Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

131–140 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#131

Earlier quoted context omitted.

I believe merchants are not allowed to charge extra for visa or mastercard, but there is a hefty commission payed to them. They then use this to attracts customers and/or banks to sign up. Rupay customers end up paying part of the hefty commissions (albeit indirectly) that Visa charges the merchants and the Visa customers get discounts, cash backs and offers. A payment network is just a payment network, they shouldn'…

> I believe merchants are not allowed to charge extra for visa or mastercard, but there is a hefty commission payed to them. This is not the case in India but is the case in other markets, yes. The IRCTC (national railway company) is for instance displaying it and the customer has to pay fees depending on the selected payment option. Some actors even hide this amount until you reach the page asking you for an OTP! I…

But IRCTC is a behemoth (though it is publicly listed).

We are talking about smaller merchants, would they be able to get away with the same?

Re: Indian online merchants cannot store credit card information from 2022

#132
post #93
post #19

This is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit c…

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

> The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance

Back in my younger days, I've implemented exactly such a system. Looking back, it seems like a "WTF where you thinking" but somehow it made sense back then. What is obvious practice now took 20+ years of internet evolution to reach.

I've also worked for companies that:

- Stored user passwords in plaintext so you can email the customer their password if they forgot - Stored the CVV so "we could issue refunds" - Accidentally created anonymous email relays using copy & paste code from some "how do I create a webform in PHP" site. - Test data was simply a mirror of production - Test servers would send real emails to real customers (because the test data was a prod mirror)

There are probably some other atrocities I've been exposed to but those are the highlights.

Oh yeah, forgot one:

- To "save money" on hard drives for "the server" we did a RAID0 array. Works great until one of the disks die and you loose everything. (This was my own dumb fault though).

Live and learn I guess!

Re: Indian online merchants cannot store credit card information from 2022

#133
post #94

Earlier quoted context omitted.

Yes this is stupid and it has caused me a lot of trouble since this all started. I am now seriously thinking of leaving this country and going to NZ or Canada (something which I did not want to do because of my parents). Doing business in India is so frickin hard, especially after GST. I have to spend so much time on accounting nowadays and it's getting harder and harder every day (even though all the ads say otherwi…

This is primarily because those companies haven't updated their payments systems to be compliant. The e-mandate system seems to be pretty good. Netflix is compliant and it worked seamlessly from day one of the switch. It could be because they have incorporated locally, which can be difficult for many other companies.

> This is primarily because those companies haven't updated their payments systems to be compliant.

For big companies with decades or more of legacy cruft, it's a hell of a lift to make their universe compliant. Especially if your large company tends to fall onto the "decentralized org structure" part of the spectrum where a billion teams run around doing their own thing with very little top-down oversight.

It's the same kind of story as it was for GDPR (and CCPA to some extent). Some companies can pull it off easy because their org structure is way more top down. Others that are bottoms up have a much harder time because you have to heard a million different teams towards something new that doesn't really deliver much immediate business value.

I assure you though, these companies are all no doubt hard at work making life better for their india customers... it is just a much harder lift for their organizations to handle. Which is not to say their org structure is a bad one. It just isn't optimized for top-down mandates like these.

Re: Indian online merchants cannot store credit card information from 2022

#134
post #129

The sooner we move everything to one-time tokens (apart from subscriptions) the better. It's absolutely a ridiculous security model we have in place at the moment. I pay absolutely everything I can with Apple Pay now. I also would like to be able to use one-time disposable cards (without an additional fee) in Europe (ala privacy.com) but I have yet to find such a service.

Doesn't the Apple credit card do this? I think they call them virtual numbers.

Re: Indian online merchants cannot store credit card information from 2022

#136

Something I learned in college - not all countries have the same laws as the US where it's easy to dispute a charge and the burden of proof is with the merchant. If India is one of those places where the burden of proof is on the customer, and it's difficult to dispute charges, it makes sense to tokenize things.

The burden of proof in India is with the merchant. Proof of transaction has to be provided (invoice etc.,)

Re: Indian online merchants cannot store credit card information from 2022

#137

Earlier quoted context omitted.

And yet people still think hiring Indian software and IT engineers is a good idea. This is not a racist thing. So don't disagree because it hurts someone else's assumed feelings. There is a significant gap in that sort of knowledge there.

"assumed feelings"? Does that somehow magically excuse racist statements like this? Good engineers are everywhere. Bad engineers are everywhere

[deleted]

Re: Indian online merchants cannot store credit card information from 2022

#138

Earlier quoted context omitted.

RBI(Central bank) has been filling-up for a long time for the total lack of security practices by merchants & data-privacy laws. e.g. One can control how much money can be withdrawn from the credit/debit card per-day according to domestic/International merchants/online/physical/ATM/ etc. through net-banking with the minimum in the multiples of INR 1000. So even if the card data gets stolen, Criminals can utmost withd…

So who has to pay up. What I mean, let's say your cc data gets stolen and somebody draws money from your card, can't you just initiate a charge back?

Chargeback rights and liability of fraud for creditcards are significantly different in different regions even for seemingly identical visa/mastercard cards.

Re: Indian online merchants cannot store credit card information from 2022

#139
post #30
post #19

This is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit c…

That's a weird generalization. Yes there are terrible, insecure e-commerce sites in India, the same as there are in the USA and everywhere else on the planet. India is also the top 7-8 e-commerce market in the world. Large local apps in the space have valuations in the tens of billions of dollars, and all major global players like Amazon and Walmart are involved in the country as well. These $100B in annual sales are…

That's a weird generalization

It doesn't seem like a generalization at all. It's someone relaying their actual experience:

"having worked with many E-Commerce shops in India as a consultant"

It very often happens on HN that if someone talks about something they had personal experience with, that people try to characterize it as a generalization, as if that somehow magically makes the statements a fantasy. It does not.

Re: Indian online merchants cannot store credit card information from 2022

#140
Pardon me if I’m incorrect, but isn’t this like one of the best use cases of Stripe? Stripe usually takes care of CC/ACH information and tokenizes it, only passing the tokens to the merchant instead of the merchant having to store the CC information. Maybe this would be a good way to start a payments company boom in India?
Post reply on HN