Earlier quoted context omitted.
From the article: "As an extra security measure, we have to ask customers for the ZIP code associated with their card. There is a trade-off here: adding extra inputs to the form can increase bounce rates, but by adding it, our business is more secure and less prone to fraud."
Is the zip sent to the card processing company? Do they check that the zip matches your address? What if the customer just moved? I've implemented card payments on multiple occasions, but not once have I seen a credit card processor that offered to validate the zip code. Unless the name and zip can actually be sent to the credit card processor, and they have access to that information based on the credit card number…
And I haven't met a bank that didn't ignore the middle initial when validating a credit card. Even though they all say "enter your name as it appears on the card".
Which just makes it easier for them to be stolen. If someone gets a hold of your card number they probably also have the record of what you bought. If you had it delivered to your house they have your first and last names and zip code. All they need is the CVV2 (pick a random number from one to one-thousand) and they're in the clear.
I really don't get credit card security at all. Seems to me to be a lot of smoke and mirrors that the banks just plaster over with insurance for when they have to give back stolen money. It doesn't actually prevent or deter theft, just sweeps it under the rug.