4 ms·
3D Secure is a complete disaster. It encourages users to put ridiculously sensitive information like social security numbers and bank credentials into an iframe
by Titanous 11y ago
3D Secure is a complete disaster. It encourages users to put ridiculously sensitive information like social security numbers and bank credentials into an iframe in the merchant site. This trains users to be phished.
- tonfa 11y agoReally depends on the bank, some of them have a decent 2fa system for 3d secure.
- occamrazor 11y agoSome of my credit cards redirect to a page hosted by the issuer. Others require me to authorise the transaction in an app on my phone.
- floatboth 11y agoSocial security numbers?! Who the hell implemented it like THAT? 3D Secure redirects to the bank's site (not in an iframe! a real window with a visible address bar) where you enter a one-time code from SMS!
- Titanous 11y agoI have worked with systems implementing 3D Secure and have multiple credit cards that trigger it. I can assure you that the standard deployment for US-based banks and merchants uses iframes and in the majority of cases will ask for enough personal information to steal your identity or drain your bank account.
- the_mitsuhiko 11y agoI assume this is a US problem because in the US card fees are high enough that banks don't need to worry too much about fraud yet. Look at European banks if you want to see reasonable 3D Secure.
- the_mitsuhiko 11y agoEh. 3D Secure is a protocol which can be implemented in reasonable ways. My bank has a 2FA in there.