7 ms·
As a UPI user who is using this from literally day 1 and who is hard core advertiser of this, here are few important points: 1. Security: Signup requires phone
by dheerendra73 6y ago
As a UPI user who is using this from literally day 1 and who is hard core advertiser of this, here are few important points:
1. Security: Signup requires phone number validation via SMS and phone number must be registered with bank. It also requires additional details like debit card validation. This makes is hard to spoof. After signup your device finger print is stored with NPCI and this works as 1st factor. An additional PIN is also required during signup.
You can send money only from registered device and requires fingerprint and pin validation.
2. Every digital transaction in India triggers SMS, so that provides additional transparency to user.
3. All payments are from bank account to bank account and they happen in real time! Also no transaction fee!
4. Merchants require no special equipments and they advertise their VPA usually via QR code in shops so it’s easy for users to pay.
4. Online payments can be either user triggered or can be requested via pushing payment request to user app. However user needs to approve the request with pin.
Point 3 & 4 were the biggest reasons why India adopted it pretty quickly. Also ofcourse due to Jio boom & cheap chinese smartphones!
- 9nGQluzmnq3M 6y agoQ: If a phone number has to be registered and validated, why not use that as the unique ID, instead of creating a separate VPA? For comparison, in Singapore, the local UPI-like "PayNow" network uses numbers as IDs, meaning you can easily send money to anybody in the system (these days virtually everybody) without needing to know their bank. You can also transfer to any Singaporean company or organization via their Unique Entity Number, which is an existing company/org ID assigned at formation that includes a checksum. https://abs.org.sg/consumer-banking/pay-now https://abs.org.sg/consumer-banking/pay-now
- actuator 6y agoFrom my understanding, I think just your phone number/VPA is enough to send money. I am not sure how it works in practice but I assume the VPA concept is there so that your phone number is not exposed if you don't wish to.
- captn3m0 6y agoThis only works if both parties are on the same PSP and no VPA lookup over UPI is required. So if I am not registered on PhonePe, you can’t send me money using just my phone number there. For other cases, most PSPs will automatically register mobile@psp for you with an opt-out.
- pcx 6y agoVPA is used for discoverability across UPI clients. Phone numbers can be used for discoverability among users of a single client. For eg: foobar@icici on Google Pay & baz@hdfc on PhonePe can transact with each other, but can't use phone numbers. But +91-1234567890 & +91-9876543210 can discover & transact only if they are both on either PhonePe or Google Pay or any other client application. QR Codes were initially client-specific too, but now they are scannable across apps. UPI truly is a revolution. I can have a 6Rs chai tea (8 cents) from a road side tea stall and pay using UPI with zero transaction fees.
- bahularora 6y agoYou can have phone_number@paytm or phone_number@bank as you vpa is you prefer that, also UPI API, you can search users with phone number so if i want to send money to a friend and I know his no I can search his VPA/s
- signal11 6y ago> UPI truly is a revolution. I can have a 6Rs chai tea (8 cents) from a road side tea stall and pay using UPI with zero transaction fees. The main benefit of UPI is that it works really well for small amounts, e.g. the INR 6 tea. Such small transcations were traditionally too small/uneconomical for Visa/Mastercard. However as the transaction size grows, say you're buying a laptop for INR 50,000 -- that's when the protections Visa/Mastercard build in against fraud start helping you and UPI's "no transaction fee" value proposition also starts looking like "no accountability". Interestingly, India has a home-grown Visa/MC alternative called RuPay, which also waives transaction fees for small amounts and is a credible alternative to Visa/MC. Unfortunately Indian startups have been obsessed with pushing e-wallets (PayTM et al) or direct electronic cash transfers (UPI) because it benefits them -- as the transaction size goes up it certainly doesn't protect the consumer.
- dheerendra73 6y agoyes they can be used as well. In fact Phone number can be used to discover UPI ids connected to them and if user has signed up via NPCI app BHIM then <phone_number>@upi is a valid VPA.
- nmridul 6y agoI use same phone number across multiple bank accounts. So I create unique UPI IDs to receive in each. So Google pay is linked to icici, Airtel is linked to Canara bank. When people send money, I receive it in the corresponding one. With just phone number, I will need to get multiple sim cards for each bank account. (User of both UPI and PayNow)
- fractalb 6y agoAnd UPI names are easier to remember than phone numbers. And you can change your phone numbers without any worries
- sanmon3186 6y agoVPA based on just the phone numbers may be convenient, it can lead to frauds. At least in India where - for most part - phone numbers aren’t treated like one’s personal data. Apps like Truecaller make it worse. Imagine receiving tons of involuntary charity requests on your UPI app, waiting for you to pay. If not fraud, it will clutter the whole experience of UPI payments.
