Live data from Hacker News

A simple solution to credit card fraud, and why you won't see it any time soon

blog.rongarret.info

41–50 of 130 posts

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#41
post #36
post #32

Earlier quoted context omitted.

You are being downvoted because it is generally understood that there are indeed rather serious consequences for victims of credit card fraud[1]. If you have a viewpoint that is polar opposite to how everybody else understands something, maybe it's your obligation to explain it better. And saying that you're in some form of authority to speak about the subject isn't an explanation. [1] http://en.wikipedia.org/wiki/Cr…

Updated: Apologies, I see now that the original comment specifically states there are no victims, period... even merchant victims. Incorrect. There are no serious consequences for the victims of credit card fraud (unless you consider the victims to be the merchants). When fraud takes place, the credit card company removes the bill from your statement. Then they take the money back that they sent to the merchant. The…

He was very explicit in saying, multiple times, that his assertion was true for any definition of victim. It's easy to show that the victim of credit card fraud is typically the merchant, not the consumer.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#42
What are the downsides of making the CVV on your card have to come from a txt message to your phone? It seems like this could piggyback on the existing system that exists and would work with all current implementations. (It doesn't solve the subscription stored card problem I guess...)

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#43
post #37

Earlier quoted context omitted.

The merchants are the victims, and the consequences include lost payments, lost merchandise, chargeback fees, lost cashflow when the merchant account provider starts requiring a risk reserve, and lost cashflow when their account gets terminated for exceeding the acceptable chargeback ratio. It can even lead to loss of the entire business. How is that not a consequence of credit card fraud?

This is true, although I think most people generally assume the "victim" in the case of credit card fraud is the individual whose card number is stolen.

parent poster said "any definition of victim"

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#44
The "solution" to credit card fraud is monitoring and insurance.

I don't worry about credit card fraud because my credit card company does not hold me responsible for fraud as long as I bring it to their attention in a timely manner (30 to 60 days). So I just make sure to review my statements every month.

Yes, in a general sense I pay the cost of this insurance because all businesses are imaginary pass-through entities. By that standard, let's not tax businesses either since we ultimately all pay those taxes too.

But, complex technical solutions ALSO have a cost--not only to implement and maintain, but in the friction they introduce into the commerce of everyday people's lives. And since businesses exist to minimize costs, we can assume that they have not implemented complex technical solutions because they cost more than the insurance.

In summary: not every optimal solution exists in the space of engineering. Social and legal structures can help solve problems too.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#45
post #22

I've thought about this "problem" and decided there's no problem. You're solving a non-problem if you try to solve credit card fraud. The reason we don't deal with credit card fraud is that there are no consequences for being a victim, for any definition of victim. If the victims had consequences, then there would be demand for action. But there is none. Further, because there are no consequences, the cost to solve c…

While others have talked about the merchant as victim, it should be noted that the individual whose card is stolen and used also are victims. This is esp. true for folks who work multiple jobs or have very tight finances. Having to navigate banks to get fraud protection started or having your finances thrown off balance even for a day can be really hard on those people.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#46
post #14

To expand upon the author's idea, the problem is not just that credit card data is reusable, but that possession of credit card data amounts to permission to charge any arbitrary amount to it . Not legal permission, mind you, but permission in the sense that the infrastructure lets you do it, and you have to sort out the consequences through social/legal channels after the fact. Not only should future payment systems…

I agree with your solution of an affirmative step. I can see internet credit/debit card transactions moving towards a "request for funds" model where the consumer(via smartphone) has to explicitly ok the transfer of funds:

Merchant - (RFF) -> Bank - (prompts for auth) -> Consumer - (grants auth) -> Bank - (RFF granted) -> Merchant

Of course, smartphones are still potentially insecure, another more cumbersome model could revolve around challenge-response codes - where the customer has an offline digital code card:

[Merchant - (RFF) -> Bank - ($challenge) -> Merchant -($challenge) -> Consumer(punches in challenge code) - ($response) -> Merchant - ($challenge$response) -> Bank - (auth) -> Merchant

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#47
post #31

There's a simpler explanation to why merchants don't charge extra for credit card purchases: The cost of accepting cash is not zero. The logistics of drop safes and daily deposits plus losses due to counterfeiting, robberies and pilfering can cost a similar amount to the 3-4% credit card fees. That's why merchants aren't grumbling too much.

