9 ms·
You can blame the evil competitor but the real problem is that credit cards are not the right tool for payments to strangers over the internet. Every time I do
by eduction 3y ago
You can blame the evil competitor but the real problem is that credit cards are not the right tool for payments to strangers over the internet.
Every time I do a CC transaction I’m giving a stranger exactly the information they need to do an entirely different, arbitrarily large CC transaction in my name with any merchant. That’s bonkers.
I’ve recently seen more use of Apple Pay via websites. Assuming it works as Apple Pay usually does, this at least is technically more secure (though I don’t like giving Apple more power) since it’s basically an exchange of cryptographically secure/verifiable one time tokens.
PayPal is no one’s favorite but at least if you use that you’re not handing over your CC number. (And yet they seem to lock out tons of merchants, hmm)
Why are we still using credit cards? It’s not great as a consumer either - I have had my card locked for traveling within the same city and spending maybe $20 at a merchant I don’t usually visit. I had it locked because of a $5 web service monthly charge - and I had verified the same charge the two prior months.
- tough 3y agoCC in europe require a 2fa confirmation where you recieve usually a notice of the amount you're approving
- reaperducer 3y agoCC in europe require a 2fa confirmation where you recieve usually a notice of the amount you're approving How does that work when you buy things in places where you don't have cell service? Yes, they exist. Even in Europe.
- bonestamp2 3y agoI guess in those cases, something offline like google authenticator (or similar) would be better.
- SXX 3y ago> Yes, they exist. Even in Europe. You mean you have wi-fi, but don't have cell service? That is like... super rare.
- qup 3y agoIt's not rare at all where I'm at. I mean actually, I frequent a business where you cannot get a cell signal, but they offer free wifi. Metal building blocks the signal. This could happen anywhere.
- plorntus 3y agoRight but then you just connect your phone to the wifi? The following methods I have had for the 3DS card payments are (ultimately depends on the bank): - Bank sends you a tiny card reader that you enter your PIN and it gives you a one time code. If you want to make payments that require 3DS (online only ofc) you have to have this card reader on you but it doesn't actually require an app or internet connectivity. - You have an app on your phone, you drag a code from a notification onto another area of the app itself which does something (somehow - no idea the purpose) and verifies the transaction. Certificate is stored on device only. - You open an app and it'l notify of the purchase amount, location, merchant and you just tap allow - You receive a code in the mail that is renewed once a year which is then combined with a SMS message (or app notification). The payment flow asks you for some characters from both codes. You do not require cell service for any that I have used and wifi is enough. Further Edit: Just to clarify though, all of these are ONLY for online purchases. Purchases in shops you just use your pin if it requires authorisation.
- lxgr 3y agoThere's Wi-Fi calling, but unfortunately at least in Germany, many operators don't support receiving SMS over that, unlike the US carries I've tried it with. However, most banks/issuers have since switched to using their app as the second factor, so all you need is Wi-Fi, practically. A few even support displaying an offline code in the app that you can enter during checkout, but that's becoming less common since it doesn't support displaying the amount and payee given how it works.
- jhugo 3y agoNot rare at all. I grew up in such a place (well, before WiFi, but now it has WiFi and still doesn’t have cell service), and have lived in two other houses like this. On holidays I have stayed in hundreds of places like this. I remember in Berlin going to a bar where there was no cell service (some combination of poorly sited base stations and thick walls made of something dense). They of course offered free WiFi considering this. Where I am now, there’s a section of beach full of cafes that has no cell service. If you walk 100m north or south it’s fine, but that bit is a dead zone. All the cafes have free WiFi.
- can16358p 3y agoAnd how does the PoS machine work then? In the edge case where there is no cell service yet the PoS device has connectivity (e.g. WiFi or other cellular service) they might set up a WiFi access point for users to get push notifications (assuming the 2FA method is not archaic insecure SMS).