- efitz 6y ago> why not use that as the unique ID Maybe I don't want to give people my phone number Maybe I have multiple phones Maybe I anticipate changing my phone number (maybe I hate my current carrier) Maybe I want something easy for people to remember, or catchy "mybusinessname@mybank" Forcing people to use a particular naming regime should only be done if there is a very compelling case for limiting your users
- captn3m0 6y agoSince that is the most obvious UX, most PSPs automatically assign you mobile@PSP. However, VPA lookups are public (VPA->Name), so your mobile Numbers can now be used to get your real name, which resulted in a lot of backlash and PSPs making this an opt-out feature.
- kylehotchkiss 6y agoForeigner who spends a lot of time in India here - I find the heavy reliance on SMS/phone numbers to be a frustrating part of the system. If I want to get something with my wife's card, I have to have her phone nearby. I wish they'd think of some creative additions to only using phone number for 2fa. After all, if somebodies card can be stolen, there's a chance their phone can get stolen at the same time.
- tumblewit 6y agoNot to mention the fact that if both card and phone (associated with the card) are stolen at the same time it is a headache to block the card since now you don’t have the phone to log in to your account to block it which requires 2FA. Calling customer care is possible but if they ask for verification then again you don’t have your phone.
- jeswin 6y ago> Calling customer care is possible but if they ask for verification then again you don’t have your phone. Card blocking is easier with phone calls. With most banks, there's a direct option right at the start via IVR - the operator will confirm basic personal details (like DOB), and done. I have had to do it more times than I should have had to.
- sm_4096 6y agoIndia's largest state bank (SBI) has somewhat moved away from just using SMS, their debit card now supports 2FA using their app and their credit cards now support 2FA over app, E-mail and SMS. Though I think RBI regulation still require a 2FA for all online domestic transactions.
- rudiv 6y agoThe regulations require it to be enabled by default afaik. SBI (I don't have experience with other banks) allows you to turn off 2FA for different classes of transactions. It's hidden away in the settings on their legacy web interface.
- stjohnswarts 6y agoDoesn't it bother you that they track everything you do, buy, sell, and know where you go all the time? That they have a forever record of your entire consumer life and potentially beyond? This is why I choose cash whenever possible.
- captn3m0 6y agoI diversify my payments, wherever I can - but not too much, since the other end is relying on too many third parties. I use SIMPL as a second layer for small value transactions, as it shows up as a single line item on my CC statement. This is also a country where millions of people give their transaction data willingly to companies like Walnut.
- SuzyM 6y agoYes, this disturbs me also (I also prefer cash). Unfortunately cash is regarded as "old fashioned" by many.
- sytelus 6y agoI am far less impressed by Indian system. First, it is almost impossible to use regular credit card in India that otherwise works in rest of the world. Indian POSes expect pins and most international credit cards do not have one so they get auto-decline. Some slightly smarter POSes will try to do things like Verified by Visa and usually there are so many bugs in implementation that things never gets through. One of the challenge I give to non-Indian folks is buy Internet access on international airports in India. It is impossible unlike rest of the world. The worst thing is that to even get in the Indian payment system you need govt issued citizenship documents and wait for approvals. Indian websites accepting online payments are usually extremely poorly designed and can't handle International credit cards at all. Most even require that you must have Indian phone number. So imagine you come to airport, have working International plan but you can't use it for payments or anything because the entire system assumes you are an Indian citizen with documents, all government approvals done and have a mobile phone number in India.
- captn3m0 6y agoSadly, the answer to almost all of your issues is regulation. India, in response to various terrorist attacks, enacted laws that made: 1. Burner phones impossible. Every new SIM requires a physical KYC 2. Every bank account requires KYC. And linking to a phone number 3. If you are a public WiFi operator(such as an Airport or a Internet Café), you are bound by law to keep KYC records of who used your services. The easiest way for this in India (that covers almost everyone) is to send an OTP over SMS. Sadly, this doesn’t work if you just landed in India and don’t have a working SIM. The credit cars on PoS is more of a US issue because US banks refuse to support chip-and-PIN. With NFC payments being supported more and more (no PIN required), this should get easier - but I don’t think of this as a fault in the Indian system. Disclaimer: I work at a Indian payments company.
- amf12 6y agoIndian POSes expect pins and most international credit cards do not have one so they get auto-decline This is actually an America problem and not a world problem. Even cards and POS in Europe are chip enabled. On the other hand, I have used my PIN-less American credit card in Europe and India and it always worked without asking for a PIN. Indian websites accepting online payments are usually extremely poorly designed and can't handle International credit cards at all. Most even require that you must have Indian phone number. +1, the entire online banking experience sucks. buy Internet access on international airports in India. It is impossible unlike rest of the world. The worst thing is that to even get in the Indian payment system you need govt issued citizenship documents and wait for approvals That's not true. There are cell-phone service providers on the Airport that issue you a working SIM with an international passport on the spot. You don't need Indian citizenship. But you do need an Indian bank account for UPI.