4 ms·
Here's an anecdote about India. They started requiring customer authorisation on all card transaction recently (signature doesn't cut it and no Paywave for you
by prebrov 10y ago
Here's an anecdote about India.
They started requiring customer authorisation on all card transaction recently (signature doesn't cut it and no Paywave for you). There were reports on how that that forced Uber to use local payment gateway.
Anyway, couple months ago I was in Chennai, went to a restaurant with a customer and when the bill came which customer didn't give me a chance to pick up, they handed over a card AND a PIN number for the card.
I was shocked, naturally. The customer explained to me this is standard practice and "a requirement" now for locally issues cards.
It isn't really, but since most terminals are wired and installed at the checkout counter, Customers aren't invited to enter the PIN over at the other end of the venue and aren't keen to, frankly. It is upper class who uses cards for payments and psychologically and culturally they're expecting a full service. Walking to the terminal to enter a PIN is a bit of a "walk of shame".
So, that's how best government intentions turn into known, en-masse and country-wide security hole and a direct breach of banking service contract, that requires customer to keep PIN private and waives any responsibility if PIN is shared.
I would not at all be surprised if this 12-digit personal API ID will be shared just as easily as a card PIN.
- supergreg 10y agoI was under the assumption that the 12-digit ID is public data, the bank account number, not the password to access it. Unless they can scan your iris and derive the number themselves to identify you, which makes it similar to a bitcoin address, while the private key for that address is your biometric data.
- prebrov 10y agoI very much doubt they plan to equip POS's with biometric readers, not to mentioned I doubt there's a reliable enough tech to deploy at such scale.
- blackoil 10y agoNow a lot of establishments are getting wireless terminals, which they bring to your seat.
- tushar-r 10y ago>It isn't really, but since most terminals are wired and installed at the checkout counter, Customers aren't invited to enter the PIN over at the other end of the venue and aren't keen to, frankly. It is upper class who uses cards for payments and psychologically and culturally they're expecting a full service. Walking to the terminal to enter a PIN is a bit of a "walk of shame". In the last 2 years or so, since PIN has become mandatory, I've come across one instance where the hotel asks for the PIN in this manner. Most of them have wireless terminals now and the others ask you to come over and type in the PIN. This experience is quite rare in Chennai or Bangalore.
- siddharthdeswal 10y agoI'd like to clarify a couple points here. The terminals have been in use for years now across petrol pumps, restaurants, malls, pubs etc. And the majority are the wireless kinds now where they bring the machine to you to punch in the pin number. And the cultural part about the upper class finding it a walk of shame is, quite frankly, ridiculous. Instead, we feel secure giving out the pin number because we know that the person needs the card and the pin to make a transaction and we'll get an SMS the moment a transaction goes through. And more often than not, we're too lazy to walk to the terminal so we just tell the waiter the pin number.
- catchmrbharath 10y agoI have been guilty of sharing the PIN in restaurants, when they don't have wireless terminals (which happens very rarely). There are a couple of reasons why I didn't feel it was a security hole. 1. All Indian cards are chip cards, hence they cannot be replicated (or not replicated quickly) 2. I get a transaction message immediately. I know exactly how much money was charged into my account. 3. My credit card cannot be used anywhere to make a transaction > 20$ without a 2 factor message to my phone. All these security ideas are built into the system and its not opt in.
- prebrov 10y agoThanks for clarifying, peeps! As you understand, I'm selling it at what I bought it for, merely retelling what I've been told. In this particular case, bill was definitely more that $20 and to my knowledge, there was not 2-step auth, just a notification. I definitely seen it more than once and it also does seem to me that wired terminals are still quite common, but I might be wrong since I, naturally, pay with foreign bank's card and don't have to punch in a PIN. Afaik, fully cloning a chip card is fairly easily done with a cloning device, one of those you might have seen hooked up to an ATM. And I'm happy that you guys seem to be content with the way things are. I'd be totally paranoid having to share my PIN even once, ever. I mean, after that some one should be able to withdraw tons of cash and after I see the notification, bank would be in their full right to refuse reimbursement on the grounds that I shared my PIN. And they'd be absolutely right. Cheers!
- softEngg 10y ago> I'd be totally paranoid having to share my PIN even once, ever. I mean, after that some one should be able to withdraw tons of cash and after I see the notification, bank would be in their full right to refuse reimbursement on the grounds that I shared my PIN. And they'd be absolutely right. Well, most of us have a separate account for making small transactions like these. Even if it gets misused I won't lose much.
- eCubeH 10y agoCan relate to some parts of this. Controls are bypassed routinely. The concept of privacy is a foreign idea, almost. People don't understand basic elements of security. But openly giving up your PIN seems quite silly. Not shame as much as laziness and stupidity, it seems.