Live data from Hacker News

Payments down 20% in my SaaS after EU introduced PSD2

globalbankingandfinance.com

91–100 of 121 posts

Re: Payments down 20% in my SaaS after EU introduced PSD2

#91

This article would be significantly better if it introduces what PSD2 and 3DS actually are, for those unaware of the abbreviations. PSD2 - https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... 3DS - https://en.wikipedia.org/wiki/3-D_Secure Furthermore, I want to note that the author works for a company that sells products that "eliminate unnecessary 3DS friction" (in their own words).

I found those links slightly difficult to understand. Am I correct in summarizing these definitions as follows? PSD2—The EU law requiring your bank/card issuer to establish SCA for online purchases. SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. 3DS—3-Domain secure, the protocol used by online merchants to com…

> something in addition to a credit card number

Two things, actually. The credit card number doesn't count as a "thing" anymore.

This is why SMS-OTP alone is not sufficient (representing only possession), but mobile phone app based solutions are (they represent possession of a linked device and usually ask for biometrics or a PIN code).

Re: Payments down 20% in my SaaS after EU introduced PSD2

#93

So, some VP at a fraud prevention company recommends merchants to avoid using 3DS and use a fraud detection platform, got it. I don't know if we can find better data somewhere else but I would assume that abandonment rates will decrease thanks to PSD2: - SMS tokens are finally on their way out; more and more people are installing their bank's mobile app, which is used as the second factor (you get a push notification…

Here in Sweden, some major banks already refused to let you do card transactions without SCA/3DS, before PSD2 was even passed. As a result, PSD2 finally being implemented is a welcome relief for me, because those annoying services that would always cause a card decline are now being forced to show a 3DS prompt instead. That prompt is also pretty convenient here because of the wide deployment of Mobile BankID . (The e…

While I mostly agree with you the fact that BankID does not support (desktop or non-android) linux at all or other secure auth methods like U2F for any platform is sad. If you want to be a modern citizen in sweden today you need to use at least one device with a non-free OS just to access basic services.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#94

This article would be significantly better if it introduces what PSD2 and 3DS actually are, for those unaware of the abbreviations. PSD2 - https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... 3DS - https://en.wikipedia.org/wiki/3-D_Secure Furthermore, I want to note that the author works for a company that sells products that "eliminate unnecessary 3DS friction" (in their own words).

I found those links slightly difficult to understand. Am I correct in summarizing these definitions as follows? PSD2—The EU law requiring your bank/card issuer to establish SCA for online purchases. SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. 3DS—3-Domain secure, the protocol used by online merchants to com…

>SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code.

I've run into this a few times and it has made me very hesitant. You're effectively being asked to log into your own bank account from a link on a third party website or, even worse, an app.

It makes me uneasy, because I feel like a malicious site or app could intercept this and access the account directly. Or do some other kind of trickery that I cannot foresee.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#95

The practical outcome looks more like: → Customers who have had their card on file will fail the next subscription payment. Many are going to discover they have been paying for months/years for something they didn't really need, and walk away. → Incorrect 3D-Secure integration will cause payments from EU to fail straight away. Even some payment gateways didn't understand how it worked back when the enforcement loomed…

>It's a misconception that people are going to get confused by PSD2. We in Europe, depending on the bank, have had it for two years now. We got used to it and if we really want to pay, we will.

When a (random) app opens a bank login page for me and asks me to type in my back login information in a third party app, then that very much does confuse me. That's one of the ways people get scammed through phishing attacks. And now this is effectively mandated by law.

I've definitely chosen not to pay for a few things, because I didn't trust the app enough with my bank's login information. With a credit card I could easily dispute false charges. With bank authentication, I doubt it'll be as easy.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#96
post #9

This sounds wonderful to me. 20% of would-be buyers were saved from mindlessly consuming and paying for stuff they don't need — by just a tiny little UI friction. Imagine what a mandatory essay about the reason for your purchase would accomplish.

That's nice of you to decide for the would-be buyers that they didn't need the stuff they wanted to buy. Do you offer this as a service?

Re: Payments down 20% in my SaaS after EU introduced PSD2

#97
post #94

Earlier quoted context omitted.

I found those links slightly difficult to understand. Am I correct in summarizing these definitions as follows? PSD2—The EU law requiring your bank/card issuer to establish SCA for online purchases. SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. 3DS—3-Domain secure, the protocol used by online merchants to com…

> SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. I've run into this a few times and it has made me very hesitant. You're effectively being asked to log into your own bank account from a link on a third party website or, even worse, an app. It makes me uneasy, because I feel like a malicious site or app could i…

With the way it currently works people can just charge your credit card with the account number only, more or less (everything publicly printed on your credit card). So by default they can already take money from your account which is probably one of the main bad things that could happen anyways.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#98

I absolutely hate 3DS, for two reasons: 1) I now have to do the 3DS procedure for amounts as small as 1,80€ 2) My bank's 3DS "website" requires me to enter my online banking PIN (the one for my entire account, not just my credit card PIN!) and since that website gets opened in an Android WebView I can't even be sure that the app invoking the WebView doesn't actually obtain my PIN through a key logger. Fantastic.

I’ve personally always found 3DS a bit worrying from a security POV. I’m sure much smarter minds than mine designed it, and had reasons for doing so, but I’ve seen it implemented in iframes on websites I use before. It really doesn’t seem to encourage good security practices in normal users where they’re being encouraged to enter their bank password when the URL they see doesn’t match. Plus the URL itself often refer…

If I were cynical I would say that the purpose of 3DS is to make it easier to scam people. It trains users to input their bank login details into third party apps and websites - something that you were told not to do over and over again in the past. I'm also sure that banks will be far less happy to refund fraudulent charges in these cases.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#99

Then make your service compelling enough for me to go through the motions of confirming the payment in my banking app. Or integrate with Android Pay/Apple Pay. Cry me a river, but I rather prefer to be in control about who gets to withdraw money from my card, and how much.

I want virtual cards. But properly.

Re: Payments down 20% in my SaaS after EU introduced PSD2

#100
post #94

Earlier quoted context omitted.

> SCA—Strong Customer Authentication: something in addition to a credit card number, e.g. your bank account password, a mobile push notification, a SMS code. I've run into this a few times and it has made me very hesitant. You're effectively being asked to log into your own bank account from a link on a third party website or, even worse, an app. It makes me uneasy, because I feel like a malicious site or app could i…

With the way it currently works people can just charge your credit card with the account number only, more or less (everything publicly printed on your credit card). So by default they can already take money from your account which is probably one of the main bad things that could happen anyways.

I was under the impression that this new system changed where the liability lies. With a credit card I can dispute fraudulent charges. My bank's and my interests don't conflict. With the new system it seems like there's a conflict between my interests and the bank's when fraudulent charges happen.
Post reply on HN