- sethhochberg 3y agoPersonally, I am substantially more suspicious of whatever random wifi network I’d need to connect to in this scenario than I’ve ever been with payment terminals out in the wild. There so, so much more attack surface on my phone than there is with my credit card - and resolving fraud on the credit card is as easy as a phone call to the issuer (at least in the US). No such luxury if my device gets pwned or networks are MITM’d or I’m associate to suspicious activity originating from this network.
- tough 3y agoThe PoS asks for the pin in sales > 50e for 99% of population, you can change your personal limits but still this is not sms 2fa/based but a physical/android based pos to charge the bank lends you
- can16358p 3y agoWhile a random WiFi network isn't what I'd love to join too, at least it's an option for receiving a code through an encrypted channel (push notifications). If that encryption can be MITMed, then there is a much bigger problem as any traffic can be MITMed at cellular network level anyway, voiding out any WiFi-MITM concerns.
- toast0 3y agoPoS can do offline transactions and sync them later, if the merchant is willing to accept the risk.
- dijit 3y agoIt does work, though I am not 100% certain of how. Something to do with having a “next authentication token” on your device already with a 24hr expiry.
- dtech 3y agoYou 2FA trough your bank app, SMS is too insecure for this purpose.
- btilly 3y agoI have had too many phones land in water, then get bricked, then be unrecoverable. Then find that 2FA locked me out of key stuff. Like my Apple account. I know that SMS is insecure. But I can get it back after a predictable disaster.
- tough 3y agomost 2fa codes you can store the qr seed you get into your authenticator app as backup code. sms is trash yeah, 2fa just works if you care enough to know how (in most sites)
- btilly 3y agoWith my Apple account, I didn't even remember 2fa having been set up at all. And if I had backed it up, it would have been to a computer that itself had been replaced when it died. With the Time Machine archive having been corrupted and unrecoverable, so it would have been lost. Today I've noticed the qr seed idea. But I'd prefer having my personal phone having access to nothing irreplaceable, and not worrying about it if it dies. If I work in an environment that needs to be secure, then I'll worry about following security recommendations. But to whatever extent possible, I prefer not working in an environment that needs to be secure. And then not bothering with the UI disasters that secure solutions regularly impose on people.
- lxgr 3y agoIt’s not really a security concern, but SMS is only one factor (and EU regulations require banks to ask for two). SMS fees outside the US are also orders of magnitudes higher – paying a few cents for that can make the entire transaction uneconomical for banks, since interchange rates are also heavily capped in Europe.
- throwaway22032 3y agoCard present and card not present transactions are differentiated.
- lxgr 3y agoThe SMS (or more likely, bank app) confirmation thing only happens for online payments – and if you don't have internet, how are you shopping online? For payments involving the physical card, the chip on the card and your PIN are the two authentication factors required. (Credit and debit cards are PIN-based in the EU; signatures aren't a thing anymore there.)
- SXX 3y agoThis is not mandatory by law though and mostly it's up to merchant to decide whatever they require 2FA or not. AFAIK payment processors like Stripe actually let you make 3DS (and whatever it called for MasterCard / AMEX) mandatory. I guess problem is that in US you'll lose a lot of customers by declining payments without 2FA. Also likes of AMEX use 2FA via email so I guess there could be fraud too.
- lxgr 3y agoIt is required by law (the PSD regulation, specifically) in many circumstances.
- pedrocr 3y agoUnfortunately we didn't use the contactless change to finally fix this. NFC payments are still stuck in the world where the client doesn't have a way to make the payment themselves so has to trust the payment terminal the merchant puts in front of him with their secret information. The transaction should have been reversed. The merchant should have the dumb side, where they only communicate payment details, and the client's phone should be the one doing verifications and initiating the payment. It's bonkers that this hasn't become standard yet. Even more bonkers that internet payments didn't make the same switch long ago.
