3 ms·
This sounds like more of an issue with our card payment systems rather than individual merchants. All it takes is 16 digits to fraudulently use somebody else's
by ROFISH 13y ago
This sounds like more of an issue with our card payment systems rather than individual merchants. All it takes is 16 digits to fraudulently use somebody else's money and the merchant is typically liable in case of that. And to add insult to the injury, they add a $20 chargeback fee on top. The banks and processors aren't taking responsibility and instead forcing merchants whose core focus is on selling and shipping rather than the intricacies of payment handling.
Due to this lopsided arrangement, banks and processors have no reason to change the system. We should force them to take the risk of fraud; it's the only way to make the system better for everyone.
- keithpeter 13y agoIs it not 16+3, the code on the back of each credit card? If not, why not?
- dangrossman 13y agoThe exact number of digits you need to know isn't relevant. The problem is that you can spend someone else's money just by knowing their digits, the recipient is expected to reject that money if it's not your digits, but is given no way to truly verify identity or ownership.
- Silhouette 13y agoThe problem is that you can spend someone else's money just by knowing their digits That's part of it. The other parts are that unlike a PIN or password, people routinely tell others what those digits are, and that the system works as a pull (the merchant decides when to collect the money and informs the customer's bank via the payment processing system) instead of a push (the customer decides when and where to send the money and informs their own bank). Most of the problems with security, fraud, chargebacks and related areas in the card payment industry ultimately start from this fundamentally flawed model.
- latj 13y ago"The exact number of digits you need to know isn't relevant" The number of digits doesnt matter but CVV vs. no CVV does make a difference. CVV is the way to verify that you are allowed to use the given credit card number (its actually the second V in the initialization). CVV is completely separate from the way the credit card number is generated. If someone else has your card number and CVV it implies: Either your numbers were stolen directly from your card or your information was stolen from some third party server. If your information was stolen from, say a merchant's server, it implies that they did not properly encrypt your credit number and that they stored CVV which should not even be in their database to begin with.
- tghw 13y agoWith traditional merchant accounts, it's up to the merchant how much they check. As long as the 16 digits are correct, the processor will process the transaction. All of the other data (CVV, exp date, name, address, etc.) is optional.
- amerkhalid 13y agoAt our company, we use Authorize.net. Auth.net has something called Address Verification System[1]. I think it just matches zip codes but I might be wrong. If we get AVS check fails on billing address, we automatically reject the order. If AVS check passes but shipping address is different and based on some other criteria like order history, order amount; we have someone double check on the order. I think every merchant should implement these basic checks. Not sure if it is possible with Square but I would assume they do provide something similar. [1] http://en.wikipedia.org/wiki/Address_Verification_System http://en.wikipedia.org/wiki/Address_Verification_System