Live data from Hacker News

Payments down 20% in my SaaS after EU introduced PSD2

globalbankingandfinance.com

101–110 of 121 posts

Re: Payments down 20% in my SaaS after EU introduced PSD2

#101

Earlier quoted context omitted.

With the way it currently works people can just charge your credit card with the account number only, more or less (everything publicly printed on your credit card). So by default they can already take money from your account which is probably one of the main bad things that could happen anyways.

I was under the impression that this new system changed where the liability lies. With a credit card I can dispute fraudulent charges. My bank's and my interests don't conflict. With the new system it seems like there's a conflict between my interests and the bank's when fraudulent charges happen.

I suppose if the authentication is strong enough then they can claim any fraud that happens to be user-responsible.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#102
post #98

Earlier quoted context omitted.

I’ve personally always found 3DS a bit worrying from a security POV. I’m sure much smarter minds than mine designed it, and had reasons for doing so, but I’ve seen it implemented in iframes on websites I use before. It really doesn’t seem to encourage good security practices in normal users where they’re being encouraged to enter their bank password when the URL they see doesn’t match. Plus the URL itself often refer…

If I were cynical I would say that the purpose of 3DS is to make it easier to scam people. It trains users to input their bank login details into third party apps and websites - something that you were told not to do over and over again in the past. I'm also sure that banks will be far less happy to refund fraudulent charges in these cases.

I agree with you that it’s bad practice to enter your login date into an arbitrary app.

However, you and the gp should complain to your bank because it’s their job to provide a secure confirmation method. My banks push the confirmation to their app that has separate without the possibility of stealing my bank credentials (in trivial ways).

Re: Payments down 20% in my SaaS after EU introduced PSD2

#103

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

I’ve personally always found 3DS a bit worrying from a security POV. I’m sure much smarter minds than mine designed it, and had reasons for doing so, but I’ve seen it implemented in iframes on websites I use before. It really doesn’t seem to encourage good security practices in normal users where they’re being encouraged to enter their bank password when the URL they see doesn’t match. Plus the URL itself often refer…

With SCA, it seems rare now to be asked to set up a password or PIN for 3DS in the UK.

It's more common to get a one-time-use code via SMS or a notification in an app for transactions with a higher risk.

Both of those make it possible for the bank to provide the consumer with information about the transaction that should be hard to spoof.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#104

Earlier quoted context omitted.

With the way it currently works people can just charge your credit card with the account number only, more or less (everything publicly printed on your credit card). So by default they can already take money from your account which is probably one of the main bad things that could happen anyways.

I was under the impression that this new system changed where the liability lies. With a credit card I can dispute fraudulent charges. My bank's and my interests don't conflict. With the new system it seems like there's a conflict between my interests and the bank's when fraudulent charges happen.

The size and locus of liability varies by the country of card issue. The US is particularly "generous" in shifting most of the liability onto credit card issuers; few (or any?) other countries do so.

BTW the origin of this legal regime is the card issuers themselves back in the 1960s as people were reluctant to use the cards. It's also good law in the sense that the card companies can modulate the line between reducing friction vs their fraud detection abilities & tolerance for fraud.

Of course one of the downsides is they do this via mass surveillance. That's why I put the quotes around "generous" -- it wasn't out of good will towards customers. Another was pushing quite a bit of responsibility onto merchants.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#105
post #78
post #64

Earlier quoted context omitted.

It quickly gets complicated. There are many more variables to take into account. - SCA exemptions - Prepaid Cards (with no built in 2FA support) - Banks in less developed markets (No 3DS) - "We encountered a 3DS processing error" is a common nondescript message which occurs with international payments For regular merchants, the decrease in conversion (double digit) is VERY far away from any improvements in chargeback…

Depends on the business though, right? In a high-value, low-margin business, reducing chargeback losses to almost zero might be worth the cost of a double-digit conversion drop. In other circumstances, the same numbers can be catastrophic.