- lxgr 3y agoThat would have been nice, but not backwards compatible with millions of POS terminals and payment processing setups out there. One big advantage of contactless card payments as implemented in most countries is that you can seamlessly introduce it, making it look like a regular chip or even magnetic stripe transaction to the POS and everything behind it.
- jhugo 3y agoWith the recent new QR systems around Southeast Asia, they got around this by adding support to existing terminals with just a software update. They print out the QR code for the payer to scan. It’s a bit janky, but works until the merchant updates their terminal to one with a screen capable of displaying the QR.
- lxgr 3y agoIt might work for some use cases, but being able to receive a payment is often only part of the story. There's reconciliation, settlement, refunds, tax reporting, handling of/liability for fraud disputes and much more. For example, consider a rental car agency or a hotel reservation. These usually make extensive use of the pre-authorization "feature" [1] of credit cards to reserve a deposit without actually charging it before the final billing amount is known. After a rental car is returned, toll charges are often posted to the card weeks or months after the rental. QR payment systems often don't support these use cases at all (since they're usually payer-initiated and confirmed); and even if they did, chances are that their API semantics are sufficiently different from credit cards as to require significant reworking of the POS and/or backoffice systems of the merchant. [1] It's actually more of a historical artifact of how authorization and clearing/settlement used to, and to some extent still do, run over almost completely independent rails, but for some use cases, this can actually simplify things.
- Retric 3y agoWe’re still using credit cards because they severely limit personal liability. Many CC companies give you the ability to have temporary cards with short term expiration linked to your account. However, there is minimal incentives for you to do so.
- ajmurmann 3y agoThe credit card company and indirectly the vendors carry much off the cost of fraud. The credit card company spends a lot of resources on preventing this fraud. Introducing a proper solution for online payments would allow them to reduce costs and offer better deals to vendors and consumers. They also are the only participant in this who is a individual participant rather than a group. It seems like this is the ideal setup for credit card companies to introduce innovative solutions. They have the incentive and the leverage, yet it's not happening. What am I missing?
- hnburnsy 3y agoYou are missing that the credit card companies want less transaction friction. If they wanted security we would have chip + pin in the US like the rest of the world. Charging volume overrides everything. Interest rates and those that carry a balance more than make up for fraud losses.
- lxgr 3y agoStrong authentication/payment confirmation and strong consumer liability protection are not mutually exclusive. In the EU, card issuers and merchants are required to use 3DS for e-commerce payments and PIN verification for in-person payments in many circumstances; yet chargebacks are still possible.
- photonthug 3y ago> I have had my card locked for traveling within the same city and spending maybe $20 at a merchant I don’t usually visit. I had it locked because of a $5 web service monthly charge - and I had verified the same charge the two prior months. This happens to me almost every time Skype bills me, and I've been a customer for probably 10+ years with both my bank and Skype, and the billing is regular as clockwork. For at least of half of that time, I've complained about it vocally and customer service can't do anything. Now I think about this every single time I hear "AI-assisted fraud detection", and by extension, "AI-assisted security" and really "AI-assisted XYZ". Without another credit card, I guess I'd simply live in constant fear of being embarrassingly declined totally at random on any/every transaction. It's not like I* know the billing cadence, even though my bank has a decade of history. Clearly they are simply selling my history to the highest bidder, because they certainly aren't using it to help me. On a related note, ever notice that vanilla "exact substring match" search even in gmail is just as bad as google web search? All these corporations that are allegedly indexing us to "value-add" with some perfect high-resolution consumer model can't even do basic shit despite all the spying. I almost expect* my privacy to be fucked, like I guess hey that's modernity. What never ceases to surprise me lately is how the pretense has kind of dropped and we get nothing in exchange, even petty conveniences.
- aembleton 3y ago> This happens to me almost every time Skype bills me, and I've been a customer for probably 10+ years with both my bank and Skype Why are you still with that bank? Even if you like everything else about them, couldn't you just open an account with another bank for Skype billing? Having more than one account is helpful anyway for avoiding having a single point of failure where you can't buy anything.
