5 ms·
I work in ecommerce consulting - most of my clients take CC info on their site, the forms on the checkout POST (over SSL) to the PSP who then return a token to
by notmything 10y ago
I work in ecommerce consulting - most of my clients take CC info on their site, the forms on the checkout POST (over SSL) to the PSP who then return a token to the site, all future transactions use the token.
Most people don't want to bounce customers to a third party site for payment, it really hurts conversions.
- 4ad 10y agoI certainly hate it when merchants bounce me to a different site. It's most likely I will never complete the transaction and just buy from Amazon instead. If your site sacrifices user experience, I will hate your site. Simple as that. Amazon understands the convenience factor really well. I hope Apple Pay (on the web) takes off. While I don't like yet another middle man, and I don't care about its security benefits in the slightest, I appreciate the consistent and convenient interface it provides, so I will use it, if offered the choice.
- enraged_camel 10y ago>>If your site sacrifices user experience, I will hate your site. Simple as that. Even if said sacrifice keeps your credit card safe? I mean, if you are staying on the same site, you have no guarantees that the site isn't storing your credit card info in an unsecure manner.
- 4ad 10y agoI don't care about keeping my credit card safer that it already is. I am not liable for credit card fraud. In this insecure world we live in, I have not lost a single dime, nor any time, nor was I inconvenienced in any way by card theft. It's not my problem to worry about. My debit card was skimmed once, a few weeks ago. The bank detected fraud, notified me that they sent me a new card, and I didn't lost any money. I only lost two minutes of my life while I was talking to the bank on the phone.
- Cyph0n 10y agoI'm assuming you ended up with no debit card for a few days at least. That's a huge inconvenience in my opinion.
- 4ad 10y agoNo, because I have many debit cards from different banks in order to have redundancy and increase availability when the bank's system is down, or a particular card simply won't work at some merchant, but other will (usually happens in the US with my European cards).
- tutts 10y agoSo the sites should drop the safety features because there exists a user who would not be personally inconvenienced by the theft of their credit card details?
- Cyph0n 10y agoAnd that adds the overhead of managing multiple balances, fees, and credentials. You don't seem to be a typical bank user, so I'm still going to conclude that getting a credit/debit card stolen is a huge inconvenience.
- enraged_camel 10y agoThe biggest risk of credit card data being stolen is not loss of money, but identity theft.
- kalleboo 10y ago> it really hurts conversions This. We saw about 50% would prefer on-site transactions, 50% would prefer off-site transactions (PayPal or Amazon payments). Remove one of the options and half your customers just disappear.
- bemmu 10y agoWas about preference, or maybe most people just shrug and choose one at random?
- Silhouette 10y agoMost people don't want to bounce customers to a third party site for payment, it really hurts conversions. That is certainly true in my experience. Also, some of the payment services have a habit of changing the appearance and/or behaviour of their hosted systems, sometimes not for the better, and typically without warning. That is a risk you might not be willing to take for something as important as your payment flow. I know of at least one local business that switched from Stripe Checkout to using Stripe.js from their own site as a direct result of Checkout being significantly changed and resulting in customer support enquiries about the new behaviour that the business had no idea how to answer.
- phereford 10y agoI've worked with similar organizations that want the transaction on their site due to all the reasons mentioned in the comments. There are providers that use JavaScript to allow you to take payment information on your platform but never let the sensitive details hit your server. I believe this removes your platform as an attack vector for leaking credentials. The only locations that have traces of that information are the browser and the payment provider.
- Silhouette 10y agoUnfortunately, even if your payment service is hosting the system that processes the sensitive details, there's always an element of vulnerability on the merchant's side if they are hosting the rest of the site, simply because a compromise could redirect customers to a hostile alternative site to collect those sensitive details. At that point, they're really no better off than a completely fake site that never had any real relationship with a payment service at all. Merchants should always be serving their own pages securely for this among other reasons, even if they are never intending to receive sensitive payment credentials.
- phereford 10y agoYou are absolutely right.
- 10y ago
- cillian64 10y agoI don't understand this at all. I really, really don't want to give my credit card details to some random webshop who are exceedingly unlikely to have solid security. If I can use PayPal or another well known payment provider, great, I don't even have to type in my details. But even a less well known PSP is more likely to get it right than a small business webshop. A slightly jarring user interface seems a small price to pay for a much lower chance of my payment details being compromised. Is this a minority view?
- 4ad 10y agoI am not liable for credit card fraud. The last thing in the world I want is inconvenience for me, when it's other people's money at risk (bank, merchant, CC company, whoever), not mine. On the other hand, Paypal itself is a liability. Blocking your account (and your money!) for months without recourse, randomly reducing expense limits to nothing (50 EUR) are not just some Internet stories, but things that have happened to me personally multiple times. When my card was stolen (debit card even!), I didn't lose a dime, nor time. Bank just sent me a new card the same day. I didn't even have to report the fraud, they detected it themselves, as they are really good at that. They just called me to tell me about it, and that they sent me a new card.
- jjnoakes 10y agoYou aren't liable for credit card fraud, but that money comes from somewhere. Today it is a small percentage charged to the vendor; do they pass it on? And tomorrow, when the problem gets worse and the fees start to climb, will you still not care? Why be content with a system that may indirectly charge you for other people's lack of security? Why not look for ways to focus the cost on the vendors who lack security?
- ek750 10y agoYes, you're right, they pass it on. But as costs start to get noticible to the involved parties (direct and indirect), hopefully that would prod the ones that don't care now, to start.
- mrweasel 10y ago>it really hurts conversions That has to be a local issue, because that is flat out wrong. The majority of all e-commerce sites does exactly that. I have yet to meet a PSP that believe send the entire credit card number, expiry and CVV was the right solution. I've talked to exactly one PSP that supported accepting credit cards in an iframe, and that was only available to existing customers, because they where discontinuing that service. In most of northern Europe at least, customer have been use to credit card payments redirecting them to third party sites since at least 1999. It has zero effect on conversion.
- manigandham 10y ago> That has to be a local issue, because that is flat out wrong. You can't declare it a possible local issue and then say it's wrong. And it's definitely been measured (in my own testing at various companies and by many many others) that it hurts conversions to break the flow into separate redirect.