Live data from Hacker News

How India's banks killed the future of commerce

blog.cleartrip.com

21–30 of 60 posts

Re: How India's banks killed the future of commerce

#21
post #17

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

> IIT students were arbitrarily limited in the number of hours they could spend online because some administrator thought they should get out more Wow, I didn't believe you at first, but it appears to be true. [1][2][3] They appear to be justifying by claiming, besides that it prevents them from meeting others, that it somehow causes suicide and depression and that it is responsible for falling grades. Does anyone kn…

Well they are even planning to remove all ceiling fans: http://www.indianexpress.com/news/iit-to-remove-ceiling-fans...

Re: How India's banks killed the future of commerce

#22
post #19

Earlier quoted context omitted.

NO - 3D secure is not good for the customers. the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")

Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.

In most cases the question is the default. The typical flow is the user tries to do a transaction - bank identifies they are not registered for 3D secure yet - a couple of questions and a OTP later - a 3D secure password is chosen. But the question remains the default one unless the user decides to take the effort of changing it.

Re: How India's banks killed the future of commerce

#23
post #12

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

India is generally conservative about financial issues. In this case, it puts them on the wrong side. But their conservative approach also shielded India from the banking crisis experienced by US etc. From http://www.nytimes.com/2009/06/26/business/global/26reddy.ht... “If America had a central bank chief like Y. V. Reddy, the U.S. economy would not have been such a mess,” Joseph E. Stiglitz, the economist and Nobel…

I'm quite willing to be convinced that a conservative monetary system has shielded some countries from certain isssues, but some economist saying so doesn't make it so, not even if he's a famous economist. So some background on the mechanics would be nice.

Re: How India's banks killed the future of commerce

#24
This is nothing. Every time somebody finds an easier way of doing things, the government and the babucracy finds a way of muscling in and making it as bad as all the earlier options. Some of it is not bad, but others are nuts. I should start a list.

- Vehicles registered in one state cant be used for too long in another state

- Banks have insane policies

- Online electronic tax filing requires that you complete the process in paper format as well. To complete the electronic process you have to send it in by normal snail mail as well. And you cant get acknowledgments.

- Universities don't recognize each other between states

-

Re: How India's banks killed the future of commerce

#25
post #19

Earlier quoted context omitted.

NO - 3D secure is not good for the customers. the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")

Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.

The monkey could also fetch the secret question from the 3DSecure page and show it to the user, right? Or am I missing something here? How will adding more information to the login page make it more resistant against mitm?

Re: How India's banks killed the future of commerce

#26
post #23
post #12

Earlier quoted context omitted.

India is generally conservative about financial issues. In this case, it puts them on the wrong side. But their conservative approach also shielded India from the banking crisis experienced by US etc. From http://www.nytimes.com/2009/06/26/business/global/26reddy.ht... “If America had a central bank chief like Y. V. Reddy, the U.S. economy would not have been such a mess,” Joseph E. Stiglitz, the economist and Nobel…

I'm quite willing to be convinced that a conservative monetary system has shielded some countries from certain isssues, but some economist saying so doesn't make it so, not even if he's a famous economist. So some background on the mechanics would be nice.

Not sure if you read the NYT article but it goes into some detail.

Re: How India's banks killed the future of commerce

#27

Notice how they made the post on Feb 14, but show only data for Feb 1. Is it really surprising that the first day with the new system saw fewer transactions? Making claims that this move "permanently hobbles India's mobile commerce" based on evidence like this is surely unwarranted. I really think 3D secure is a good move. All it requires is entering your internet banking password at the time of making the transactio…

I agree, but that is what I would do if I was an annoyed phisher, blogging about the new security system in my way.

Re: How India's banks killed the future of commerce

#28
post #8

Earlier quoted context omitted.

NO - 3D secure is not good for the customers. the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")

> because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us") Seems pretty valid argument to me.

Rather than downvote it's easy to factually counter your argument: it's not because e.g. keyloggers or mitm attacks can compromise the account. Then afterward, the 2-factor auth is used against the customer as a smokescreen - basically banks say 'oh but we've got this very secure system, it can't be cracked'. Then you have to get into a very technical argument with the bank, which is either hard to win (because only 1 person involved understands, deliberate or not) or impossible (because most customers don't understand the details, and we can't expect them to).

This is not a hypothetical situation - this already happens in Western Europe! It's hard to hold banks or merchants responsible for fraud. Now they shouldn't always be held responsible, that's the first issue; but even in cases where they are (like when they guaranteed upfront that they'd take the risk of fraud, as they used to do in the early days of online banking/payment) their first line of defense will be vague 'our technology is tamper proof' arguments. Many consumer association websites are full of stories about this.

Re: How India's banks killed the future of commerce

#29

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

About the SMS limitation - you got it wrong here, the limit is for sending SMSes with the same text and definitely not for receiving them. There's no limit on the amount of normal SMSes (with different content) you can send in a day. I think that's a pretty good move, spam SMS is turning into a huge problem here.

Buy my awesome product! (token: aa32cdf)

problem solved.

Re: How India's banks killed the future of commerce

#30

India has a lot of public policy mishaps such as this. It seems that the people making these rules oftentimes don't do adequate research regarding what's feasible for such a large developing, and rapidly changing country. A couple of other examples: There was recently a rule to limit SMS spam by limiting each cell phone to receive a max of 100 texts per day, there still is a rule where you can't entering the country…

About the SMS limitation - you got it wrong here, the limit is for sending SMSes with the same text and definitely not for receiving them. There's no limit on the amount of normal SMSes (with different content) you can send in a day. I think that's a pretty good move, spam SMS is turning into a huge problem here.

Thanks for the clarification. I'd just skimmed an article summary and wasn't aware of the details of the plan.
Post reply on HN