Live data from Hacker News

Verified by Visa and Mastercard SecureCode are broken and need to be fixed

cxpartners.co.uk

11–20 of 64 posts

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#11

Every now and then when I purchase something from a Verified by Visa-"friendly" site (Newegg comes to mind), I often find that I'm able to complete the purchase without entering my password. It's disturbing to say the least.

I recall creating my password for Verified by Visa, but never successfully entering it again. It's never stopped me from getting the goods and getting charged, though.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#12
VbV is badly broken, but the suggestions here miss one of the most important points. The use of an iframe means that users can't tell where VbV is coming from and can't be sure either that it is secured or that it's really coming from the bank.

This is just begging for copycat phising and MITM attacks.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#13

Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…

What happens if I book a flight at a badly infected internet cafe computer in Chiang Mai and a key logger reads my password

Does VbV make this any worse? It's very difficult to protect against (other than "never use untrusted computers").

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#14

Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…

That is, in fact, the exact opposite of how the banks operate. You are limited to $50 in liability for any fraudulent transaction in your account that you report in a timely fashion, guaranteed by law (in the US at least), and every bank I am aware of waives the $50 for marketing purposes.

Essentially all financial risk for credit card transactions is borne by the merchants. (Which is one reason why the banks don't seem to do much about fraud -- why should they inconvenience their customers to protect someone off of the balance sheet who doesn't get a choice to not use their bank?)

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#15
post #14

Even though there's no choice (here at least, when you want to use your Visa over the internet) I HATE, HATE, HATE the concept and here's why: For starters I thought it's a phishing attack, when the frame popped up for the first time. But the worst is that I don't feel it protects me, despite the marketing crap dished out by CC companies. The only reason is to protect Visa. What happens if I book a flight at a badly…

That is, in fact, the exact opposite of how the banks operate. You are limited to $50 in liability for any fraudulent transaction in your account that you report in a timely fashion, guaranteed by law (in the US at least), and every bank I am aware of waives the $50 for marketing purposes. Essentially all financial risk for credit card transactions is borne by the merchants. (Which is one reason why the banks don't s…

While we are in public-service-announcement mode: I believe that the above protections are still a lot smaller for debit cards than credit cards. You still have $50 limit on liability with debit cards, but you must report the theft very quickly indeed and the thief is emptying your personal account in the meantime:

http://banking.about.com/od/checkingaccounts/a/stolendebitca...

This is why I never use a debit card for anything.

We now return you to your regular HN programming.

Re: Verified by Visa and Mastercard SecureCode are broken and need to be fixed

#16
3DS being broken was known long before 3DS was finalized. It's not new. However, it's successful because of the security it brings to merchants. Merchants implement it because they get covered. It's the perception of security that works.

Until 3DS implements some out-of-band authentication, you won't have something secure. Implementing OoB auth isn't difficult, either. The technology has been around for a LONG time, with proven results.

Post reply on HN