Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am very surprised Amazon is killing payments.

All in all though, this means I will be much less likely to support any Kickstarters.

With Amazon Payments, I did not have to re-enter my CC#. Backing a project became an impulse buy. Click, type PW, done.

Now I have to go get my wallet, type in a bunch of information, which gives me a LOT longer to think about if I really want to back a project or not.

Indeed the primary reason I use Kickstarter over other funding websites is because I don't have to re-enter that payment information so often.



Backing projects is going to get easier—your card details will be saved. Not only will you not have to re-enter your payment information when you back a project, but you won't even have to go to Amazon each time.


There's a "Remember this card for future pledges" checkbox. So if you value having your CC saved, you can keep that feature.


But this is then an extra place where his credit card details are stored, and he may not have decided to trust Stripe like that yet.


Big payment processors like Stripe are storing your full credit card number forever whether you choose to "Remember me" or not.

The checkbox is whether you want to be able to pay again without retyping it.


I mentioned in another part of this thread, the payment page as shown on the blog entry does not indicate that my CC# is stored with Stripe, rather from all appearances it appears to be stored with Kickstarter.

Now having read this thread I get that in fact Stripe is storing it, but if I hadn't read the responses to my initial post, I'd just assume Kickstarter was asking to store my CC# which I wouldn't agree to.


What Kickstarter save is a unique token, ex. da39a3ee5e6b4b0d3255bfef95601890afd80709 (not a real token, just an example).

The token can only be used with the private / public key pairs that Stripe provided to them, so even if a hacker got access to Kickstarter's database, they would still need the private/public keys to make use of the tokens.

Also, my expectations are that only whitelisted IPs should be able to access Stripe with the key pairs of Kickstarter.


Not only that. The hacker could only use the token to transfer money between you and KickStarter, not to another account. So unless they also had access to make withdrawals from KickStarter - they couldn't do anything useful other than annoy KickStarter with a bunch of erroneous charges.


Haha, I forgot to mention that.

Basically, the only important information Kickstarter gets from any card are the last 4 digits, whether it's Visa, Master Card, AMEX, etc., and the expiration date.


The box on Kickstarter does not indicate data is stored with stripe, it looks like it is stored with Kickstarter.

As others have indicated, this is one more place that my CC# is stored. I have more trust in Amazon's security than in Kickstarter's, although from what I have gathered reading this thread it sounds like the data is stored in Stripe, which I have a tendency to trust based on name recognition.

If the page is to be presented as is though, with no other information, I am not going to store my CC# with yet another .com that hasn't been around that long.


If the page is to be presented as is though, with no other information, I am not going to store my CC# with yet another .com that hasn't been around that long.

Why not? Any fraudulent activity is your CC company's problem, not yours.


And I have to get all my cards replaced. Again. Which means updating all the merchants who do have my CC#. All of that has a cost in terms of my time!


I thought that Stripe gave sellers a customer token, so you only had to write your card details once.


Amazon is not killing payments, just a product for payments. Eventually everything but Login and Pay with Amazon will be discontinued.


I always thought 'Pay with Amazon' was 'Amazon payments'. What's the difference?


Like what?


You don't have to get your wallet if they have sophisticated Stripe support - now you can get your Stripe card info by entering in a code that is texted to you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: