It's easy to understand: PayPal is mitigating risky transactions. It makes sense, is perfectly legal, and frankly... I applaud their continued efforts to combat fraud and other bad actors.
EDIT: Downvote all you want for disagreeing... but this (fraud and risk mitigation) is exactly why PayPal "won" the P2P payments space.
I'd have no problem if they just said, these products have an enormous rate of fraud, so we're dropping them.
But instead, their reason is that these products bypass copyright protections. No mention of fraud or anything related to the actual transactions they're processing, they just don't like the products.
Which, fine, PayPal can choose to support or not support whatever products they like, but I'm not going to applaud them for playing copyright police with products which have, as the Supreme Court would say, "significant noninfringing uses."
I'm guessing PayPal isn't blocking all VPN services, just those which are insufficiently subtle about their ability to use them to bypass Netflix's location restrictions. Maybe UnoTelly should rename to UnoDefinitelyNotForWatchingNetflix.
The Supreme Court argument is immaterial. The Supreme Court can and does deem a lot of things legal (eg free speech for hate groups), which are a legal necessity. I'm proud that our country embraces such freedoms, even if I personally don't always agree with the messages. For example, I wouldn't shop at any store that actively promotes hate speech, even though the speech is legal.
Maybe PayPal is getting flak from rights holders (even Netflix), which makes VPN traffic too risky right now. Maybe they're really dogmatic about the issue ("we hate VPNs and copyright pirates!") or maybe they really just don't want to get caught in the middle of a political battle that they don't care about.
Which is completely separate and different from you original comment. Gotta love it when people just decide to move the goalposts and pretend they didnt.
This comment was perfectly inline with my original comment. My original comment said: "PayPal is mitigating risky transactions." In this case, they stated that the risk is due to copyright infringement. For some unstated reason (eg. directly or via pressure via rights holders), PayPal has deemed that such website operators are "bad actors" and are an unnecessary risk.
EDIT: Instead of making a snarky, low-information comment, I suggest you actually refute what I said. That's considered good HN etiquette.
Maybe they have data that shows otherwise? Obviously there's no causality but it's feasible that there are high levels of correlation amongst users of their service. Or maybe not. I have no idea and neither does anyone else here, unfortunately. Everyone is just engaging in Kremlinology based on crumbs of information.
In the context of payment processors, "risky transaction" means fraud.
People are criticizing you because it looks like you wrote your first post without understanding the issue and now try to defend it by altering its meaning through redefinition of common terms.
This article is about Paypal banning VPN providers who are using Paypal to accept payment for providing VPN service. It has nothing to do with people trying to buy things with Paypal over a VPN where Paypal can't log a reasonably trustworthy IP address; in that situation, there's increased likelihood that the paypal account is compromised, but preventing a VPN provider from taking payment using Paypal has no effect on fraud committed via people using their VPN service. They are separate issues.
Maybe a few VPN providers are fraudulent, but the major ones aren't. You pay them, you get a VPN. You pay for SmartDNS, you get that service. It's what people do once they have those services that's considered bad by copyright holders, and so they're applying pressure to payment services like Paypal, to get them to stop processing payments for those services.
If you look into the campaigns copyright holders are waging, the major one is an attack at funding sources for all kinds of services: file hosting, VPNs, etc. They are attacking those services and their funding, because trying to go after people who use those services—for things copyright holders don't like—has proven largely futile.
Again, what this article is NOT about: If you try to pay for things offered on a completely legitimate website and you pay with a completely legitimate credit card, but you're browsing using a VPN, it's likely to get declined. Risk of payment fraud or goods purchased using compromised accounts—via VPN which makes fraud harder to trace—is an issue but it's separate from what the article is talking about, and it's distinct from what people in this thread are complaining about regarding the article. While some people might legitimately complain about bans on payment for services over a VPN (it makes it difficult, if you don't trust your ISP or wifi service, to go VPN-only if you can't buy most things), it's fairly clear that such payment-provider or retailer behavior is motivated at combating fraud.
The issue here is entirely about copyright holders being mad and threatening the payment processors of service providers, because service providers are doing things copyright holders don't like, not because the service providers have unacceptable payment-collection risk profiles.
