Earlier quoted context omitted.
Then it's a good thing that many banks in the EU now have 3DSecure validation through the phone app instead of SMS
What if you lose your phone? In my country banks only allow you to use one phone for mobile authorization, so you can't even have a backup phone. I really wish 3DSecure was optional so I can turn it of when going to foreign vacation.
The underground world of credit card network exploitation
241–250 of 280 posts
Re: The underground world of credit card network exploitation
#242Earlier quoted context omitted.
What do you recommend as an alternative to stripe?
You pool your payment providers using something like https://hyperswitch.io
Re: The underground world of credit card network exploitation
#243Earlier quoted context omitted.
My guess is the difference lies in the fact that the EU limits credit card fees to something around 0.5% That means the CC companies can't offload the financial burden of this onto the vendors (and they in turn onto their customers), which leads to them having an actual incentive to improve security.
> That means the CC companies can't offload the financial burden of this Most CC company (CCC) revenue comes from charging the poor people who can't pay their bills ("interest"). Merchant fees are only a small portion of revenue for most cards [1]. In the case of Discover for example it's less than 10% of their revenue, and in the case of Amex it's less than 33%. Other cards fall in-between. [1] https://www.valuepeng…
Re: The underground world of credit card network exploitation
#244Why does the US seem so far behind when it comes to banking? - Chip and PIN has been in the UK since 2004 and mandatory since 2006. It wasn't until a decade later that the US caught up. - Faster Payments allow for instant bank transfers (usually) between any bank account for free. Receiving transfers from clients in US (even with a US Wise bank account) was always a nightmare. - Since the EU introduced Strong Custome…
I would say it’s not worse than most of the world though. Much of the world is rampant with fraud borne entirely by the consumer. For instance QR based bank transfers are popular in much of the world outside the western developed world. Fraud is insanely rampant but the ease and utility vs cash makes it acceptable. Transactions costs are near or actually zero and there’s no POS infrastructure. But people meticulously check their transactions because theft is so rampant. The banks and governments seem unconcerned though.
As such I put the US somewhere in the midpoint globally for this space. There are some smaller economies with strong regulatory regimes that do better for sure. There are many more that do much worse. Obviously the goal is the better not the worse, but I think it’s cherry picking to lump the US into being the worst.
Re: The underground world of credit card network exploitation
#245It is instead a showcase on how mediocre issuers can be when authorizing transactions, and how non-sensical the system has become that the merchant ends up paying the price for chargebacks.
Re: The underground world of credit card network exploitation
#246Cloudflare has tools to prevent too many form submits. You can specify which page, how many submits and so on. I found out about this when I had a problem of somebody running a script of trying different credit cards over a two hour window. My payment processor told me I should prevent these types of things. So I investigated and never had this problem anymore. Cloudflare is amazing at preventing all kinds of attacks…
Re: The underground world of credit card network exploitation
#247Earlier quoted context omitted.
> Things have definitely changed here recently. At least in San Francisco, at-table terminals are now the norm in sit-down restaurants. Staff generally use the same device for order-taking and payment. I used to work in PoS industry. This tech is new-ish to the US but not to the rest of the first-world. 15 years ago, paying with a CC @ the table was common in Europe, but the terminal could ONLY do payments. The devic…
For sure. "Bring the card to the device" and "bring the device to the card" seem about equivalent to me in convenience unless the device is something that the waitstaff is going to carry all the time anyhow.
Re: The underground world of credit card network exploitation
#248Earlier quoted context omitted.
As a Canadian, it does feel like stepping out of a time machine when you pay at restaurants in the USA. Instead of using a terminal at the table to pay yourself, you need to give the server your card and wait for them to manually process it somewhere. Maybe things have progressed in recent years. But we haven't done it that way in Canada since the early 2000's.
I was visiting Seattle (from Vancouver) a few years ago, and they didn't want me to use my chip card as a chip card because if they did then I couldn't tip. What the heck is that all about? Also, we're still hearing stories about merchants in the US starting to accept Apple Pay, whereas it worked fine in almost every retailer in Canada the day it was available - even though it wasn't available in Canada for a long ti…
Re: The underground world of credit card network exploitation
#249Earlier quoted context omitted.
I've started to see more and more servers using a mobile POS with built in credit reader and receipt printer. They hand it to you for tip and signature and you don't have to hand your card to anyone.
Definetly not a better experience for all consumers. Or waiter. I do know that some restaurant owners are removing these things. They do not want to look like Olive Garden :) But it really depends on a restaurant: is it high end, type of food / drinks, it is a date place, etc. Majority of restaurant is all about experience and event payment system should match that experience.
In Japan, you don't pay at the table, you get up when leaving and pay at the exit. If you're at a high-end establishment entertaining guests, this also leaves you the opportunity to "go to the restroom" late in the dinner and pay ahead of time so that the "mess" of payments is completely forgotten.
It also means waiters don't need to run around the place with cards/readers/cash, you don't need to fumble when you left your wallet in your coat that's been hung up, don't need to squint to read receipts in the dim mood lighting in the eating area, etc etc.
Re: The underground world of credit card network exploitation
#250Earlier quoted context omitted.
"Hassle free peace of mind" meaning you do not need to remember a 4 digit code (or clicking "yes" in a phone app), while you need to check your credit card transaction list regularly to reject fraudulent transactions? I find the effort of remembering the 4 digit code/having the phone much smaller than the alternative ...
I think you misunderstood me. Peace of mind is in not having to worry about fraud being my responsibility to fight or dispute. I can call CC company or through mobile app, flag transaction, get my money back and never spend another minute on the issue.
And even if you have peace of mind, I wonder who pays for the cost of the fraud. I would imagine the bank will just pass it over to the consumer in some fees. So a system that reduce fraud (even if can't eliminate it completely) is still better in my opinion.