Live data from Hacker News

Payments down 20% in my SaaS after EU introduced PSD2

globalbankingandfinance.com

41–50 of 121 posts

Re: Payments down 20% in my SaaS after EU introduced PSD2

#41

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

100% agree, this is self-interested drivel with nonsense data and no actual evidence. Intention is to sell their product.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#42

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

> which is used as the second factor (you get a push notification, you have to unlock and accept the transaction).

This breaks more often than you'd think. I'm still locked out of Facebook on one device because I can't seem to receive the unlock notification and I'm terrified to reinstall Facebook on my phone and then be actually locked out. I'm not a fan of Facebook, but it's the only way to contact some of my friends/family these days via video.

I've also had similar issues with actual banks where the notification appeared and I accidentally tapped "decline" or even dismissed the notification by accident. I've also never received them (mostly with ~Transfer~Wise). Edit to add: I've also been too lazy to walk to the phone charger to press "accept" and just given up.

I think it's a pretty well known phenomenon in ecommerce that the more "clicks" you add to checkout, the less % of people that will make it to the end. I don't see this decreasing cart abandonment at all.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#44
>Users may also choose to abandon a transaction simply because there are additional steps to complete, giving them more time to contemplate their purchase.

Good. Means you've manipulated people into spending their money very intensely if they will abandon the transaction once the first rational thought comes in. I would personally add a third factor for good measure.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#45

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

> which is used as the second factor (you get a push notification, you have to unlock and accept the transaction). This breaks more often than you'd think. I'm still locked out of Facebook on one device because I can't seem to receive the unlock notification and I'm terrified to reinstall Facebook on my phone and then be actually locked out. I'm not a fan of Facebook, but it's the only way to contact some of my frien…

Google, Duo, and Authy all seem to do fine even in low-data (1 bar non-lte 4g) scenarios, so that's probably a bank & facebook issue. They probably rely on the push notification to carry and push state to the user's device with no backup mechanism for when this fails.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#46

Very interesting to hear about the impact of this regulation on industries many here work in but I have many questions that were answered… What is PSD2? What is 3DS? Why do these exist and what did they solve? Edit: Thanks for the responses everyone!

> What is 3DS?

3DS stands for 3 Domain Secure. Payment processing requires a lot of service providers to co-ordinate; card issuer, merchant acquirer, card network to name a few.

The three domains in 3D refers to the domains of Issuer (the bank that issued the your card), Acquirer (the bank that the merchant has their account in), and the Network (Visa, Mastercard etc., which connects Issuing banks and Acquiring banks).

I'm vastly simplifying because now a days there are new entities which are difficult to typecast into one of Issuer/Acquirer/Network because depending on the scenario they can act as any or all three.

Unlike the Internet which has reasonably well defined protocols/services to provide end user services (HTTP, SMTP, DNS etc.,) online payment processing has evolved by monkey-patching systems as newer challenges have arose. There are no well defined protocols or standards so you have these vast network of systems that somehow work-together to process online payments. Once in a while it fails exposing its innards like how people came to learn about T + 2 settlement during Gameshop saga.

> Why do these exist and what did they solve?

3DS is kind of a protocol that'll enable a card holder to authorise a payment while minimising the number of service providers that have access to their card details. A typical implementation of 3DS requires card holder to authorise a payment through PIN. Another is through second factor auth such as SMS OTP, or RSA tokens, Apple's Face ID.

> What is PSD2?

This is a European specific regulation to make payments more secure. 3DS is one of its requirements.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#47

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

For me it opens the bank app which shows amount, seller, subject line and asks me to confirm with pin or fingerprint, taking all of 2 seconds. No more entering bank card numbers. Not sure what bank youi are using but this seems like bad implementation not bad idea.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#48
post #36

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

Before 3DS I had my credit card details memorized, so I could shop online conveniently. Now I have to keep my phone around and type in SMS passwords everywhere.

3DS should do the exact opposite, away with SMS.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#49

In Poland we have something called "Blik" ( https://en.wikipedia.org/wiki/Blik ) state of the art internet payment system. https://blik.com/en Sadly it has to be supported by bank (to be specific their mobile app) so not usable by all EU customers. But since it is also operated by banks (they share cost of IT infrastructure) commission is much lower than Visa/MasterCard and milion times easier to use. In 2020 Blik ha…

Sweden has adapted something similar, Swish[1]. Co-owned by banks and so far without any fees for private entities. The adaption rate has been really incredible. Already 75% of the population has signed up for it and, in 2020, made over 600 million transactions.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#50
post #9

This sounds wonderful to me. 20% of would-be buyers were saved from mindlessly consuming and paying for stuff they don't need — by just a tiny little UI friction. Imagine what a mandatory essay about the reason for your purchase would accomplish.

You actually have a point. I think 3-D Secure both fulfills it's purpose to increase consumer protections when paying online, while at the same time, as you suggest, it's acts as a soft obstacle reminding the consumer to maybe re-evaluate their purchase.

I'm not saying it's frictionless nor perfect, but things were worse earlier. Card and identity fraud is increasing, and will continue to be a valuable target, not least because we're moving towards a cashless society (some say).

Post reply on HN