> Now instead of acquiring N numbers, the hacker needs to acquire N+3 (or N+4) numbers
This seems almost as reductive as suggesting my mechanic should keep her customers' key(k) in their cars(c) in her parking lot because instead of just acquiring c, now the thieves just need to acquiring c+k.
If we were talking about 3 extra digits on the card number, that would be one thing. But we're talking about a separate authentication factor, which seems pretty worthwhile to me. Getting that info isn't exactly a snap if you don't just find it laying around-- it's not like you can brute force it. I'd be pretty astonished if a credit card company didn't cancel someone's credit card if someone was tried a handful of transactions with random security codes, let alone enough to guess one number in a thousand.
Sure, there are undoubtedly better ways to handle these transactions, but lacking magic wands to change a giant dinosaur of an industry that should have wanted to change on its own, this is a prudent policy-based strategy to mitigate harm. Whether or not you sweat these breaches is a good way to gauge your own processes, but it's not a useful way to gauge industry-wide processes.