Live data from Hacker News

How India's banks killed the future of commerce

blog.cleartrip.com

11–20 of 60 posts

Re: How India's banks killed the future of commerce

#11
I have stopped using credit cards online for over a year, prefer online banking based payments, because it is one username and 2 passwords(authentication, transaction)

I dont like 2 factor authentication, especially with mobile/sms, when I am abroad or travelling, I still can do my transaction

Re: How India's banks killed the future of commerce

#12

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

India is generally conservative about financial issues.

In this case, it puts them on the wrong side. But their conservative approach also shielded India from the banking crisis experienced by US etc.

From http://www.nytimes.com/2009/06/26/business/global/26reddy.ht...

“If America had a central bank chief like Y. V. Reddy, the U.S. economy would not have been such a mess,” Joseph E. Stiglitz, the economist and Nobel laureate, has said.

Re: How India's banks killed the future of commerce

#13
post #6
post #2

It seems to me like it was the government that started the whole mess.

It usually is :) but cleartrip might just be right here to blame the banks. Asking for more secure authentication is a good idea, particularly in India where on more than one occasion, I've had to stop people from writing down my credit card number for "the record". That transaction volumes decreased on the /first/ day 3-D secure (and now, the one-time password) was implemented is hardly surprising, but I think once…

I agree with your point I have found it hard to prevent merchants from writing down credit card numbers(!!!) and these additional layers of security are needed for the market. On the contrary, though I am a regular user of credit / debit cards for online transactions in India - atleast 3-5 times a month, I have found it really hard to use my credit card from the beginning of the month since they introduced the one-time-password.

I have not been able to use my credit card even once since this was introduced due to various reasons - the SMS service that banks are supposed to deliver One-Time-Password is not sent promptly or I do not have a way to get password to authorize even an IVR transaction in time.

It might all work out after initial issues are resolved but so far I find this to be a pain.

Re: How India's banks killed the future of commerce

#15

Notice how they made the post on Feb 14, but show only data for Feb 1. Is it really surprising that the first day with the new system saw fewer transactions? Making claims that this move "permanently hobbles India's mobile commerce" based on evidence like this is surely unwarranted. I really think 3D secure is a good move. All it requires is entering your internet banking password at the time of making the transactio…

NO - 3D secure is not good for the customers. the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")

I think all your points are valid, but they're referring to a different problem - which is how get control back from the banks to the customer about chargebacks. This problems wasn't introduced by 3D secure, it was always there and it was always just as bad. If you want to replace 3D secure with something that's better, I'm all for it, but this post implies that we should get rid of it as well.

Re: How India's banks killed the future of commerce

#16
India's systems are generally not designed for the "new entrants" and most of the incumbents design the system with walled gardens to protect themselves.

For a startup like us who have a web based software like basecamp, there is no way we can charge subscription services. Infact no payment gateway exists for us to take credit card payments from Indian customers.

Thanks to PayPal, we can serve international customers much easily. I have a lot of anger against the people who run India's large services as if its an entitlement, without caring for the new entrants.

Re: How India's banks killed the future of commerce

#17

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

> IIT students were arbitrarily limited in the number of hours they could spend online because some administrator thought they should get out more

Wow, I didn't believe you at first, but it appears to be true. [1][2][3]

They appear to be justifying by claiming, besides that it prevents them from meeting others, that it somehow causes suicide and depression and that it is responsible for falling grades.

Does anyone know if this is still in effect? The most recent article I could find is from 2008.

[1] http://timesofindia.indiatimes.com/city/delhi/IIT-D-follows-...

[2] http://educational-newsflash.blogspot.com/2010/11/restrictio...

[3] http://vikashkablog.blogspot.com/2007/01/internet-ban-in-iit...

Re: How India's banks killed the future of commerce

#18

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

About the SMS limitation - you got it wrong here, the limit is for sending SMSes with the same text and definitely not for receiving them. There's no limit on the amount of normal SMSes (with different content) you can send in a day.

I think that's a pretty good move, spam SMS is turning into a huge problem here.

Re: How India's banks killed the future of commerce

#19

Notice how they made the post on Feb 14, but show only data for Feb 1. Is it really surprising that the first day with the new system saw fewer transactions? Making claims that this move "permanently hobbles India's mobile commerce" based on evidence like this is surely unwarranted. I really think 3D secure is a good move. All it requires is entering your internet banking password at the time of making the transactio…

NO - 3D secure is not good for the customers. the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")

Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.

Re: How India's banks killed the future of commerce

#20
post #6
post #2

It seems to me like it was the government that started the whole mess.

It usually is :) but cleartrip might just be right here to blame the banks. Asking for more secure authentication is a good idea, particularly in India where on more than one occasion, I've had to stop people from writing down my credit card number for "the record". That transaction volumes decreased on the /first/ day 3-D secure (and now, the one-time password) was implemented is hardly surprising, but I think once…

Interesting to learn. Thanks!
Post reply on HN