my credit card information and who knows how good their database security is.


A website will hardly roll their own payment processing tho. often,they dont store your cards, a third-party trustworthy processor like Stripe does.


> trustworthy processor

Trustworthy to whom? The customer doesn't even know who your card processor is.


It's the total lack of security. With the automatic consequence that all kinds security theater get imposed, stripping people of all kinds of rights, and solving none of the problems.

As a customer, I don't see the fees. But yes, by an eagle-eyes view the amount of inefficiency on the system is a problem too, as is the oligopolization. But those don't get in my mind when I make that kind of choice.


> It's the total lack of security. With the automatic consequence that all kinds security theater get imposed, stripping people of all kinds of rights, and solving none of the problems.

Not that I’m claiming that credit cards are a bastion of security, but could you be more specific?

What rights are you giving up? What inefficiencies do you see?


Have you tried promoting other methods such as standard credit card payments above PayPal? Have you AB tested removing PayPal? It could be a convenience but not a blocker.


For some markets/niches PayPal is a must due to customer trust, and they are not shy in exploiting their position to the fullest.


Paypal also has massive costumer trust outside of HN. Many people would not dare enter their credit card info on a website but will happily click the buy with paypal button. It also has incredibly low friction, which makes you more money.

In europe, the UX flow for someone ordering with a credit card goes: Enter cc info -> wait for 3d-secure notification -> click it -> enter passcode and possibly fingerprint as well -> click approve -> wait for the site to send you back from 3d-secure page -> order confirmed

With paypal, this flow, that happens everytime someone buys from your site, even repeat costumers, is reduced to: Click buy with paypal -> possibly login to paypal again -> click "yes i want to pay this" -> order confirmed.

Some sites even make use of paypal's delivery address API and don't even require you to enter it.

It's really a no-contest that costumers using paypal will drop out of the flow at a significantly lower rate than costumers using a card. In some markets, your busines is dead in the water if you decide to not accept paypal.


As a user who uses paypal a lot, this is exactly why - I don't trust random websites with my credit card number, but I already have decided to trust paypal and given an option to use paypal vs a site's own CC processing, I'll use paypal.

I'd love to be wrong though, since after reading all this I kind of feel bad for the merchants, but otherwise I'll continue to prefer using paypal.


Lots of so called challenger banks offer virtual cards which can be used with merchants you do not trust, thus mitigating the risk of them having your ACTUAL card number which they can abuse/leak.


Yes, but if you already have PayPal, it's much easier to just use it as opposed to: 1. get an account with a new back 2. transfer funds 3. have new temporary card issued 4. use that card to pay


Me too. The issue is that while PayPal is pretty bad, I don't know of any other processors that are any better (from the customer perspective). And PayPal is universal, nobody else is. I don't want to have to manage multiple payment processors.


I think amazon payments is similar, from the customer perspective.


If I don't get the 3d secure authentication from my bank when buying something with a credit card then I don't trust this site. The places I buy from don't even offer paypal as an option, I guess they must be too expensive for the local web shops.


This isn't a Paypal-specific practice, but rather a common practice for credit card acceptance for certain types of business; if these customers go to some other bank for card acceptance a merchant account, they'll get similar conditions.


True to some extent — usually banks are not as eager to ban you without any prior notice as PayPal nowadays.


I'm pretty sure that seizing customer funds is part of their profit model. They've been doing it for a very long time, and well beyond anything that could reasonably be explained via regulatory or card scheme requirements.


> we swept our Paypal account daily to mitigate this risk

...so, is there a list of forbidden character combinations one should scan for somewhere? That sounds like a super useful thing to have.


"Swept" in this case means withdrawing all the cash from the Paypal account




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: