5 ms·
That begs the question: isn't fraud important enough that we should have more security on credit card? 2-factor authentication is now a well known process. How
by Fradow 11y ago
That begs the question: isn't fraud important enough that we should have more security on credit card?
2-factor authentication is now a well known process. How come you can still order things with a card number and nothing else whatsoever?
Well, here are my 2 guess, not exclusive:
- fraud prevention is actually a lucrative business, and having better security would destroy a cash cow
- the added security is deemed too hard for a large part of the population, and would raise support cost too much
- 5h 11y agoI think it's more due to the volume of ancient systems out there that do not & will not support added security measures. Visa 3d secure is popular now though.
- chkuendig 11y agoThe crazy thing is that both visa 3d secure and the same thing from mastercard dont require 2FA either at my bank. All they need is a password. in comparison, all online banking transactions go through a challenge-response process with an separated card reader and my debit card.
- scoates 11y agoVerified By Visa is (almost?) always embedded into a merchant's page (on their domain) as an iframe. At least in Canada. It's nearly impossible for normal users to verify that they're sending their password to their bank, and not to the merchant. Training users to send merchants sensitive bank passwords is a step backwards.
- 5h 11y agoTrue, it shows a prompt specified by the user at registration ... presumably that might be to establish trust? (it's been a long time since i registered mine & can't remember off hand) ... if so that's probably security theatre I think the reset process requires postcode & DOB (in the UK anyway) which would high a good probability of being available in the data-dump type scenario.
- gambiting 11y agoIn the UK, many online retailers have actually implemented 2-factor authentication for online orders. So when I order something from a UK website using my UK card, it brings me to my bank's website where I have to either type in random characters from my password, or I am presented with a list of transaction and I have to pick ones that I recognize(most of the list is bogus). Obviously it doesn't solve the issue of someone using my card on a foreign website.
- SixSigma 11y ago> That begs the question No, it raises the question. https://en.wikipedia.org/wiki/Beg_a_question https://en.wikipedia.org/wiki/Beg_a_question
- LordKano 11y ago-the added security is deemed too hard for a large part of the population, and would raise support cost too much "Older people" When I think of how difficult it was to teach my grandparents how to use the Picture in Picture functionality of their projection TV, when they were in their 50s... It makes me very afraid of how well people of their generation would handle two factor authentication on their credit cards, now that they're in their 70s and 80s.
- zeveb 11y ago> That begs the question It raises the question, not begs it. To beg the question is to engage in circular reasoning. > - the added security is deemed too hard for a large part of the population, and would raise support cost too much I think that this is a big part of it. There's also the fact that really, cryptographically-secure cards cost more, and that someone would have to pay for the readers themselves, and (I believe) there's no infrastructure in place to prevent evil-retailer.invalid from charging one's card for more than one actually wanted to authorise. With the rise of cell phones, I think that there's a real opportunity to build cryptographically-secure payment and identity protocols. A smartphone is, after all, a general-purpose computer that fits in one's pocket. The tough part isn't implementing the protocols; it's defining them, and making them user-friendly.
- draw_down 11y agoPeople say "begs the question" often enough in a colloquial manner that I think it's pretty obvious what is meant. Others sure do enjoy pointing this out, though.