Live data from Hacker News

Payments down 20% in my SaaS after EU introduced PSD2

globalbankingandfinance.com

31–40 of 121 posts

Re: Payments down 20% in my SaaS after EU introduced PSD2

#31
The practical outcome looks more like:

→ Customers who have had their card on file will fail the next subscription payment. Many are going to discover they have been paying for months/years for something they didn't really need, and walk away.

→ Incorrect 3D-Secure integration will cause payments from EU to fail straight away. Even some payment gateways didn't understand how it worked back when the enforcement loomed for the first time, and this is literally their job. The solution is to read the documentation carefully and fix your stuff.

It's a misconception that people are going to get confused by PSD2. We in Europe, depending on the bank, have had it for two years now. We got used to it and if we really want to pay, we will.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#32

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

I’ve personally always found 3DS a bit worrying from a security POV. I’m sure much smarter minds than mine designed it, and had reasons for doing so, but I’ve seen it implemented in iframes on websites I use before. It really doesn’t seem to encourage good security practices in normal users where they’re being encouraged to enter their bank password when the URL they see doesn’t match. Plus the URL itself often refers to Arcot, the company who make 3DS, rather than the bank whose branding is all over the page. Very weird.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#33

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

Here in Sweden, some major banks already refused to let you do card transactions without SCA/3DS, before PSD2 was even passed. As a result, PSD2 finally being implemented is a welcome relief for me, because those annoying services that would always cause a card decline are now being forced to show a 3DS prompt instead. That prompt is also pretty convenient here because of the wide deployment of Mobile BankID.

(The experience before was: pray this merchant supports 3DS, discover that it doesn't, fish out your phone and open mobile banking, authenticate with mobile banking, find and use the toggle that temporarily allows non-3DS transactions. Now I just bring up the authentication app when prompted.)

Re: Payments down 20% in my SaaS after EU introduced PSD2

#34

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

PSD2 is an EU directive that changed how online payments can take place within the EU. The key points are basically these:

Strong customer identification is required. In Denmark we handle this with our national identity system NemID (soon to be mitID). Which is a national two-factor system, that we previously mainly used for stuff like online banking or interacting with the public sector but is now also required when you buy something online.

Releasing the ownership of your financial data from the banks. Meaning that you can give third party companies access to your banking data. In Denmark this has revolutionised budgeting because the area was disrupted by companies that saw a gap in the age old online banking systems. As an example, my “overview” in my netbank was basically just a table of the data they used to physically mail me, today it offers all sorts of BI like tools to show me how I spent my money because an app named Spir or Spiir or something like it completely revolutionised the area. As you may be able to tell, I’m still doing my budgeting in my own spreadsheet, but the spiir app is one of the most popular apps in Denmark.

Over all it has been pretty well recover in Denmark. Having to utilise two-factor identification when you buy stupid shit online is annoying, and it’s likely costing some sales as people have a few more seconds to think while they pick up their phone, but over all people are happy with the increased protection it also offers them.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#35
Consumer protection legislation protecting consumers. I don't see the issue.

> Since many consumers are not familiar with the 3DS process, there is a higher chance of abandonment during the authentication process. Users may also choose to abandon a transaction simply because there are additional steps to complete, giving them more time to contemplate their purchase.

The data here is not really provided so we have no way of verifying they are stating e.g. simply that conversion in Germany went from 80%+ to 40%+ just due to PSD2 requirements to verify identify. 50% of consumers stop their purchase because they have to verify their CC? That seems absurd.

If the reason as cited above is unfamiliarity this means it is a purely temporary impact. If its birthing issues of implementation that too should be temporary. If consumers stop their biy due to reflection or realising that they don't trust the shop that too is a good thing.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#36

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

Before 3DS I had my credit card details memorized, so I could shop online conveniently. Now I have to keep my phone around and type in SMS passwords everywhere.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#37

In Poland we have something called "Blik" ( https://en.wikipedia.org/wiki/Blik ) state of the art internet payment system. https://blik.com/en Sadly it has to be supported by bank (to be specific their mobile app) so not usable by all EU customers. But since it is also operated by banks (they share cost of IT infrastructure) commission is much lower than Visa/MasterCard and milion times easier to use. In 2020 Blik ha…

is that per calendar year or in total?

Re: Payments down 20% in my SaaS after EU introduced PSD2

#38

Then make your service compelling enough for me to go through the motions of confirming the payment in my banking app. Or integrate with Android Pay/Apple Pay. Cry me a river, but I rather prefer to be in control about who gets to withdraw money from my card, and how much.

Those are pretty big transactions as the law will only apply to small ones later. It's really hard to believe people are leaving multiple 1000s of Euro transactions just because they didn't bother to learn how to check an app.

I think it's much more likely that some payment methods became completely unusable, so people are abandoning their transactions to redo them elsewhere. And also, some of those must have been fraudulent, but probably very few.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#39

Then make your service compelling enough for me to go through the motions of confirming the payment in my banking app. Or integrate with Android Pay/Apple Pay. Cry me a river, but I rather prefer to be in control about who gets to withdraw money from my card, and how much.

Seriously, if having to stand up and get whatever 2FA token thing your bank needs is too much effort for a purchase on your site, then I have strong doubts about how much your service is really worth.

Another explanation would be that customers run into trouble because they don't know how to use secure online payments. In my opinion, those customers probably shouldn't be doing any online banking on their own with the massive fraud risk that comes with stuff like this.

This line says it all, in my opinion:

> Users may also choose to abandon a transaction simply because there are additional steps to complete, giving them more time to contemplate their purchase.

PSD2 saved a lot of people from making bad financial decisions by the sound of it.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#40

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

The main issue to SMS tokens going away are all those people, specially elderly ones, that now are forced to buy a phone they cannot understand how to deal with.

Just like the clever idea some cities have had to initially only offer covid vaccination appointments over their website.

Post reply on HN