And that I guess is the OPs point.

It should be a choice a business can make based on their circumstances. Instead, the EU legislates conversion loss for everyone.

If you think about it, when was the last time you entered even a CVV2/CVC on Amazon? Compare that to most regular sites which require you to enter CVV. Some allow you to enter the card holder name and address, while others don't and just sent the shipping address you've entered.

And it's not like this is a surefire way to make things better anyway. Like was mentioned before, it makes people that know about these things queasy when a random site redirects you to your bank and wants you to log in. What better way to scrape bank login info than a fake login screen for your bank? It's like when banks introduced TAN numbers. Then indexed TAN, SMS TAN etc. What regular user that fell for the "Please enter 3 TAN numbers to verify your account" will figure out whether a shady site is scraping their logins?

Re: Payments down 20% in my SaaS after EU introduced PSD2

#106
post #87

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

>> more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification, you have to unlock and accept the transaction Great - so much for those times where I've been traveling internationally, been able to make a purchase using a web page hosted on a shared computer or one owned by a companion, but don't have mobile phone access to get a push notification. Than…

i get your point, but i can't remember in recent years that there would be any difficulty to get wifi access even if i didn't have roaming, so this feels like a mere inconvenience instead of an impossibility

Re: Payments down 20% in my SaaS after EU introduced PSD2

#107

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

And what are people who don't own a smartphone doing? Do they just throw their cards to the trash, since they have become useless?

Re: Payments down 20% in my SaaS after EU introduced PSD2

#108
post #104

Earlier quoted context omitted.

I was under the impression that this new system changed where the liability lies. With a credit card I can dispute fraudulent charges. My bank's and my interests don't conflict. With the new system it seems like there's a conflict between my interests and the bank's when fraudulent charges happen.

The size and locus of liability varies by the country of card issue. The US is particularly "generous" in shifting most of the liability onto credit card issuers ; few (or any?) other countries do so. BTW the origin of this legal regime is the card issuers themselves back in the 1960s as people were reluctant to use the cards. It's also good law in the sense that the card companies can modulate the line between reduc…

For online transactions almost all liability is with merchants. Seems like unless chip is used then offline transaction fraud liability is also on the merchant (otherwise that shady convenience store wouldn't have any reason to check your signature/ID all the time).

Re: Payments down 20% in my SaaS after EU introduced PSD2

#109
post #104

Earlier quoted context omitted.

The size and locus of liability varies by the country of card issue. The US is particularly "generous" in shifting most of the liability onto credit card issuers ; few (or any?) other countries do so. BTW the origin of this legal regime is the card issuers themselves back in the 1960s as people were reluctant to use the cards. It's also good law in the sense that the card companies can modulate the line between reduc…

For online transactions almost all liability is with merchants. Seems like unless chip is used then offline transaction fraud liability is also on the merchant (otherwise that shady convenience store wouldn't have any reason to check your signature/ID all the time).

The article pointed out that with the new system the online transactions liability shifts to the banks. Thus the article claims banks may reject a payment request if they consider the merchant suspicious.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#110
post #78

Earlier quoted context omitted.

Depends on the business though, right? In a high-value, low-margin business, reducing chargeback losses to almost zero might be worth the cost of a double-digit conversion drop. In other circumstances, the same numbers can be catastrophic.

And that I guess is the OPs point. It should be a choice a business can make based on their circumstances. Instead, the EU legislates conversion loss for everyone. If you think about it, when was the last time you entered even a CVV2/CVC on Amazon? Compare that to most regular sites which require you to enter CVV. Some allow you to enter the card holder name and address, while others don't and just sent the shipping…

In Norway after the redirect to the payment page from a bank to approve the transaction the only thing one typically types is the phone number and the birthday. The rest happens on the mobile.

A bank in Spain implemented this even better as one does not enter anything on the site. Rather one has to go to the bank app on the phone and approve the purchase there. The latter is very frictionless especially with biometric authentication.

Post reply on HN