6 ms·
> then receiving a code in a text message and typing it back, and now typing yet another personal code Really? In my experience aside from typing the card numb
by ginja 5y ago
> then receiving a code in a text message and typing it back, and now typing yet another personal code
Really? In my experience aside from typing the card numbers, all I have to do is approve the transaction with 3D secure which is one tap in my bank's app. It has never failed in my experience.
Maybe you need to switch banks? :)
- jraph 5y ago
- ginja 5y agoAh that makes sense. I respect you not wanting to use an app, but most likely >90% of the people who make online purchases also have their bank's app so it makes sense that the flow is optimized for that. I use Wise too, but they also support 3D secure and it is generally required on European merchants... Works great in the app, but it's probably clunky without it too :/
- IshKebab 5y ago> I don't have any Android or iOS device on which I can install your app, and I would not do that anyway. I don't think you can really complain that they aren't using convenient 2FA because you don't have a smartphone. It's a pretty reasonable thing to require these days. You didn't complain that the online shop itself required the use of a computer.
- pinephoneguy 5y agoNot for 2fa. There are standards for that and they don't need smartphones. Also: I would trust the security of a computer owned by someone without a phone more than that of the average smartphone at this point.
- jraph 5y agoI don't think forcing people to go to the GAFAM is fine, no. (And yes, I have a smartphone but that should not be a requirement neither. My computer should suffice). > You didn't complain that the online shop itself required the use of a computer. Obviously online shopping requires a computer. It would not make sense to complain about this (though if I had to be a bit pedantic, the computer does not have to be mine. I don't need to own a computer). At the moment the situation is workable for someone not having a smartphone, so, fine, but I hope it stays this way.
- joshvm 5y agoSo there are a couple of issues at play here. First, a merchant can charge your account with only your card number, date and CVV. If you call up and pay someone, say an insurance company, that’s all they need. Now your bank might automatically reject that charge if it seems suspicious, but that’s their call. This is why fraud is/was so rife in the US, because anyone who imprints your card can pay with it. Adding a chip and 3D secure mitigates that somewhat. If someone steals your card, usually it’s just an inconvenience because the bank will freeze your card, issue a new one and refund fraudulent transactions. Typically the reason you see 3D secure is for chargeback protection. Chargebacks from fraudulent cards are both common and expensive for retailers and they want to minimise it - so they check your address etc. Ever notice that the checks sometimes make no difference? For example sometimes the billing address gets checked and fails if you put in the wrong one, other times it doesn’t seem to matter. I believe this is a merchant decision (some places just use it to generate invoices for tax purposes). I don’t know of any regulation for using apps, but 2FA may be required? With Wise I can respond either via SMS or the app. I also have another fintech card which gives the option of sending the OTP over email which is useful when the app isn’t available. Also as an expat I have two phones with different sims, so I need solutions that aren’t device locked (at least one bank only allows me to have one mobile device registered).
- jraph 5y ago> So there are a couple of issues at play here. First, a merchant can charge your account with only your card number, date and CVV But the 2FA authentication of 3D secure with an SMS was fine(-ish) for me. I'd prefer this didn't rely on a phone (having network reception), but fine. It's better and more conforting than no verification at all. Requiring me to validate two different forms with both an SMS and my bank account password is a bit much. But I'll adapt. I wish they turned those two forms into one directly though.
- KronisLV 5y agoIt depends on how the payment is integrated, i guess. Is some relatively local stores it's along the lines of: - check out an item in the cart - you're taken to a payment processor's page (gateway) - there you pick your payment method, e.g. which of the supported banks you use - then you enter your bank's user ID and personal identifier - then a prompt pops up on your phone (though you can also use a "code calculator") with a reference ID - you enter your PIN code to confirm the prompt on your phone, granting the gateway access to your bank account - it then lists your payment accounts, from which you pick one that you'd like to pay with - then you get yet another prompt on your phone, this time you have a separate longer PIN to enter for confirming the payment - you do so, the payment is processed and you're taken back to the store page, with your order placed Note: that app (SmartID) that's used for the codes and confirmations isn't actually maintained by the bank, but is a separate entity, so to make a payment you might have to rely on the shop being up, the payment gateway being up, the confirmation solution being up and the bank also being up. Despite all of those vectors for failure, i've actually had a pretty good track record with this solution (i've only seen the bank's service crash once and the occasional store have issues). Oh, and the app can also be used to confirm authentication for online banking: you enter your bank user ID and personal identifier, which makes a prompt pop up on your phone, so you also get 2FA there out of the box! For anyone wondering: https://www.seb.lv/en/private/daily-banking/smart-id https://www.seb.lv/en/private/daily-banking/smart-id Of course, the bank also has its own app where you can make payments to specific people, or request payments, as well as view your account balance and see how your investments are doing, which is pretty nice, though you cannot use it for confirming those purchases. On global stores (e.g. the likes of Amazon, eBay, AliExpress etc.), however, the process is generally far less involved, you just check out an item that you want, shortly afterwards the money shows up as "reserved" on your account. If you don't recognize that order, you can dispute the charge. Of course, if you don't have card details saved, you would need to enter that information first (card number, name, expiration date, code), but the end result is the same there. That said, despite the seemingly more cumbersome approach of integrating with the bank directly for payment processing instead of going with just the card approach, i'd say that it has some security advantages for sure! With this approach, even if my bank account is compromised, no one can make payments without having direct access to my phone AND knowing the codes (as long as the system works). Of course, many still choose to pay with their cards instead.
- rr808 5y agoThat always scares me, if you lose/break your phone you can't use your card any more?
- ginja 5y agoYou can still pay in person using chip & PIN or use an ATM without the app. This only applies to online shopping AFAIK.
- saberdancer 5y agoOnline shopping at the more secure sites.
- stronglikedan 5y agoSurely the bank's website offers the same security features, so that accounts may be accessed without a specific phone with a specific app. If not, then that bank should be avoided.