- pnpnp 3y ago> You can blame the evil competitor but the real problem is that credit cards are not the right tool for payments to strangers over the internet. Granted the entire system needs a revamp, but credit cards are one of the best tools we have to pay strangers right now. Credit card money isn’t your money being spent, and comes with a fraud guarantee. I would rather use a credit card than something linked to my money in a checking account for sketchy transactions. Yes, it’s a hassle when the card number inevitably gets stolen, but NFC payments, etc are starting to tackle this. One thing I’ve seen a lot is people misunderstanding credit cards. If you pay them off monthly, you usually get some kind of reward and additionally a huge layer of fraud protection from your personal finances. That being said, I also can’t wait until more secure credit card systems become more prevalent.
- LeafItAlone 3y ago> you usually get some kind of reward What kind of reward? I’ve always paid mine off each month and never gotten a reward on any of my ~15 cards.
- mdhen 3y agocash back? airline points? I would say you must not be American but you said you have 15 cards so I don't know what to think.
- LeafItAlone 3y agoI think it’s possibly your wording that had me confused. > If you pay them off monthly You get the things you mentioned whether or not you pay them off monthly or just pay the minimum and carry a balance. You just have to remain “in good standing”.
- rhn_mk1 3y agoIn much of the world, the "credit card" payment goes through a pre-paid card. Then you're actually putting your own money on the line, and even if there's a guarantee, it's a pain to actually go through the process of invoking it. If this is one of the best tools, then I'm really dismayed at the state of payments around the world. SEPA bank transfers are so much better, even if they have other problems.
- cryptica 3y agoA multi-cryptocurrency payment system would be the perfect solution for online payments but unfortunately nobody has figured out how to solve the double-bullet problem which stands in the way of mass adoption.
- zirgs 3y agoCentral banks are preparing to launch the digital euro and the digital dollar. Cryptos had their chance and they blew it.
- maccard 3y agoNo, it's really not. As a buyer I don't want irreversible transactions to someone anywhere in the world, I want something that if the seller isn't acting fairly (items not as described, not shopping orders, etc) I can lean on to get my money back.
- LeafItAlone 3y agoWe use CC because the infrastructure is there and there is legally mandated (depending on jurisdiction) fraud protection. When you pay with CC, the issuer is potentially on the hook for fraudulent payments, so they are incentivized to provide the protections. And of course there are many that use CCs for the purpose of a loan to purchase items they can’t currently afford.
- Mordisquitos 3y ago> Every time I do a CC transaction I’m giving a stranger exactly the information they need to do an entirely different, arbitrarily large CC transaction in my name with any merchant. That’s bonkers. You may be surprised to know that, when doing a "conventional" CC transaction, you are most certainly not giving any stranger information that would allow them to perform a transaction in your name on another merchant. What you are doing is providing your card information to a PSP (payment service provider) that has been contracted by the merchant and will provide the merchant with a token with which the merchant can trigger a charge request to your card but only to their own pre-approved acquirer account. The merchant can do nothing else with these tokens. A breach of the merchant's token database would be embarrassing but harmless. A breach of the PSP's database of card numbers would be bad and inconvenient for the cardholders, sure, but it would be a business-terminating event for the PSP as its PCI DSS [0] compliance would be shattered and it would be unable to operate again. In summary, ordinary card payments are essentially as secure as Apple Pay. The only difference is that in one case you are trusting a gigatech brand which is very saliently involved in the process but whose side-business in payments has only operated since 2014, while in the other case you are trusting businesses that you may or may not have ever heard of —Adyen? Braintree? WePay? Worldline?— but that have probably been dealing with secure payment processing as their primary or only business for much longer. [0] https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec...
