Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

151–157 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#151
post #123

Earlier quoted context omitted.

As a consumer in India I’m so happy at least some part of this government is doing what it’s supposed to do. A century of unchecked lobbying is pretty much the reason why the US is at the state it is. The difference I’ve seen between how things run in india and the states is that in India what’s illegal and called corruption is called legal and lobbying here. What exactly are you worried about ? Clicking authorize on…

> Clicking authorize on nytimes subscription every month? Why is that a good thing?

Because for NYTimes e.g. they don't allow online cancelation and need to through the phone retention loop.

RBI mandate thing could have been implemented better but I absolutely support the idea that recurring payment control should be with the consumer and not the merchant.

Re: Indian online merchants cannot store credit card information from 2022

#152
post #93
post #19

This is actually a good thing. Think of it like Apple's email masking service - Merchants can only store a tokenized version of your credit card instead of the real card details. I say this is a good thing after having worked with many E-Commerce shops in India as a consultant. Most of them barely know a thing about security, let alone about PCI DSS compliance. I have worked with shops that stored the entire credit c…

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Isn't that how booking.com still operates with like millions of hotels worldwide, but via fax machine?

Re: Indian online merchants cannot store credit card information from 2022

#153

Something I learned in college - not all countries have the same laws as the US where it's easy to dispute a charge and the burden of proof is with the merchant. If India is one of those places where the burden of proof is on the customer, and it's difficult to dispute charges, it makes sense to tokenize things.

The rules around chargebacks et al are dictated by the card scheme and remain the same regardless of country the merchant is operating in or car holder is transacting in. How this translates on the ground would be the primary point of difference to other countries.

Re: Indian online merchants cannot store credit card information from 2022

#154
post #93

Earlier quoted context omitted.

I have spent a long time in eComm in the west, and you see that kind of stuff there as well. The most erroneous was the company that would take credit cards in plain text, print them onto an order sheet for reception staff to put through their POS at the front desk, and then the order sheets just went into the bin near the entrance. Thousands of credit card numbers were just sitting there for the taking, in plain tex…

Isn't that how booking.com still operates with like millions of hotels worldwide, but via fax machine?

I wouldn't be surprised. I wonder what is more secure, fax or plain text email?

Re: Indian online merchants cannot store credit card information from 2022

#155
post #154

Earlier quoted context omitted.

Isn't that how booking.com still operates with like millions of hotels worldwide, but via fax machine?

I wouldn't be surprised. I wonder what is more secure, fax or plain text email?

Fax is probably way harder to eavesdrop or copy.

Email is likely backed up for years...

Re: Indian online merchants cannot store credit card information from 2022

#156
post #72

Earlier quoted context omitted.

What is this Apple email masking service? I keep reading about it but every time I pick "Apple Pay" to pay some service it tells me it's going to give them my icloud address and it gives me no option to choose "mask my email" or anything remotely related or giving some alternate email

It's called "Hide My Email" and you can use it to sign up to services in apps: https://support.apple.com/en-us/HT210425

Ah, so it doesn't work for purchases

Re: Indian online merchants cannot store credit card information from 2022

#157
post #129

The sooner we move everything to one-time tokens (apart from subscriptions) the better. It's absolutely a ridiculous security model we have in place at the moment. I pay absolutely everything I can with Apple Pay now. I also would like to be able to use one-time disposable cards (without an additional fee) in Europe (ala privacy.com) but I have yet to find such a service.

Doesn't the Apple credit card do this? I think they call them virtual numbers.

Yes this is why I mentioned I only use Apple Pay
Post reply on HN