Upvoted for taking the time to explain the nuance: blocking VPN providers vs. blocking payments occurring over VPN.
I suspect (without supporting evidence) that PayPal is only doing this in response to external pressure (eg. from Netflix, RIAA, MPAA) rather than making the decision unilaterally. I think it's unfortunate that PayPal has caved. But from a business perspective, I can understand why they've decided to cave: The transaction volume is small relative to the cost of fighting the rights holders (in legal costs, but potentially even in the political arena). Like all other banks dealing with cutting-edge issues (eg. weed legalization), they're being cautious; they have a lot to lose.
eBay had it's own P2P payment system too. It lost to PayPal, because PayPal was superior at many things (eg. marketing), but also because they cracked the fraud problem (which was an existential crisis early on in their history). I recommend reading the book "PayPal Wars" for a better historical accounting.
True, but that was all very early. The Paypal acquisition happened in 2002. "Success" in the P2P space in the late 90's/early 2000's was at a much, much, smaller scale.
You said: "...Paypal being the default payment..." I'm saying: They didn't just get anointed as the default by eBay; they became the default (and survived this long!) by taking an aggressive stance on fraud and risk.
Also... the scale wasn't as small as you think. According to the numbers [1], PayPal was doing >$2B in transactions at the time of acquisition. For perspective, estimates from 2014 [2] put Stripe at $1.5B in transactions (and a company valuation of $1.75B). Paypal wasn't small, even in 2002.
Yes, a product that "just worked" for the largest emerging P2P market plus making money while doing so is the important part. Not accepting advance payments for shady cruise ship rentals or any of the other fringe stuff that leaks onto HN constantly didn't hurt. An important lesson for the startup crowd here.
They definitely do some dumb stuff but they also process five billion transactions per year and people need to take that into consideration. The scale of the fraud and the scope of worldwide regulations they deal with is way beyond anything you can imagine.
That does seem possible, but then I suspect that buyer protection is also one of the reasons why eBay "won" the online auction space, and has a strong position in general online retail.
People always act like Paypal can just do whatever they want - they lose tons of money to fraud and are heavily regulated. That drives a lot of the annoying things they do.
I am guessing more VPN accounts tend to be purchased using stolen credit card numbers than an average online transaction. As crackers use VPN services to render their own services.
The number of chargebacks or fradulent transactions reported on your merchant account usually raises red flags and calls for account review. I am sure its pretty easy for paypal to identify such accounts with the data they have.
When carding, which means using stolen credit cards to buy things online, people usually use two layers of security: a VPN, then a SOCKS5 proxy. The latter is usually geographically located in the country/city your card is from to circumvent CC provider checks. Both components are commonly bought from traders who again use stolen CCs to buy/rent them.
The most basic anti-fraud check is comparing card issuing country against the IP location. If there's a mismatch, it's a first red flag. If you see someone popping up from a VPN or a Tor exit, it's largely the same thing.
This is true but irrelevant to the situation at hand. This isn't about blocking transactions done over VPNs, but rather blocking purchases of VPN services.
If you were going to commit fraud, wouldn't you take steps to be anonymous? I'd guess PayPal has data that shows a significant number of fraudulent transactions happen through VPNs.
I don't follow the logic of this rebuttal. The parent comment's argument implies that VPNs are disproportionately likely to harbor fraud, which isn't true of (say) phones in general.
Some customer bases are just shady. If you don't mitigate fraud, it's not fair to push it uphill to your service providers. They will stop providing service when you're more trouble than the money you generate. Business 101, this is not a tech issue.
Look at a merchant account agreement sometime, there are all sorts of businesses deemed too risky for conventional payment processors. It's not unique to PayPal and you would be almost instantly in bankruptcy if you didn't set restrictions on the types of businesses you process for.
Restricted activities include some obvious sketchy areas (check cashing) and some less obvious sketchy areas (human hair, fake hair or hair-extensions).
Why? Any company is free to set their limits on who they want to work with.
When it comes to financial situations, it's all about risk. It's completely within their right to mitigate that risk based on the profiles of the industries they deal with and this is what keeps them in business.
EDIT: Downvote all you want for disagreeing... but this (fraud and risk mitigation) is exactly why PayPal "won" the P2P payments space.