9 ms·
Ask HN: 2FA for Credit Cards?
I never understood the idea of CVC. Every website asks for it - so it seems like an extension of the card number. Why isn't there an app (or some digital way) to verify the card is mine, like authentication systems have 2FA? It will change for every transaction, unlike CVC.
- hiyer 4y agoIn India we have SMS-based 2FA for online card transactions, and a pin required for PoS ones.
- detaro 4y agoVerified by VISA, Mastercard SecureCode are exactly that.
- theandrewbailey 4y ago3D Secure, right?
- detaro 4y agoseems like that's the overarching term for the "standard" (no clue how standard it actually is), yes
- browningstreet 4y agoUgh, I switch domain registrars because my Verified by Visa attempts never worked.
- dpkirchner 4y agoSame. Additionally the last time I saw Verified by Visa the domain it used was registered to some rando's apartment in NYC. Super sketchy. Edit: this is what I'm talking about: https://news.ycombinator.com/item?id=3962944 https://news.ycombinator.com/item?id=3962944 and https://randomfoo.net/2011/06/22/mastercard-securecode-and-securesuite-net https://randomfoo.net/2011/06/22/mastercard-securecode-and-s... Looks like I misremembered the details. Still, super sketchy.
- iam-TJ 4y agoThere is. Strong Customer Authentication https://en.wikipedia.org/wiki/3-D_Secure https://en.wikipedia.org/wiki/3-D_Secure https://www.mastercard.com/gateway/payment-solutions/security/strong-customer-authentication.html https://www.mastercard.com/gateway/payment-solutions/securit... https://www.visa.co.uk/partner-with-us/payment-technology/strong-customer-authentication.html https://www.visa.co.uk/partner-with-us/payment-technology/st... https://www.barclaycard.co.uk/business/business-matters/fraud-and-security/sca-deadline https://www.barclaycard.co.uk/business/business-matters/frau...
- lovetocode 4y agoYup came here to say this exact thing.
- artpi 4y agoCame here for that. Handling those was fun to implement in our payments systems :D
- kierenj 4y agoYeah - is it not common in the US or something? You can hardly make a card purchase in the UK without it
- xeromal 4y agoThe US population values convenience over security. Honestly, I'm in that boat. Our CC processes -> Merchants -> Customers probably end up eating the fees somehow, but being able to just insert a card and bounce keeps the machine running. I assume fraud is minimal enough that the profit of convenience outweighs it.
- Symbiote 4y agoYou are describing in-person purchases, but the discussion is about online purchases. The EU+UK and Visa/MasterCard have different policies for these. Low-value [1] contactless purchases only occasionally require a PIN, higher-value in-person purchases always do, and online ones require the 2FA system linked above. [1] https://en.wikipedia.org/wiki/Contactless_payment#CVM_limit https://en.wikipedia.org/wiki/Contactless_payment#CVM_limit
- rr888 4y agoI'm not sure where you are but USA is very lax compared to the rest of the world. Obviously someone has crunched the numbers and decided a little more fraud that gets easily refunded means the customer is more profitable that strict security that could frustrate people. I've had a card with the extra Bank verification step and I stopped using it. Maybe the lower interchange fees in Europe makes the difference.
- martin-adams 4y agoOne thing to note is that payment systems are never supposed to store the CVC number, so a data breach shouldn't include that number if the vendor does things correctly. This does make it slightly different to being a 'longer card number'. In the UK, they also have additional verification steps, which can cause some issue when they go async to a payment system that expects to get a verification immediately. I've had Apple take payment twice because the 2FA verification text took too long to come through from a phone order for collection and I ended up buying the item in the store.
- rr888 4y agoI've had a bunch of restaurants secure reservations with cc numbers and CVC in a big book. I guess their tech auditors didn't pick up that risk.
- PeterisP 4y agoI'd assume that for such restaurants there are no auditors, they would do 'self-certification' where they fill out a questionnaire where they assert that they are not doing anything like this. The consequence is that if the data is leaked (finding 'common point of purchase' is sometimes done for sets of fraud) they can become fully liable for the cost of fraud because of this lie in self-certification, otherwise it would generally fall on the receiving merchant.
