Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

111–120 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#111
post #55

Disclosure: I work for a fintech in India, specialized in card payment. It seems here people see this rule as "merchants can't store card numbers any more". This is actually a lot more than that, this is the new rule: you cannot store card numbers for recurring payment. Even if you are PCI-DSS compliant. Even if you are audited by the RBI. Even if you're sponsored by a bank. The only way to store a Visa number is to…

I believe merchants are not allowed to charge extra for visa or mastercard, but there is a hefty commission payed to them.

They then use this to attracts customers and/or banks to sign up. Rupay customers end up paying part of the hefty commissions (albeit indirectly) that Visa charges the merchants and the Visa customers get discounts, cash backs and offers.

A payment network is just a payment network, they shouldn't be using their market dominance to run marketing schemes.

Re: Indian online merchants cannot store credit card information from 2022

#112

Earlier quoted context omitted.

RBI(Central bank) has been filling-up for a long time for the total lack of security practices by merchants & data-privacy laws. e.g. One can control how much money can be withdrawn from the credit/debit card per-day according to domestic/International merchants/online/physical/ATM/ etc. through net-banking with the minimum in the multiples of INR 1000. So even if the card data gets stolen, Criminals can utmost withd…

So who has to pay up. What I mean, let's say your cc data gets stolen and somebody draws money from your card, can't you just initiate a charge back?

Although charge back mechanisms exists for merchant transactions, I don't know of anyone who had got back their money lost through the theft of their card data. I wouldn't be surprised if VISA/MASTER/AMEX don't have such liabilities in India as they do in US/Europe.

I had a conversation with cyber-crime police reg the aforementioned SMS scam using ngrok, They mentioned that many in my city have lost huge sums of money through it and the scam is not just for stealing bank credentials, the attacker's application tries to exploit victim's system and had successfully installed RAT.

Successive Indian Govt. have been at loggerheads with VISA/MASTER duopoly and have successfully derailed it for domestic payments, Now Unified Payments Interface(UPI)[1] which works with payment apps has more transactions than debit/CC. So the domestic criminals have largely switched to UPI/Bank account based scams.

Occasionally some of these criminals get caught and some get their money back.

[1] https://timesofindia.indiatimes.com/business/india-business/...

Re: Indian online merchants cannot store credit card information from 2022

#113
post #30

Earlier quoted context omitted.

That's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. India is also the top 7-8 e-commerce market in the world. Large local apps in the space have valuations in the tens of billions of dollars, and all major global players like Amazon and Walmart are involved in the country as well. These $100B in annual sales are…

> That's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. I don't have the experience to know if this is actually the case, but it seems completely plausible that different countries have different regulations (or enforcement thereof) such that US companies have to care about PCI more than Indian companies. > These…

Yeah, seems plausible - after all, as I recently learned from another HN post, it is customary for trucks not to have side mirrors in India, whereas this is much rarer in the US and virtually unheard of in (western) Europe...

Re: Indian online merchants cannot store credit card information from 2022

#114

Earlier quoted context omitted.

You can receive money over UPI without a smartphone. But sending money actively (as a customer) from a personal bank account is not possible afaik.

What no? My business, and my family business both run off the ability to make upi payments by just giving a UPI Id, amount and everything your pin. Quite often, i settle accounts with my friends over UPI. One of them pays for coffee, and i just upi him his share. And we work with our own personal savings accounts.

Needs a smartphone, that’s what I was pointing out.

Re: Indian online merchants cannot store credit card information from 2022

#115
The real story is far less sensationalist than the title on HN, "Indian online merchants cannot store credit card information from 2022".

Reading through the actual notification titled "Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services", it is clear that the directive is a well deserved push away from Card on File (CoF) where the actual card details are stored by merchants, towards CoFT which is a lot less vulnerable. In fact this is exactly what Apple Pay, Google Pay, and several others are already doing worldwide.

Re: Indian online merchants cannot store credit card information from 2022

#116
post #93
post #19

This is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit c…

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Indeed, astonishing retail-level security shenanigans will happen anywhere relying on simple credit card numbers. That said, the attack surface of a piece of paper is vastly smaller than a web-app-connected database.

Re: Indian online merchants cannot store credit card information from 2022

#117
post #93
post #19

This is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit c…

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Not quite as egregious, but when I worked in QA for an internally accessible, hospital record keeping web app, most of the "test" data was real customer data, and OBVIOUSLY I had complete access to prod with no particular oversight (although I'm certain logging was enabled) for HIPPA. Still, glad it was available, as going through approval processes would've been a nightmare for our implementations.

Re: Indian online merchants cannot store credit card information from 2022

#118
post #79

Earlier quoted context omitted.

You need to have a bank account to use UPI. Banks require a phone number afaik.

Yes, I know that. But does one need to share one's phone number to barely send or receive money?

nope. just your vpa.

Re: Indian online merchants cannot store credit card information from 2022

#119

I always enter my card details (unless direct bank transfer is available, which is becoming pretty popular lyckily). But I never found the idea that a saved credit card number (23 digits) would make a shopping experience so much convenient than having to enter it. A typical checkout still has me entering my address, choosing between 5 different delivery options, agreeing to various terms and so on. The payment step i…

You probably don't want to use bank transfers, depending on your jurisdiction. Using any sort of visa/masterdcard/amex gives you some protection via chargebacks. In the UK (and I think many other places), paying with a credit card over £100 gives you enormous additional protection (the credit card company is also liable for any problems). So if someone goes bankrupt, the credit card company has to make you whole. This is super helpful if eg you can't do a warranty claim on a product because the supplier went bankrupt. The credit card company has to resolve it (which generally means a full refund).

Paying with bank transfers completely negates all this protection. Merchants love it for this reason (and lower fees), but as a consumer it offers no benefits and a lot of drawbacks.

Re: Indian online merchants cannot store credit card information from 2022

#120

Is the RBI deliberately trying to handicap credit cards in India? The decision to make recurring payments impossible, followed by having to enter card information every time I do an online transaction is making for a very frustrating experience. The justification for these decisions is always "consumer interest" but how is making consumers jump through hoops to do transact online in consumer interest? I wish the indu…

This “authorize charge” change is really giving headache both to customers and companies. If person owning CC is not available, emails are misses, etc. so scheduled e-mail campaigns are not sent, backups are not done, scheduled data loads were not performed, etc.

Basically running business is getting harder and harder in India.

So this one thing why USA is still leader: not because it is “great” but because it is still “Wild West” (sure somebody will say “free country” - let’s be honest it is more of a “Wild West”)

Post reply on HN