Apr 22nd, 2020

The Missing Multi Factor Mindset, Payfac Paralysis, Class Action Chaos

TL;DR

Jason and Hayden discuss why Zoom’s credential stuffing headlines were less about a Zoom breach and more about weak password habits and underused multi-factor authentication. They also unpack why many ISVs get stuck chasing the PayFac model when a better payments partnership may create the same upside with less operational drag. The episode closes with a look at food delivery platforms facing class action pressure over pricing structures, merchant fees, and the risk of building a business model that creates frustration for both restaurants and consumers.

Security, Payments, and the Cost of Bad Assumptions

This episode of Cents Chat starts with Zoom getting dragged through the security headlines, then moves quickly into a bigger point: sometimes the story is not the breach. Sometimes the story is the mindset that made the breach useful.

Jason and Hayden unpack three different problems that all share a common thread. Weak security habits, overcomplicated payment strategies, and aggressive pricing models can look manageable right up until they become a headline, a lawsuit, or a giant distraction from the business you were supposed to be building.

The Missing Multi-Factor Mindset

The Zoom discussion centers on credential stuffing, where attackers use username and password combinations stolen from other breaches and test them against new services. Jason’s point is that this was not necessarily a Zoom data breach. It was a reminder that reused passwords are basically a gift basket for attackers.

The answer is not mysterious. Multi-factor authentication should be enabled, encouraged, and in many business environments, required. Especially in financial services, where account compromise can lead to theft or misappropriation of funds, MFA is not just a security feature. It is a basic control.

Jason also makes the practical case for password managers. If every login has a unique, complex password, one compromised site does not automatically turn into a tour of the rest of someone’s digital life.

PayFac Paralysis Is Real

The second topic shifts to ISVs and the temptation to become a PayFac. Jason gets why the model is attractive. Software companies build strong products, realize payments can become a revenue stream, and start wondering why they are handing that upside to Stripe, Braintree, Adyen, or another provider.

The problem is that becoming a PayFac is not just flipping on a monetization switch. It brings technology, underwriting, risk, compliance, operations, and support responsibilities that many ISVs are not built to handle.

That is where PayFac paralysis kicks in. Instead of building better product features, teams get stuck researching payments infrastructure and trying to become experts in a business they did not originally set out to run.

Jason’s recommendation is straightforward: find the right payments partner. ISVs can still participate in payments revenue without carrying every burden themselves. The goal is not to win a payments complexity trophy. The goal is to build more value for customers and structure the payments relationship intelligently.

Food Delivery Fees Meet Legal Pressure

The final story looks at food delivery platforms like Uber Eats, Postmates, DoorDash, and Grubhub facing class action pressure over fees and pricing practices.

Hayden points to allegations around high fees, menu pricing restrictions, and restaurant economics. Jason connects that back to payment and platform costs, noting that if a pricing structure hurts consumers or merchants, it creates an opening for competitors.

That is the real takeaway. Whether the issue is security, PayFac strategy, or food delivery pricing, bad operational decisions do not stay hidden forever. They eventually show up as customer friction, legal exposure, lost trust, or a better-positioned competitor waiting to eat your lunch.

Featuring
  • Jason
    The Nerd
  • Hayden
    Guest Speaker
    Transcript

    Jason: Welcome to this episode of Cents Chat with Jason and Hayden. Let's jump right in to make the payment make sense. Hayden, as much as I hate to admit defeat, the consensus from our listeners is you are indeed the pretty face. So it's great to have you back in the office, pretty face and all.

    Hayden: Yeah, it's great to be here, Jason. It's great to see you too. Being in here is the only thing that escapes my quarantining lifestyle. So let's dig into these stories. The first story: the missing multi-factor mindset. Don't be dragged through the headlines like Zoom.

    Jason: Next, we'll cover PayFac paralysis, which is not another symptom of coronavirus.

    Hayden: Lastly, class action chaos. Is there about to be a frenzy around food delivery? Approximately 500,000 Zoom username and password combinations were compromised due to a credential stuffing attack. Is Zoom to blame for this?

    Jason: Well, Hayden, not really. Our friends at Zoom have really been dragged through the wringer in the last few weeks over security concerns. And I'm a huge fan of Zoom, but I can't fully fault them for this. Credential stuffing is a practice where hackers use previously compromised passwords and essentially brute force particular service providers. In this case, Zoom was the target, to figure out if any of the existing combinations they have work for a particular service provider.

