6 ms·
Not square at all, this is a fundamental problem with credit card processing. As long as the costs of fraud are borne by the individual merchants I doubt it wi
by pkteison 13y ago
Not square at all, this is a fundamental problem with credit card processing. As long as the costs of fraud are borne by the individual merchants I doubt it will be fixed. Fundamentally flawed system design / perverse incentives.
To the best of my knowledge, anybody taking a credit card will lose a chargeback if they don't have a signature. And you never have a signature in an ecommerce transaction, so you will lose all disputes. (I know the very large company I used to do the CC processing for routinely lost our chargebacks for ecommerce transactions, and at our volume we should have been able to find a system for not losing if one could be found.)
The only current "solution" is to do a good job of filtering up front and rejecting suspicious transactions, which can be helped by requiring AVS and CVV2 matches and phone calls for large orders - but there isn't really a good system for handling this at all. The best I've seen so far is a company that would verify new customers by calling and asking them a question about their neighborhood from google maps. And it's a shame that each individual merchant has to come up with something convoluted like this, and the payment processors don't provide technical help or financial guarantees for the transactions they authorize. But that's just how it is right now, and it isn't Square's fault.
- Silhouette 13y agoTo the best of my knowledge, anybody taking a credit card will lose a chargeback if they don't have a signature. It's not quite as simple as that. The customer authentication problem is what programmes like MasterCard SecureCode and Verified by Visa are supposed to solve. The trouble is, their implementations are so clunky that a lot of merchants/payment services don't use them, which in turn means a lot of end customers don't expect or understand them either, damaging legitimate conversions. I've heard that they are also not widely used in the US for whatever reason(s), though they're somewhat common here in the UK now. In theory, these mechanisms should fix much of the underlying weakness in the current card payments model, because the end customer never gives the extra security information to others, only to their own bank/card provider. And there really are (or at least were the last time I checked) payment services that will eat the fees for chargebacks on transactions that were authorised using these kinds of 3-D Secure mechanisms given reasonable evidence that the merchant did provide whatever was being paid for. Unfortunately, I'm not aware that any of the new generation of online payment services offers 3-D Secure yet, which I expect to become a significant headache for them as more horror stories like the one we're discussing here come to light. As a point of interest, much the same arguments apply to two-factor authentication schemes for cardholder present transactions, such as Chip-and-PIN, which has been almost universal in the UK for a long time now but again doesn't seem to have had as much take-up in some other countries. It's normal to consider a PIN-authenticated transaction at least as safe as one confirmed with a written signature. But again, these technologies don't seem to be universal in some other countries yet for whatever reason(s).
- ArbitraryLimits 13y ago> As long as the costs of fraud are borne by the individual merchants I doubt it will be fixed. Fundamentally flawed system design / perverse incentives. Sure, but be sure to empower consumers against the banks if you make the banks liable instead. I've always found this case study from the classic "Why Cryptosystems Fail" fascinating: In some countries (including the USA), the banks have to carry the risks associated with new technology. Following a legal precedent, in which a bank customer's word that she had not made a withdrawal was found to outweigh the banks' experts' word that she must have done [JC], the US Federal Reserve passed regulations which require banks to refund all disputed transactions unless they can prove fraud by the customer [E]. This has led to some minor abuse - misrepresentations by customers are estimated to cost the average US bank about $15,000 a year [W2] - but it has helped promote the development of security technologies such as cryptology and video. In Britain, the regulators and courts have not yet been so demanding, and despite a parliamentary commission of enquiry which found that the PIN system was insecure [J1], bankers simply deny that their systems are ever at fault. Customers who complain about debits on their accounts for which they were not responsible - so-called `phantom withdrawals' - are told that they are lying, or mistaken, or that they must have been defrauded by their friends or relatives. The most visible result in the UK has been a string of court cases, both civil and criminal. The pattern which emerges leads us to suspect that there may have been a number of miscarriages of justice over the years. * A teenage girl in Ashton under Lyme was convicted in 1985 of stealing £40 from her father. She pleaded guilty on the advice of her lawyers that she had no defence, and then disappeared; it later turned out that there had been never been a theft, but merely a clerical error by the bank [MBW] * A Sheffield police sergeant was charged with theft in November 1988 and suspended for almost a year after a phantom withdrawal took place on a card he had confiscated from a suspect. He was lucky in that his colleagues tracked down the lady who had made the transaction after the disputed one; her eyewitness testimony cleared him * Charges of theft against an elderly lady in Plymouth were dropped after our enquiries showed that the bank's computer security systems were a shambles * In East Anglia alone, we are currently advising lawyers in two cases where people are awaiting trial for alleged thefts, and where the circumstances give reason to believe that `phantom withdrawals' were actually to blame. Finally, in 1992, a large class action got underway in the High Court in London [MB], in which hundreds of plaintiffs seek to recover damages from various banks and building societies. We were retained by the plaintiffs to provide expert advice, and accordingly conducted some research during 1992 into the actual and possible failure modes of automatic teller machine systems. This involved interviewing former bank employees and criminals, analysing statements from plaintiffs and other victims of ATM fraud, and searching the literature. We were also able to draw on experience gained during the mid-80's on designing cryptographic equipment for the financial sector, and advising clients overseas on its use.