Live data from Hacker News

Europe's $24T Breakup with Visa and Mastercard Has Begun

europeanbusinessmagazine.com

541–550 of 1001 posts

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#541

Earlier quoted context omitted.

> you work on mobile apps you will notice that full attestation is too slow to put in the login path Hm, Play Integrity isn't that slow on Android, from my experience. > don't think a good security engineer would rely on atty as "front line" anti brute force control since bypasses are not that rare I'm not privy to device-wide bypasses of Play Integrity that ship with Trusted Execution Environment (which is pretty mu…

> I'm not privy to device-wide bypasses of Play Integrity that ship with Trusted Execution Environment (which is pretty much all ARM based Androids), Secure Element, and/or Hardware Root of Trust, but I'd appreciate if you have some significant exploit writeups (on Pixels, preferably) for me to look at? Hi, you don't have the break the control on the strongest device. You only have to break it on the weakest device t…

We can only hope they continue to be found so there would at least be a small cost for this kind of indignity.

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#542

Earlier quoted context omitted.

What does Belgium's capital has to do with this? Do you imply Brussels = European Union?

It is called a metonymy where you substitute a name that is associated to some other thing instead of mentionning that thing. Some examples: Wall Street = NY Stock Exchange the White House = US president and his cabinet the Pentagon = US Dept of Defense Downing Street = UK prime minister https://en.wikipedia.org/wiki/Metonymy Scotland Yard = Greater London Metropolitan Police Tehran = Government/officials of the isla…

As a person who lived for a long time in a political capital I was so frustrated with news articles titled like this.

"[City] decides [XYZ stupid thing]!!!"

No! We in the city didn't decide it - our responsibility is limited to our political representative. Everyone else voted in idiots and sent them here to decide idiot things!

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#543

> neither Visa nor Mastercard will sit idle while Europe tries to dismantle their most profitable market. Earnest question: is the EU really Visa and Mastercard's most profitable market? I would have expected it to be the US, both by customer volume numbers and in terms of regulatory environment (i.e. the US allowing payment processors to take a larger cut).

Speculation: Europe has a lower risk management cost than the US when it comes to card transactions, making it more profitable.

Smartcards with PINs were ubiquitous much much sooner (it being a French idea did not help for US market penetration), which means today the magnetic stripe on our cards is little more than decoration. Seriously, I'm 29 and I've yet to see a single magstripe payment here (while it was daily when I went to the US).

Also, we pretty much only have debit cards (don't know why, but don't know why I would want a credit card). This is even less risk for both the network and the merchant and the bank, reducing issues for all links in the chain.

Or the fact that Europe has 100M extra people in it, and a lot of countries seldom use cash nowadays.

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#544

Earlier quoted context omitted.

> important security measure It's a security measure against the owner of the device , in other words, an attack. Would you be okay with me using a remote control to forcibly slow down your car so I can merge? Using attestation this way is fundamentally incompatible with ownership. If the bank wants some assurance about a device, they need to sell or issue one to me, like credit cards or point of sale machines, which…

>against the owner of the device Would you consider MFA to be a measure against you, the owner of the device, because it makes it harder for you to login? >If the bank wants some assurance about a device, they need to sell or issue one to me They are offering you free software and are operating under a security model tied to these specific devices. You're still free to walk into their branches, or use their physical…

> Would you consider MFA to be a measure against you, the owner of the device, because it makes it harder for you to login?

In theory - of course, it shouldn't make it any harder for _me_ to login, it's just that in practice the friction is inevitable since it can't distinguish between me and someone else without it.

> You're still free to walk into their branches, or use their physical cards, if you prefer not use their limited selection of devices.

The point is that this freedom is going away. I'd absolutely want to use their physical cards (there are smartcards with e-ink displays which would be a great thing for confirming payments), but no, they're slowly taking this away, starting by limiting transfers done without their mobile app.

And _their_ mobile app needs to invade __my__ property by locking down the system. I understand this might be neccessary to ensure the UI can be trusted, but this shouldn't happen on my device as it restricts my ability to do completely unrelated things.

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#545
post #168

Earlier quoted context omitted.

Just use wise or revolut.

"Just" get another bank account before travelling. Right...

I meant that as more of a long term solution. Even if your domestic bank supports overseas payments, they most likely screw you on the fx rates, so just get a specialised card like Wise or Revolut.

It's free, their tech is great and their fx rates are more than fair.

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#546

Earlier quoted context omitted.

Just by their nature, that is inherently untrue. If your CC is stolen, you are not out all the cash in your account until the dispute is resolved. If your debit card is stolen, you lose that cash, making it more difficult to pay whatever other obligations you have that period.