- TheHappyOddish 3y agoThis is correct and the GP is (confidently) talking nonsense. However the big issue is most normal users would not have the ability to see if they're using an embedded iframe or cross origin JS from Stripe, Braintree, etc.
- erremerre 3y agoHe is not talking no-sense. He is talking what he perceives as a user. the same way that when you get a refund, you dont see the money back immediately. What the user doesn't know is that when you pay a business, the same thing happens, and the business don't get the money immediately. And to pay by credit card feels much more insecure than using paypal or amazon pay, even if it isn't.
- floomk 3y agoThat's why 3D secure exists: https://en.wikipedia.org/wiki/3-D_Secure https://en.wikipedia.org/wiki/3-D_Secure Blame your government for not caring enough to have it implemented
- Aleklart 3y agoBlaming certain government can get you banned not only from facebook but from real life altogether.
- sersi 3y agoI hate 3D secure, it's a way for banks to move the liability and inconvenience to me, their customers. In most implementation, I need to wait for an sms, often that sms takes ages to come. Then there's a bit of a monopoly with 3d secure implementation by cardinal.js and their solution falls down completely if you have a decent amount of traffic on the site (I have worked on flash sales websites, cardinal js is about as reliable as I can throw my car)
- mschuster91 3y ago> Why are we still using credit cards? It’s not great as a consumer either Because the big networks (Mastercard and Visa) as well as the issuer and acquirer banks spend insane amounts of money on advertising and lobbying - even in the EU where payment fees are capped, the cap on CC fees is notably higher than on debit card/SEPA fees, so there is a clear incentive for everyone in the chain to push for credit cards. Additionally, issuer banks make a ton of money on interest which means they have even more of an incentive to push for CC usage.
- didntcheck 3y agoAnd also this reliance on a few payment providers causes the same type of problems as this business have with Google - big businesses trampling yours on a whim, with no real recourse. The problem is actually far worse with payment processors, who are increasingly taking it upon themselves to be an unelected worldwide morality police, deciding which types of commerce shall be legal with their own de facto law
- JamesLeonis 3y agoI've talked about this before [0], but tl;dr - American banks operate worldwide, and since they are subject to US laws, worldwide banking is de facto under US jurisdiction. > The banks operate under a laundry list of laws outside of a criminal conviction, such as the Terrorist watch list as well as whole countries that are under US sanctions. US sanctions are a particularly large bite because the US will sanction you from the US financial system for working with the above, even if you are not under US jurisdiction. > This, of course, doesn't mention the all the reporting used for detecting tax evasion or money laundering. > US banks are absolutely a wing of the court by operating under the given rule of law, and through the US banks' worldwide influence this 'rule of law' gains a global prominence. [0]: https://news.ycombinator.com/item?id=28820330 https://news.ycombinator.com/item?id=28820330
- patall 3y agoIs it? My bank accounts in two European countries have in the last year transitioned from Visa Credit Cards to Vise Debit cards. Because the banks in both cases wanted about 2.5 euro per month for something that does not provide any value to me. Unfortunately Visa Secure seems to be changing its validation mechanism every 3 months though, which each time is super annoying.
- BillinghamJ 3y agoAlthough you're right that Apple Pay is cryptographically verified, you may be surprised to know these two things: 1. you can charge any amount - the amount shown in the Apple Pay UI is arbitrary 2. you can make multiple charges, also of any amount (e.g. for a subscription) It is tokenized, but practically it's just a card number you can charge like any other card number. It's also typically linked back to the original PAN, so multiple payments can be correlated together with ease
- shuckles 3y agoYour payment processor and the network has to trust you if you're reusing the Apple Pay cryptogram for a subscription payment. You _can_ do anything (e.g. you can represent yourself as an open loop transit network reader and get a card number without any authentication from express mode cards!), but the network will not allow you to succeed doing that for very long, if at all.
- JohnFen 3y ago> Why are we still using credit cards? Because they're accepted by pretty much everybody and nobody has come up with a system that is any better.