    Anything they find that they are able to log in with, they turn around and sell on the dark web for pennies per set of credentials. So the actual compromise itself did not stem from a data breach or hack of Zoom, but stemmed from the use of credentials that were previously compromised from other websites.

    Hayden: You say Zoom is not really to blame for this, but what could they have done better? It seems like this type of attack could potentially target any company.

    Jason: Hayden, you're absolutely right. Almost anybody is vulnerable to this type of attack if they're not using multi-factor authentication. And I know that is a security feature Zoom has available on their web-based platform. However, it's not built into their desktop client.

    I think just about every company out there should have multi-factor authentication enabled by default when a new account is created and should encourage their customers to be more cautious with their credentials and the services they use.

    I think the other side of it, and this is where I don't fault Zoom, is that security administrators for the customers of these products have the ability to enable multi-factor authentication, usually company-wide, so every user is forced to use multi-factor authentication. The second piece is corporate policies on password security management. All too often, people use the same passwords for every website they log into, which is exactly how these credential stuffing attacks happen.

    If you've got the same password on every website and one of those websites is compromised, those credentials can be used for a variety of other vendors: online banking, stock trading, video conferencing, you name it. The list is limitless.

    Hayden: Jason, you say unique passwords for every website, but that seems like it could potentially be a lot of passwords to remember.

    Jason: Yeah, especially for an old guy like me. Every time somebody asks me how old I am, I have to calculate it because I can't even remember my own age anymore. But there are great password management solutions out there. The way I handle this personally is I use a product called Dashlane, and every website that I have credentials to has a very long, randomly generated, complex password that's stored encrypted locally on my computer.

    That means every website has a unique password, and if one website were to be compromised, the rest of my accounts would still be safe.

    Hayden: Jason, multi-factor authentication is an added step that a lot of customers don't seem like they are ready to embrace.

    Jason: Hayden, I agree. It is an added step. But I think as security administrators or responsible vendors, we need to protect our customers from themselves. Multi-factor authentication is one of the simplest ways to prevent account compromise and account takeover. All of our products that we build have multi-factor authentication enabled by default. At some levels, depending on your roles and permissions, it can't be disabled.

    We continuously have conversations with our customers to educate them on the importance of multi-factor authentication and also make it as easy as possible for them to implement so that it poses as little burden as possible.

    The other thing that I think is important, especially if you're in the financial services industry and the possibility of an account compromise could involve theft of funds or misappropriation of funds, is that it's important to have the customer acknowledge that if they're going to disable multi-factor authentication, then you as a service provider are not liable for any activity that happens if their account is compromised.

    Hayden: I agree with you, Jason. And if you are concerned that maybe your data has been leaked in one of these breaches, you can go to cybersecurity company CybelAngel's "Am I Breached?" data breach notification service, and they'll tell you exactly where your data is going if it was breached at all. Well, Jason, I know your credentials are safe, but let's talk about your time. I can't even add up the amount of hours that I hear you talking to ISVs about what's involved in becoming a PayFac.

    Jason: Hayden, you're not kidding. I think PayFac is definitely the shiny new thing in payments. One of my favorite analogies is it's like the Web 2.0 trend of payments. And I get it. It makes a lot of sense. You have some great software companies out there that are building niche market products for specific industries.

    A lot of them, when they start out, their idea is, you know, we'll use Stripe, we'll use Braintree, we'll use Adyen, we'll use one of these guys that makes it really easy to enroll as a merchant and start processing payments. That's how a lot of them start. Then once they get a little momentum, they realize that payments is a revenue opportunity. And all along, they've just been essentially donating that additional revenue stream to the Stripes of the world.

    They develop what I like to call PayFac paralysis, where they start spending so much of their time and effort researching and trying to become a PayFac. And I don't think they realize what is really involved. There's a reason there are companies solely dedicated to providing payment services. It's a huge undertaking from a technology, risk, and underwriting perspective for somebody who doesn't have the core payments competency to become a PayFac.

    Hayden: Yeah, it sounds like part of the driving force is the ISV looking to get in on the payments action and increase revenues, but is there a way to do this without becoming a PayFac?

    Jason: You're 100% right. That is what is driving them down this path. And I think there are a lot of viable alternatives for ISVs to get a piece of the payments action without actually becoming payment facilitators themselves. We work with a number of banking partners and wholesale ISOs whose core focus is working with ISVs.

