This article would be significantly better if it introduces what PSD2 and 3DS actually are, for those unaware of the abbreviations. PSD2 - https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... 3DS - https://en.wikipedia.org/wiki/3-D_Secure Furthermore, I want to note that the author works for a company that sells products that "eliminate unnecessary 3DS friction" (in their own words).
I found those links slightly difficult to understand. Am I correct in summarizing these definitions as follows? PSD2—The EU law requiring your bank/card issuer to establish SCA for online purchases. SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. 3DS—3-Domain secure, the protocol used by online merchants to com…
Two things, actually. The credit card number doesn't count as a "thing" anymore.
This is why SMS-OTP alone is not sufficient (representing only possession), but mobile phone app based solutions are (they represent possession of a linked device and usually ask for biometrics or a PIN code).