Also, the convenience of accepting cards leads to increased sales, so it's not worth penalizing use of cards.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#48
Overreacting, shallow, misleading and bait-link article.

Overreacting:

- the most up-to-date technologies for anti-credit card fraud, namely variants of smart card/EMV, are already available and widely used by all the large credit card providers and banks in the EU and Asia (excluding domestic transactions in China and Japan). There are even US providers who use it in some situations.

- in addition, most merchants in those regions have upgraded their PoS terminals for smart cards and in some cases refuse to accept non-smart credit cards.

- he made no case for how HSBC money laundering and subprime crisis have anything whatsoever to do with anti-fraud credit card technologies. Just randomly put it out there...

Shallow:

- Not even a minor reference to the specific technology being discussed is made, only a vague mention of "public-key cryptography".

Misleading:

- the credit card industry HAS and IS deploying the most up-to-date technology. In some regions, e.g. US, there are legal or infrastructure barriers that take time to overcome.

- the key moment at which the new infrastructure is rapidly rolled out and fully enters the public consciousness is associated with the "liability shift" when credit card infastructure providers push liability for fraud to merchants, therefore forcing merchants to upgrade their equipment and processes:

-- Mastercard is implementing a liability shift for point of sale terminals in October, 2015. For pay at the pump, at gas stations, the liability shift is October, 2017. For ATMs, the liability shift date is in October 2016.

-- Visa is implementing a liability shift for point of sale terminals on October 1, 2015. For pay at the pump, at gas stations, the liability shift is October 1, 2017. For ATMs, the liability shift date is October 1, 2017. [1]

Bait-link:

- a solution is already out there. It is based on "public key cryptography". Whether it is "simple" or not is a matter of opinion at this point, without any further clarification by the author. Nothing he has proposed has improved on the solution.

[1] http://en.wikipedia.org/wiki/EMV#United_States

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#49
post #14

To expand upon the author's idea, the problem is not just that credit card data is reusable, but that possession of credit card data amounts to permission to charge any arbitrary amount to it . Not legal permission, mind you, but permission in the sense that the infrastructure lets you do it, and you have to sort out the consequences through social/legal channels after the fact. Not only should future payment systems…

> possession of credit card data amounts to permission to charge any arbitrary amount to it

The word you're looking for is "capability", not permission. Permission requires consent, which is something you give separately from the actual card number.

A minor point, but I think it changes the tone of that statement.

> possession of credit card data amounts to the capability to charge any arbitrary amount to it

I'm not sure anyone is ignorant of this fact though, and yet everyone seems OK with it.

> Not only should future payment systems be based on cryptography, but they should also require an affirmative step on the part of the payer to initiate a given transaction of a given amount. In other words, it shouldn't be a matter of handing over your card number, or even a one-use cryptographic token, and letting the merchant fill in the details. You should have to explicitly send an amount of money that you specify. Then, of course, a smart merchant would verify that the amount is correct before fulfilling her end of the bargain.

Ugh, no thanks. The system you describe is more like cash. I have to actively dole out the necessary amount, and then receive change that is counted at each transition. I abhor these types of transactions.

Convenience is a significant motivator in the adoption of credit cards. Any competing system will have to compete on simplicity. The fact that consumers and merchants haven't fled from credit card use as fraud rates (and costs) have increased is evidence that the market is willing to bear them.

The legislative changes that allow merchants to charge a CC-use surcharge will resolve the significant matter of ignorance. I do agree that consumers are largely ignorant of the hidden costs of fraud associated with the current CC model. The question is whether they'll pay these costs once they're brought to light. I believe they will continue to pay them in exchange for convenience.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#50
Banks and card corps want a fool and his money to be able to push a button and buy something with as little hassle as possible. They are more than willing to use their trillions in profits to write off and eat some fraud if it means easy use for customers
Post reply on HN