3 ms·
Walk me through an example here. I'm a telemarketer who calls you up, sells you on something, and charges your card. What changes in that scenario?
by wpietri 2mo ago
Walk me through an example here.
I'm a telemarketer who calls you up, sells you on something, and charges your card.
What changes in that scenario?
- epolanski 2mo agoYou can't charge nobody's card because in order to do so you'd first need to sign a verbal contract.
- wpietri 2mo agoAgain, please explain the details of what you're thinking. If I get a card number, type it into my POS system, collect money, and send you a product, who's going to stop me?
- vntok 2mo agoWait, am I getting it right you're talking about collecting a prospective customer's card number and CVC over the phone, and then typing it yourself in a third party system? Then it's trivial to settle: that's the big bad PCI DSS violation mouthful, so two to three things will happen. One, the customer's bank will reimburse them as soon as they complain that they have not authorized the fraudulent transaction that appears on their account. Product being sent, received, sent back, etc has no bearing on this. Two, you will be audited, fined $xx,xxx monthly and/or perhaps even get banned from the PSP layer. Again, sending real products has no bearing in this. Three, well the customer's own bank will be in touch pretty soon with yours to "settle things", as banks don't particularly like to advance reimbursements to their clients for fraudulent transactions. Hope you weren't using your own bank as a PSP as they kept receipts of everything you were doing (they just weren't looking until now).
- wpietri 2mo agoWe're not talking about fraud, we're talking about telemarketing. The case you describe is correct for fraud, but doesn't need any new law making "void and nulls contracts made by phone". That being epolanski's proposed fix for telemarketing.
- vntok 2mo agoWell you were the one talking about "If I get a card number, type it into my POS system, collect money". A PCI DSS violation is indistinguisable from fraud. If you collect random credit card numbers and then transact on them, you'll be harshly punished. Actually providing a service on the side of the fraud does not make the fraud disappear. The proposed fix to make contracts established over inbound calls void is useful as a guide for the public to clearly know their rights. And if a company still chooses to collect a payment over the phone, now that's not only a PCI DSS violation but also a theft because money changed hands from an individual to a company without a valid contract.
- wpietri 2mo agoI was talking about it in the context of a conversation with someone else, one easily available to you. It is frustrating to have someone not only give an irrelevant reply but then double down on the misunderstanding.
- epolanski 2mo agoYou can't ask for this data over phone, you can't pay over phone.
- wpietri 2mo agoI obviously can. I can call anybody and ask them for all sorts of stuff. I'm asking what, in your proposed world, would stop me.
- everforward 2mo agoI’m not endorsing the idea, but we could ban printing the card number on the card. New cards would only have a CVV, chip, mag strip and some way to differentiate between 2 cards from the same company (a colored dot?). The info would still be on the mag strip, but the vast majority of people would be unable to pay over the phone anymore. Or the internet.
- RiverCrochet 2mo agoI report the fraud to my card company. The card company reverses the charges and purses action against the fraudster if possible. The card company then tells me that because contracts made over the phone are null and void, using the credit card to make purchases over the phone is not allowed and doing it again will result in my account being closed or a penalty fee being assessed. The long term effect may be that credit card companies stop supporting remote transactions that don't use biometrics+attestation or the physical card.
- JumpCrisscross 2mo ago> report the fraud to my card company. The card company reverses the charges This already happens almost reflexively. > long term effect may be that credit card companies stop supporting remote transactions that don't use biometrics+attestation or the physical card Then I drop that card and switch to a competitor who doesn't do this.