Live data from Hacker News

A simple solution to credit card fraud, and why you won't see it any time soon

blog.rongarret.info

71–80 of 130 posts

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#71
post #34

In a rational world where declaring that government should be responsible for the foundational services that enable civil society the universal payment transaction service would be operated by the government as a public utility. In this hypothetical rational world, you would go to the government office when you needed to open a new payment account to make or receive payments. You would show proof of identity, and rec…

> In a rational world where declaring that government should be responsible for the foundational services that enable civil society the universal payment transaction service would be operated by the government as a public utility.

Already exists. It's called cash.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#72
post #58

Earlier quoted context omitted.

I agree with your solution of an affirmative step. I can see internet credit/debit card transactions moving towards a "request for funds" model where the consumer(via smartphone) has to explicitly ok the transfer of funds: Merchant - (RFF) -> Bank - (prompts for auth) -> Consumer - (grants auth) -> Bank - (RFF granted) -> Merchant Of course, smartphones are still potentially insecure, another more cumbersome model co…

You've just described ARQC EMV card payments.

After having a cursory glance through the ARQC EMV wiki entry, it seems that EMV corresponds to what we currently have in Europe -> the same (consumer) PIN is still going to be re-entered in every transaction i.e. it's re-useable and can be easily captured(camera/eyeball) for later use at POS/ATM

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#73
Not every problem needs to have a technology solution. In this case, the non-technology solution is to pass the fraud cost to the merchants (through fee) who in turn pass it to you (consumer). There is nothing wrong with it as long as everyone in the chain accepts it. Now, of course as a consumer you might feel bad about it but the penalty you pay for CC fraud is tiny. So you probably don't care because in exchange you get the convenience of using a credit card.

The industry is actually doing a lot of work to minimize the fraud and keep it under control. But there is absolutely correct understanding that it will never go down to 0. Even if you deploy super-modern PKI solution, you still have to deal with fraud like "didn't get an item", etc. Thus the benefits of not having a credit card number are not that significant in the big picture. While inconvenience and complexities are pretty high.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#74

Earlier quoted context omitted.

Ugh, no thanks. The system you describe is more like cash. I have to actively dole out the necessary amount, and then receive change that is counted at each transition. I abhor these types of transactions. Not in this case. There's no reason the merchant can't send a request for a specific amount, encrypted using your credit account's public key and signed by their private key. Your credit authorizing device (smartph…

Aren't you basically describing the "Request Money" feature of PayPal?

Yes, but imagine you can use it at the grocery store or a restaurant. Also, PayPal has a questionable reputation, so I wouldn't want to rely on them for all my day-to-day transactions.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#75
post #21

Earlier quoted context omitted.

If I could save .5% a transactin by looking at thr transaction cost on the card and then physically clicking ok I would probably do so. The problem is I have no choice one way or another.

If the true costs of fraud are 5-10 basis points, suggesting that we eliminate fraud by replacing that with a 50 basis point drain on the system seems unlikely to succeed.

Most likely that was a mental arithmetic error or he thought that 1 bp = 0.1%, but changing it from 0.5% back to 0.05% back really changes the utility. If your average CC transaction is $100, you're breaking even compared to picking up a nickel. I'd rather get on with my day then stand there waiting for the authorization or picking up a nickel.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#76
post #48

Overreacting, shallow, misleading and bait-link article. Overreacting: - the most up-to-date technologies for anti-credit card fraud, namely variants of smart card/EMV, are already available and widely used by all the large credit card providers and banks in the EU and Asia (excluding domestic transactions in China and Japan). There are even US providers who use it in some situations. - in addition, most merchants in…

I agree he the OP is overreacting and thin on details (and whiny) but this post completely misses that the main thrust is card-not-present situations and the US.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#77
post #67
post #14

To expand upon the author's idea, the problem is not just that credit card data is reusable, but that possession of credit card data amounts to permission to charge any arbitrary amount to it . Not legal permission, mind you, but permission in the sense that the infrastructure lets you do it, and you have to sort out the consequences through social/legal channels after the fact. Not only should future payment systems…

I used to work in the credit card space, and what I witnessed is that the industry is adamantly opposed to anything they perceive as inconveniencing customers, at least at point of sale where they are competing with cash. In fact, Visa and Mastercard explicitly don't allow stores to ask for an ID with card purchases. This is why anything that requires effort from the cardholder won't happen soon. Fortunately the anti…

Fortunately the anti-fraud solutions out there are pretty effective, which helps control the damage a stolen card can do.

In my experience, not reliably. For example, I've known people who gave their credit card info to a seemingly legit company, which then proceeded to make monthly debits without authorization, and this went on indefinitely. The credit card company was unwilling to intervene, and said it had to be worked out with the merchant.

That may sound surprising to you, because you're aware of chargebacks and other checks and balances. However, for some reason or another, none of that helped the victims in these cases. It's little consolation to them to say that "in theory, there are mechanisms in place to prevent this kind of abuse."

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#78
post #14

To expand upon the author's idea, the problem is not just that credit card data is reusable, but that possession of credit card data amounts to permission to charge any arbitrary amount to it . Not legal permission, mind you, but permission in the sense that the infrastructure lets you do it, and you have to sort out the consequences through social/legal channels after the fact. Not only should future payment systems…

> possession of credit card data amounts to permission to charge any arbitrary amount to it The word you're looking for is "capability", not permission. Permission requires consent, which is something you give separately from the actual card number. A minor point, but I think it changes the tone of that statement. > possession of credit card data amounts to the capability to charge any arbitrary amount to it I'm not…

Yes, capability is a fine word for this. I'd say the practical consequences are still exactly the same, regardless of the label.

Ugh, no thanks. The system you describe is more like cash. I have to actively dole out the necessary amount, and then receive change that is counted at each transition. I abhor these types of transactions.

Not as I imagine it. I think the merchant would be able to set up a transaction, and the consumer would have to take a minimal step to approve it.

Also, if this system would annoy you, I'd be fine with allowing individual consumers to opt out of it. Personally, I would absolutely opt in.

The fact that consumers and merchants haven't fled from credit card use as fraud rates (and costs) have increased is evidence that the market is willing to bear them.

Partially. But this fact can also be attributed in large part to the major barriers to entry.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#79
post #22

I've thought about this "problem" and decided there's no problem. You're solving a non-problem if you try to solve credit card fraud. The reason we don't deal with credit card fraud is that there are no consequences for being a victim, for any definition of victim. If the victims had consequences, then there would be demand for action. But there is none. Further, because there are no consequences, the cost to solve c…

Even if you eventually get the money back, fraudulent credit card txns are extremely stressful and can easily have real impacts on debit card accounts. Saying so matter of factly "there is no consequence" is obviously wrong.

Re: A simple solution to credit card fraud, and why you won't see it any time soon

#80
Two, possibly ancillary points:

As someone who was part of a lawsuit involving public key cryptography I can assure you that the barrier to deploying it in the US rested squarely on RSA Data Security (patent holder) until the patents expired.

To understand how to deploy better security look at Stripe. Stripe is displacing (with pre-existing card technology) the connection between card companies and merchants with a better experience. With an established customer base they will be in a position to drive the replacement of cards.

No system with as many moving parts as the credit card system has, can be "quickly" changed (and by quick here I'm talking demi-decades) however it can be disrupted and replaced.

Post reply on HN