Verified by Visa and Mastercard SecureCode are broken and need to be fixed
1–10 of 64 posts
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#2For starters I thought it's a phishing attack, when the frame popped up for the first time.
But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa.
What happens if I book a flight at a badly infected internet cafe computer in Chiang Mai and a key logger reads my password?
"No, Mr. Zapp, our logs show irrefutable proof that your password was typed with suchandsuch transaction. Sorry, you're liable, you obviously didn't protect the password."
Scary stuff.
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#3I agree this is an awful user experience, at a time where the trend in payments is to make the user's experience better this is a huge step back.
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#4Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#5Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…
It's unfortunately obvious that the CC companies are pushing this as hard as they can, with no concern for customers, banks or merchants. :-/
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#6It is already really hard to teach casual computer users about security online. The one thing that used to work so far was "never enter your password on a website you've been redirected to" and "always check the site's identity in the address bar". Verified by Visa redirects you to some website on some random server and asks you to enter your password. There is no way for the user to check it's authenticity.
A much more reasonable design would be to control all sales via your bank's website, i.e. having an inbox with "purchase requests" and approving them through your bank's interface. That would be both secure and very transparent to the user, and the bank could easily control the level of security required (passwords, TANs, ...).
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#7It's disturbing to say the least.
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#8Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#9An additional problem with the implementation is that it requires javascript. I was working on a project for a UK bank - their security guidelines required securecode, but their accessibility guidelines required that the site work without JS. Sadly achieving the two is impossible. I agree this is an awful user experience, at a time where the trend in payments is to make the user's experience better this is a huge ste…
Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed
#10There doesn't ever seem to be a permanent opt-out, so anytime I want to buy something from a merchant that uses it, I have to hunt for the magic button to get around it again.