4 ms·
risk score means the possibility of a transaction being fraudulent. here's another way you can do this for cards issued in Europe: if the risk score is too high
by TheSmoke 11y ago
risk score means the possibility of a transaction being fraudulent. here's another way you can do this for cards issued in Europe: if the risk score is too high start a 3D secure transaction. if the risk score is acceptable then start a normal transaction. a full 3D transaction will never mean it is not fraud however you will have no liabilities when a chargeback is issued by the card holder. many of your US customers, if not all, will fail to pay via 3D-secure because god knows why tons and tons of US card holders or issuing banks are not enrolled in 3D-secure system.
- daxelrod 11y agoAs a US customer, I'm hesitant to use 3D Secure because: 1) The implementations by Visa and MasterCard have security weaknesses, terrible usability and look like phishing: http://www.cl.cam.ac.uk/~rja14/Papers/fc10vbvsecurecode.pdf http://www.cl.cam.ac.uk/~rja14/Papers/fc10vbvsecurecode.pdf 2) My understanding is that my bank shifts liability to me for 3D Secure transactions. Why would I want extra liability?
- TheSmoke 11y agoin turkey, banks automatically enroll your debit or credit cards to 3d secure networks so you don't have to do it yourself. all you have to do is to enter a one time password sent to your mobile phone during payment. with full 3d secure payments the liability shifts to the customer and you will have no liability. because the customer verified the payment him/herself by hand with the otp. p.s. i am yet to read that link.
- PhantomGremlin 11y agoYeah, "Verified by Visa" is exactly like phishing. Good paper. Fortunately here in the USA I haven't been asked for my credentials in at least 10 years. So it seems to have died the death it so richly deserved. Do people encounter this on a daily basis?
- Symbiote 11y agoIt's ages since I've seen it used in the UK, although not 10 years. More like three or four. (The redirect sometimes happens, but it's automatically approved.)
- justincormack 11y agoI used it the other day. It did say 3d secure will change soon.
- jtheory 11y agoI'm in France -- I still see it for almost 100% of the purchases I make online if the merchant is here in France, and a decent number of them when the merchant is in the UK. The last purchase I made with my bank card that got the interstitial page was about half an hour ago. It sends a text to my mobile for me to plug into the form to approve the txn -- thus, not like phishing in this case. But for a while this was a real nightmare because my mobile number changed, and I couldn't figure out how to convince my bank to store the new number (it turned out after many months and phone calls I was sending the requisite paper form to the wrong address for my type of account...).
- TheSmoke 11y agoin turkey, any purchase online over 300 turkish liras must be 3D-secure. all debit and credit cards issued in turkey are automatically enrolled in the 3D-secure system. all 3D-secure transaction pages are hosted by issuer banks. they send us an SMS including a OTP and we enter it on the page and that's all.
- tormeh 11y agoNorwegian here. It's very common. It doesn't say "3D-secure" or "verified by visa", but logging in with your bank credentials (Bank-ID) sometimes feels like it's more common than not.
- derefr 11y agoVisa and co. are big—really big—so I've never understood why they've not just leaned on the OS manufacturers and browser makers to provide them some form of unique, unforgeable signal to users that they're interacting with a real bank. There could be, say, an HTML5-exposed API capable of triggering "super-modal" forms (like OS UAC does) if-and-only-if the page is being served from a secure origin cross-signed by some "Web Banking Working Group Certificate Authority" that all the banks and OS makers are members of.
- Vexs 11y ago"with one (UK-government-owned) bank, two wrong password attempts simply lead to an invitation to set a new password." Good lord! Reading through this document is like reading a primer in how not to make a secure form.
- spb 11y agoWait, what? Like, [Microsoft Bob][1] style? [1]: https://channel9.msdn.com/Blogs/TheChannel9Team/Ben-Armstrong-Running-Virtual-PC-and-Virtual-Machines https://channel9.msdn.com/Blogs/TheChannel9Team/Ben-Armstron...
- PhantomGremlin 11y agomany of your US customers, if not all, will fail to pay via 3D-secure because god knows why As I mentioned in another reply, "Verified by Visa" is a stupid joke. Which, fortunately, I don't think I've seen anymore in at least 10 years. The paper linked in the other reply to you provides more details of how stupid this thing is. IIRC basically the first time you encounter it you get a popup asking you to create an account. Yeah, right, I'm on some random website and I'll just start entering all sorts of security information into a popup. NOT! I did some checking when I first encountered it, and decided it was legit. But 99% of people won't. They'll just say "fuck this, I don't need this shit". They will then go elsewhere. I encountered it a few more times after I first signed up. And it would have maybe a 50% success rate of actually "verifying" my transaction. I'd enter the information and nothing would happen. It's the antithesis of the friction-free way that Amazon does business. I probably use Amazon once every few years but they still have all my info saved. I don't have to enter an address, I don't have to enter a CCV, I don't have to enter a credit card number. It only takes a few mouse clicks to complete an order on Amazon. So, which payment method would the average person prefer? Edit: look at what Wikipedia has to say, it generally makes the same points as the paper. Why would anyone voluntarily want to use this? https://en.wikipedia.org/wiki/3-D_Secure#General_3-D_Secure_criticism https://en.wikipedia.org/wiki/3-D_Secure#General_3-D_Secure_...
- Liru 11y agoI've been bugged by the "Verified by Visa" thing in the last month when trying to add Skype credit for my parents. Completely stupid implementation that didn't even work; I clicked "cancel" and my Skype transaction still went through.