In Europe your liability for Card Misuse is capped at 50€ for things that happened before you blocked it. Also how would someone misuse it? You need a PIN Code for every transaction anyway, and the EMV Chip can't be cloned like Magstripes. Online Payments need a mandatory 2 Factor Authentication

I have always heard that the 2fa verification really depended on the vendor actually doing that auth so I always scrape the 3 verification number (what is it for anyways ?) at the back of my card. It's just 3 numbers after all.

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#547
post #324

Earlier quoted context omitted.

Visa and MC have basicly all of these configurations, depending on country & legislation: - Direct Debit - Deffered Debit - Rolling Credit - Installment Credit And if you are a $MegaBigCorp customer of them, you can customize even more.

indeed. my credit card requires me to preload money from my bank account. it's like there is a second account that keeps a balance that i can spend using the credit card. whenever i use it, the balance is updated. how the credit is paid off i don't know. it could be either right away, or the amount is just hidden by my bank until it is time to pay off at the end of the month. either way, the credit limit is zero. so…

So, your credit card is in practice a debit card?

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#548
post #324

Earlier quoted context omitted.

Visa and MC have basicly all of these configurations, depending on country & legislation: - Direct Debit - Deffered Debit - Rolling Credit - Installment Credit And if you are a $MegaBigCorp customer of them, you can customize even more.

indeed. my credit card requires me to preload money from my bank account. it's like there is a second account that keeps a balance that i can spend using the credit card. whenever i use it, the balance is updated. how the credit is paid off i don't know. it could be either right away, or the amount is just hidden by my bank until it is time to pay off at the end of the month. either way, the credit limit is zero. so…

that is not a credit card :)

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#549

Earlier quoted context omitted.

This isn't about the payment network. The EU already has their own payment network, too. It's about card payment and even if things ending up in your network they first going through visa. And it's about online payment (PayPal).

A lot of European online stores support asynchronous SEPA transfer. You complete your order, they issue a code and amount of money to send. You send the money with that reference code attached and they don't ship it until they get the money. It works for online order because you might be waiting a week anyway.

yes, but in many cases that is because this payment method predates "modern" online payment and they "just kept it around"

depending on what you buy "a lot" can be close to non or close to all

In the end it has major issues:

on the consumer side

- majorly reduced consumer protection compared to e.g. pay pal. If you wire transfer by yourself doing charge backs ~two weeks later after not getting the goods is hard, potentially non-viable (dep. on country etc.).

- you can typo address or reference number, leading to a lot of headaches (also recently they changed it so that the recipient "name" has to be correct, but many companies send you only IBAN,BIC,ref number and not the exact by letter company name under which the bank account operates...)

on the seller side (sometimes also affecting consumer)

- the order is in a "in-between" state until they receive the money, which can be days. During that time they can't rely on actually receiving the money but they also have to keep the good ready to sell. Especially in situations where you e.g. sell limited time/amount goods (e.g. resellers, collector goods etc.) this can be a pain. If you then add any form of expiration data (e.g. concert ticket) this can make the payment method a absolute no-go.

- your selling/order processing system needs access to your companies incoming transaction history, which preferably should be a separate account. This mean additional administrative overhead and failure conditions. Also many such systems are kinda build crappy in my experience.

while I have been using that in some situations it really isn't competitive as a modern online banking solutions

but what it also shows is that you can get really far with comparably "dump/naive" methods.

----

Also for completion there is one additional SEPA method: That is you give the company the right to just take money from you bank account. You can split that into 2 versions: 1) permission for fixed amount reoccurring payments (e.g. donations,subscriptions) 2) arbitrary amounts at arbitrary times. The later requires a relatively high burden/overhead on the sellers side so you only see it with Amazone or Paypal

Re: Europe's $24T Breakup with Visa and Mastercard Has Begun

#550

I always find it entertaining to hear people try to argue that what these companies do is soooooo difficult and that's why they're valuable. It's just multiple computers keeping a balance. It's not complicated. No, these companies keep themselves in power not because they've solved such a difficult problem that nobody else can, but because they have a moat which they protect. Time to do away with these foreign entiti…

I very distinctly remember a dev talk at early 2000s Microsoft where a distinguished engineer recently come to MSFT from VISA described the herculean effort that it took to run this network. There was an anecdote that he shared that stuck with me where they had a worldwide daily balance mismatch of something like 0.37 cents and it was all hands on deck to find the missing thing. Yeah, man, it is very difficult to run these networks, hence so much money in it.
Post reply on HN