- DennisP 4y agoA few years ago I read a book about a prolific CC hacker, which said restaurants were the worst for CC security. It wasn't unusual for them to store CC numbers with CVC on easily-hacked computers. The hacker would target common restaurant software and just snarf up the numbers remotely.
- blackoil 4y agoIn India, all online transactions require providing an OTP sent to mobile. Retails transaction require entering PIN on the terminal. You can make transactions below 5000 INR using NFC swipe, but that is optional and can be disabled. UPI, India's smartphone/app based payment system also requires entering a PIN to make the payments.
- InsomniacL 4y agoThe CVC essentially is an extension of the card number that is only required when making purchases when the physical card is not present. The CVC is smaller in size and located on the rear of the card to defeat snooping via over the shoulder/cctv/cameras..
- Hamuko 4y agoI'd been under the assumption that the CVC is on the other side on purpose so that it doesn't allow seeing all card details at once. But I just got sent a new credit card, and all of the details - card number, expiration, name, CVC - are on the magnetic stripe side.
- pavlov 4y agoI moved back to Finland after years in the USA, and found out that credit cards from Finnish banks now require a 2FA system for online payments. It works fine. The online purchase enters a short flow with my bank, they send a request to the bank’s app on my phone, I approve it there and the purchase flow returns to the vendor’s site. Everything about banking in the USA was seemingly decades behind my experiences in Northern Europe, so it may take a while for American banks to figure out credit card 2FA… (They still regularly use paper checks in America. Bank transfers don’t exist. Many operations require a visit to a bank branch, of which there are absurdly many. I’m surprised they didn’t have mechanical calculators.)
- DanAtC 4y ago> they send a request to the bank’s app on my phone I'm glad US banks don't require me to install proprietary apps on my phone.
- MagnumOpus 4y agoYou might be unsurprised to know that alternatives exist. Generally SMS/email auth or hardware token auth. (Less secure and more unwieldy respectively, but there are still surprisingly many dumbphone users with a lot of money.)
- aPoCoMiLogin 4y agoit doesn't have to be an app, it can be SMS
- ezfe 4y agoI've gotten the same thing from Capital One
- eythian 4y agoThis also applies in the Netherlands, I approve them through the app.
- hocuspocus 4y ago
- deleted 4y ago[deleted]
- egello 4y agoIn Turkey, where I live, online transactions require 2FA. An sms is sent for you to enter the pin or a notification is sent to your online banking app asking for approval. I thought this was a standard procedure in online banking.
- Signez 4y agoYou are looking for "3D Secure"; in Europe, it is required by regulation for all non-recurring online payments over 30 euros.
- theandrewbailey 4y ago(USA resident here) I've made several high value purchases ($100+) online without getting an additional 3D secure prompt. However, my credit union is rather liberal in locking my card for what they think are suspicious transactions. It's a text or call to customer service to unlock (where they verify recent transactions), but I'd rather enter a password more often than have my card randomly locked.
- xyzzy_plugh 4y agoActually it's possible you did get a 3D Secure prompt, but many US banks don't do anything with it and just instantly redirect back with authorization. It's impressive how far behind US financial institutes are.
- theandrewbailey 4y agoI've been with the same bank for years, and I will occasionally get one (once or twice per year). I shop on the same sites, too.
- rad_gruchalski 4y agoIn Germany: 1) register a credit card for online transactions at https://www.sicher-online-einkaufen.de/ https://www.sicher-online-einkaufen.de/, 2) activate with an activation code sent by post, 3) every transaction or 1st of every recurring transactions has to be approved via bank's online app (in my case Volksbank via touchid).
- xaduha 4y agoFirst World problem, literally. I've read that swiping cards is still widespread and magnetic strip is mandatory and chips are optional, but I wonder whether people in USA still sign their cards. Paying online without a code from SMS or push notification is an exception, usually happens when you save your payment method when buying something through a well known giant like PayPal or Steam.
- FernandoMax 4y agoStripe provides SCA as a standalone product. They connect with the bank issuer of the CC, prompts the Challenge asked by the bank, and then Stripes sends if it's ok or not.
