Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

121–130 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#121
post #93

Earlier quoted context omitted.

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Not quite as egregious, but when I worked in QA for an internally accessible, hospital record keeping web app, most of the "test" data was real customer data, and OBVIOUSLY I had complete access to prod with no particular oversight (although I'm certain logging was enabled) for HIPPA. Still, glad it was available, as going through approval processes would've been a nightmare for our implementations.

> going through approval processes would've been a nightmare

So internal apps can skip the HIPPA approval process? Or everyone can?

Re: Indian online merchants cannot store credit card information from 2022

#123

Is the RBI deliberately trying to handicap credit cards in India? The decision to make recurring payments impossible, followed by having to enter card information every time I do an online transaction is making for a very frustrating experience. The justification for these decisions is always "consumer interest" but how is making consumers jump through hoops to do transact online in consumer interest? I wish the indu…

As a consumer in India I’m so happy at least some part of this government is doing what it’s supposed to do. A century of unchecked lobbying is pretty much the reason why the US is at the state it is. The difference I’ve seen between how things run in india and the states is that in India what’s illegal and called corruption is called legal and lobbying here. What exactly are you worried about ? Clicking authorize on…

> Clicking authorize on nytimes subscription every month?

Why is that a good thing?

Re: Indian online merchants cannot store credit card information from 2022

#124

Kudos to Indian govt, this should be the default for any e-commerce websites. I have to resort to PayPal to avoid my credit card being stored in the e-commerce merchant sites but some of sites do not support PayPal. It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account.

>It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account. If you are in the EU, in my experience with the GDPR, this is not allowed. The e-commerce merchant must allow users to have the option to remove this information. PS: I had to file a formal complaint against a telecom company to have this resolved.

Unless they have to store those details for N years because of local laws. Obviously they could hide old cards in the UI and/or implement a soft delete.

Re: Indian online merchants cannot store credit card information from 2022

#125
post #65

Earlier quoted context omitted.

I don't agree with your interpretation on this being a stealth tactic but even if this was one it's just the state institutions acting in the interest of their mandate. This might not be beneficial to you employer or Visa or MasterCard or few high flying credit card users of the super rich class but it is in the interest of the people. If they think it's time to move beyond cards due to the strategic overdependence o…

> If they think it's time to move beyond cards due to the strategic overdependence on foreign service providers like Visa who can disrupt the Indian financial system at the behest of their US govt Is there any evidence that the RBI actually thinks this? You seemingly criticise GP on their inference of an ulterior motive but then posit your own ulterior motive.

Yes, some basis exists for such assumptions. RuPay and UPI were originally conceptualised by RBI and Govt of India to solve the overdependence problem. Otherwise RBI and GoI had no reason to introduce RuPay and they could have let the market develop organically.

Recent RBI moves of data localisation and enforcement actions against Diners, American Express and Mastercard also indicate strong intent.

Re: Indian online merchants cannot store credit card information from 2022

#126
post #55

Disclosure: I work for a fintech in India, specialized in card payment. It seems here people see this rule as "merchants can't store card numbers any more". This is actually a lot more than that, this is the new rule: you cannot store card numbers for recurring payment. Even if you are PCI-DSS compliant. Even if you are audited by the RBI. Even if you're sponsored by a bank. The only way to store a Visa number is to…

I believe merchants are not allowed to charge extra for visa or mastercard, but there is a hefty commission payed to them. They then use this to attracts customers and/or banks to sign up. Rupay customers end up paying part of the hefty commissions (albeit indirectly) that Visa charges the merchants and the Visa customers get discounts, cash backs and offers. A payment network is just a payment network, they shouldn'…

> I believe merchants are not allowed to charge extra for visa or mastercard, but there is a hefty commission payed to them. This is not the case in India but is the case in other markets, yes. The IRCTC (national railway company) is for instance displaying it and the customer has to pay fees depending on the selected payment option. Some actors even hide this amount until you reach the page asking you for an OTP! I don't think it's necessarily done with malicious intent, but it exists.

Sometime you won't see Visa or Mastercard but instead "Debit Card" and "Credit Card" vs "Rupay" for instance.

Re: Indian online merchants cannot store credit card information from 2022

#127
post #75

Earlier quoted context omitted.

I don't agree with your interpretation on this being a stealth tactic but even if this was one it's just the state institutions acting in the interest of their mandate. This might not be beneficial to you employer or Visa or MasterCard or few high flying credit card users of the super rich class but it is in the interest of the people. If they think it's time to move beyond cards due to the strategic overdependence o…

Ah maybe my comment is not clear, I am not judging on whether this is a good/bad move for people. I wanted to explain that the card number will still be stored: it only applies to recurring payment (at least for now). So for anyone worried about entities storing the card number... this will continue. I understand the confusion, but just to clarify I'm a big fan of UPI :). Now, is it good move for the people? It's a c…

MDR problem can be solved as you indicated. It also needs a solution pretty soon too.

EU and developed countries' banks live and finance their profits on fees as they don't make much or any money on loans and other traditional financial tools. Those fees aren't going to go away.

Re: Indian online merchants cannot store credit card information from 2022

#128
post #93

Earlier quoted context omitted.

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Not quite as egregious, but when I worked in QA for an internally accessible, hospital record keeping web app, most of the "test" data was real customer data, and OBVIOUSLY I had complete access to prod with no particular oversight (although I'm certain logging was enabled) for HIPPA. Still, glad it was available, as going through approval processes would've been a nightmare for our implementations.

The healthcare place I worked (mid 00's) kept all the prod passwords in a text file accessible to half the company. No auditing of logins into those servers either, so who knows what was leaked.

Re: Indian online merchants cannot store credit card information from 2022

#129
The sooner we move everything to one-time tokens (apart from subscriptions) the better. It's absolutely a ridiculous security model we have in place at the moment. I pay absolutely everything I can with Apple Pay now. I also would like to be able to use one-time disposable cards (without an additional fee) in Europe (ala privacy.com) but I have yet to find such a service.

Re: Indian online merchants cannot store credit card information from 2022

#130
post #65

Earlier quoted context omitted.

> If they think it's time to move beyond cards due to the strategic overdependence on foreign service providers like Visa who can disrupt the Indian financial system at the behest of their US govt Is there any evidence that the RBI actually thinks this? You seemingly criticise GP on their inference of an ulterior motive but then posit your own ulterior motive.

Yes, some basis exists for such assumptions. RuPay and UPI were originally conceptualised by RBI and Govt of India to solve the overdependence problem. Otherwise RBI and GoI had no reason to introduce RuPay and they could have let the market develop organically. Recent RBI moves of data localisation and enforcement actions against Diners, American Express and Mastercard also indicate strong intent.

I'm talking about your statement of "disrupt[ing] the Indian financial system at the behest of their US govt".

It's a pretty strong claim. If you have any evidence for this, please share it here.

Post reply on HN