Live data from Hacker News

Payments down 20% in my SaaS after EU introduced PSD2

globalbankingandfinance.com

11–20 of 121 posts

Re: Payments down 20% in my SaaS after EU introduced PSD2

#11
I'm really glad my bank got FaceID 3DS right as PSD2 were introduced, it's really quite painless to do the 2FA (just tap the notification, look at your phone and put it back).

Previously you had to use an ancient SMS based SIM app on your phone or use a dongle to authenticate, took over a minute usually.

A way for retailers to "bypass" 3DS is to use Klarna or similar (free in-app invoice that needs to be paid within 14 days). Even though it's usually quite simple to use my debit card, it's still more of a hassle than paying whenever I want within 14 days, so that's what I choose when I'm in a hurry.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#12
post #4

what is PSD2?

It is the Revised Payment Services Directive requirements for Strong Customer Authentication. An EU directive that applies to credit cards issued by EU merchant banks for transactions that occur within the European Economic Area.

Basically a popup that will request some extra form of security verification for relevant transactions.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#13
This article would be significantly better if it introduces what PSD2 and 3DS actually are, for those unaware of the abbreviations.

PSD2 - https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev...

3DS - https://en.wikipedia.org/wiki/3-D_Secure

Furthermore, I want to note that the author works for a company that sells products that "eliminate unnecessary 3DS friction" (in their own words).

Re: Payments down 20% in my SaaS after EU introduced PSD2

#14

> The first thing that can reduce conversions is the higher rate of 3DS triggered user abandonment. Since many consumers are not familiar with the 3DS process, there is a higher chance of abandonment during the authentication process. This would presumably go away once PSD2 is fully implemented and all purchases require it, which is a benefit of requiring it by law rather than letting merchants choose whether or not…

I agree, the change needs to be viewed overall. The liability shift is a godsend, it also decreases customer support contacts to verify if the order is fraud or not.

Also, paired with 3DS2's frictionless flow we actually saw a small uptick.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#15

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

The 3DS is a handheld console by Nintendo.

Just kidding, 3DS is short for 3D-Secure and is an approach to make payments with credit cards more secure. Things like 3DS are mandated by the PSD2 which came into effect a while ago.

PSD(2) is short for payment services directive, its a set of rules to make online payments more secure and reduce the risk of fraud. It has some requirements, such as two factor authentication (3DS) etc for basically any service that is processing payments online.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#16

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

3DS is 2FA for credit card transactions. PSD2 is the law requiring it in EU.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#17

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

3d-Secure is basically a form of 2FA for payments. It has been around for almost two decades. US banks seem to have happily ignored it, as well as EMV/NFC cards even when good ol' magstripe had been shown to be hackable with a potato, and thus companies who lived in the US come to do business in Europe, find an "impenetrable wall" of having to integrate correctly with a 2FA process they don't understand. Same as GDPR, really. "How come it's opt-in and not opt-never?"

Re: Payments down 20% in my SaaS after EU introduced PSD2

#18

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

I'll link up Stripe's docs for SCA[1] as they have been very helpful for me in getting Leavetrack[2] set up for SCA.

PSD2 is the Second Payment Services Directive from the EU. A directive is required to be implemented in national law no more than two years after it is passed and whilst there have been delays, the past 12 months have seen a ramping up of banks implementing Strong Customer Authentication.

3DS (3D Secure) is like 2FA for debit/credit cards. In my case, I bank with Monzo and if a transaction requires 3DS, I have to open the Monzo app on my phone and confirm it. There are other aspects to SCA e.g. if I have used contactless payment frequently, I am more likely to be prompted to enter my PIN to confirm I still have my card.

[1] https://stripe.com/gb/payments/strong-customer-authenticatio... [2] https://leavetrackapp.com/

Re: Payments down 20% in my SaaS after EU introduced PSD2

#19

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

The biggest thing with PSD2 seems to be the introduction of mandatory 2FA (CVC code/card number are not sufficient).
Post reply on HN