- lucideer 4y agoTook a trip to the US recently and was astounded at how many places charged my card without any PIN or verification requirements. The seeming normality of service staff taking your card out-of-sight is also unnerving - staff typically don't even lay a finger on your card in Europe. The US is truly in the dark-ages when it comes to payment security. It seems this is yet another example - didn't even realise US cards didn't have 2FA for online transactions.
- jaywalk 4y agoRestaurant staff stealing your card info just isn't really a problem here in the US. I'm sure it happens occasionally, but there's just not a whole lot that can be done with it. Online purchases will almost always require address verification, for example.
- tjansen 4y ago> The seeming normality of service staff taking your card out-of-sight is also unnerving You usually don't need to do this anymore though. I think I have eaten out in the US about 15 times this year, and never needed to hand out my credit card. Many restaurants have a QR code on the check that allows you to pay online. Some have credit card terminals on tables (Ziosk). Others let you pay at the register when you leave.
- kube-system 4y agoI prefer it. We have good fraud liability laws. If someone steals my card number, it's the bank's problem. I am a heavy credit card user, and over my lifetime I've only had two instance of unauthorized purchase. Both times, the bank caught it algorithmically and prevented the purchase anyway.
- ghaff 4y agoI've had more than that. And I've had random purchases declined for whatever algorithmic fraud reasons. But it's never been a serious problem and these days I make sure I have multiple cards so even if one is declined, I have backup.
- 4y ago
- eliseumds 4y agoHappens most of the time I spend a few hundred dollars or more with N26 (Germany), Revolut, ING Direct (Australia) and Nubank (Brazil). OTP via their mobile apps (or SMS fallback). 1. Ye, it'd be great if I could configure it to do 2FA on all online transactions. Does anyone know what exactly triggers 2FA? 2. I have an account with BTG Pactual (Brazil) and their virtual card gets a new CVC after each transaction, pretty cool.
- xvello 4y ago> Ye, it'd be great if I could configure it to do 2FA on all online transactions. Does anyone know what exactly triggers 2FA? AFAIK, 3DS is opt-in on the merchant side, as it requires integration work. Visa & MS are pushing the envelope by only insuring against fraud if 3DS is properly setup. If the merchant chooses not to implement it (and some have decided not to, to reduce checkout friction), they have to bear the financial risk of the fraudulent transactions.
- billpg 4y agoTo everyone mentioning 3D Secure et al, I've only used them on the payments side, but it doesn't resemble the 2FA systems that the original poster was asking about. What's going on when the browser does stuff just before the payment is accepted?
- sysadm1n 4y agoThe thing about 3-D Secure is that it uses your phone number to verify it's 'you' making the purchase, but if your phone is lost/stolen and you get a new SIM, you're locked out of making any purchases with any cards tied to your old number. You can always update your details on the card provider's site so there is that. Another thing: SMS is not secure and a SIM-swap away from someone being able to make purchases in your name. I wish SMS just got deprecated as a form of verification. It's 2022, come on, we can do this!
- xaduha 4y ago> SMS is not secure and a SIM-swap away from someone being able to make purchases in your name. as in physically getting hold of a SIM card and putting it into another phone? That's what SIM PIN codes are supposed to protect against, but nobody uses them anymore because they are disabled by default now and set to 0000. But you can still do it, every SIM has a PIN and PUK codes. But SMS isn't 100% secure for different reasons though.
- kube-system 4y ago"SIM swap" attacks are typically when an attacker cajoles a carrier to swap a number to a new SIM.
- xaduha 4y agoAh I've heard of those, but that seems like another "first world problem" similar to 3-D Secure not being widespread. That's why identity theft is such an issue in USA, just by having enough information you can make customer support do all kinds of things over the phone.
- kklimonda 4y agoIt depends on your bank - mine has an application for phones that is used to interact with 3D Secure, confirm money transfers etc.
- hocuspocus 4y agoPure SMS based 2FA is already being deprecated in the EU, as on its own, it isn't compliant with the PSD 2 requirements.
- rojobuffalo 4y agoI wouldn't want it. In my 15 years of using a credit card I've had fewer than a handful of times where there was a fraudulent transaction on my account. The credit card company covered me, and in total I don't think it has exceeded a few hundred dollars. And in that same time I've made thousands of transactions. The addition of a 2FA step for every one of those transactions would be an enormous cost increase on my attention and time.