    It's almost like a PayFac-in-a-box or PayFac incubator type scenario, where they can get all of the added benefits of being a payment facilitator without having all of the overhead and expenses of doing it themselves. We've created some super viable partnerships between ISVs and acquiring banks that have an appetite for technology-based companies that have a payments component to their platform.

    In the long run, it's a much more profitable opportunity for the software company because they're not diverting resources into an area where they don't have core competency.

    Hayden: Yeah, that certainly sounds like a much quicker roadmap. And speaking of roadmap, it looks like a lot of ISVs sacrifice developing new features to attract more customers in order to build payments technology.

    Jason: Spot on, Hayden. My message to most of the ISVs that I talk to who don't have a lot of payments experience is: focus on your product. You've built a great product in whatever vertical you specialize in. Maybe it's salon software. Maybe it's gym software. You know that business inside and out. Diving into payments is a massive undertaking.

    Find the right payments partner. You get all the upside of being a payment facilitator when you find the right payments partners, and then you don't sacrifice building the features and functionality that your customers want. At the end of the day, most of an ISV's customers don't care whether they're a PayFac or not. What they care about is the value that product adds to their business.

    So focus on adding more value to your customers' businesses instead of trying to become an expert in something that you're not.

    Hayden: Knowing about the years you have spent developing payments and compliance technology, I can attest to the complexities and overhead of being a payments company. So let's talk about a few PayFacs that took the long road: Uber Eats, Postmates, DoorDash, and Grubhub.

    Jason: Yeah, I've definitely dedicated a lot of my life to payments technology. And in fact, if it weren't for that group of companies, I probably would have died of starvation with the long hours in the office.

    Hayden: Yeah, I'm right there with you, Jason.

    Jason: So you mentioned that those guys were in a lawsuit. Tell me more about it.

    Hayden: Yeah, well, the lawsuit has been said to have no ties to the coronavirus and was filed last Monday in a federal court in New York. But these food delivery service companies are being accused of charging exorbitant fees and forcing restaurants to raise prices for dining customers, which in some severe cases is up to 40% of the sale price.

    Jason: That's ridiculous, considering the average cost to process a credit card transaction is around 2%. The fact that they're charging 38% above their cost is probably indicative that they're trying to offset huge payment technology expenses in addition to their core application development.

    Hayden: Yeah, well, several customers even allege that they have monopoly power that they wield against restaurants and consumers. They're basically forcing restaurants to charge uniform prices for restaurant menu items throughout all purchase platforms, which then prevents restaurants from charging different prices to meal delivery customers than they charge to dine-in customers for the exact same menu items. And based on the lawsuit filed, that restriction is what qualifies as an unlawful price restraint.

    Jason: I'm certainly not in that vertical, so I don't understand all of the expenses associated with it. But I know every time I use one of those services, they're also charging me delivery fees and other fees on top of the items that I purchase. So it just doesn't add up.

    I think one of the possible outcomes of this is that restaurants start doing something very similar to cash discount programs, where in order to comply with the terms of the meal delivery services, they offer discounts to customers who pay with cash in-house. And I think it only creates complexities and mistrust with the business's patrons. But I understand it. The business has to make money too.

    Hayden: Yeah, I think it's going to be interesting to see how this shakes out in court, but it sounds like there's definitely going to be a big opportunity for some new players in the food delivery service vertical.

    Jason: You're right, Hayden, and they're already popping up. In fact, we've been working with an ISV that is in that exact vertical, and they're going to market charging their merchants three and a half percent. So I think there's a big opportunity for companies that structure their payments relationships right to come in and compete against the big names. I'm sure the restaurants will be more than glad to jump on board and pay three and a half percent as opposed to 40%.

    Hayden: All right, Jason, it is time to make payments make sense. Give me the takeaways.

    Jason: Well, payment supply chain, if you're not heavily pushing multi-factor authentication to your customers, you're asking for some negative press. ISVs, focus on your core product and the features that help you get new customers. Find the right payments partners. And lastly, if your pricing structure ultimately hurts consumers, you're only painting a target on your back for new competitors.

    Hayden: Thanks for joining us today. And if you've got a topic you would like us to discuss, follow and message us on social media at Cents Chat. And as always, we would love your feedback. Hayden out.