It's super cheap and has saved us tons of money and headaches!
Not only that, but processors routinely penalize merchants who fail to screen fraudulent transactions sufficiently with fines and eventually banishment from the processor.
A few processors might provide something like this as a paid value-added service, but it's unusual. The next-gen all-in-one card processors would make a lot of money if they offered this.
But if you think about the case he describes in the article, there is very little distinguishing a fraudulent purchase to test the validity of a credit card vs a legitimate one, unless they are completely careless and initiate multiple transactions from a russian IP, in the middle of the night.
The biggest problem is the very expensive chargeback fee from Stripe. It looks like he could avoid some of them by, for example, reporting accounts that had no activity as fraudulent and refunding the purchase before being hit with a chargeback claim, but I don't see how putting such a burden on businesses makes sense to begin with. A fee that grows in proportion to the % of chargebacks the company generates would be more fair.
1) The implementations by Visa and MasterCard have security weaknesses, terrible usability and look like phishing: http://www.cl.cam.ac.uk/~rja14/Papers/fc10vbvsecurecode.pdf
2) My understanding is that my bank shifts liability to me for 3D Secure transactions. Why would I want extra liability?
Fortunately here in the USA I haven't been asked for my credentials in at least 10 years. So it seems to have died the death it so richly deserved.
Do people encounter this on a daily basis?
(The redirect sometimes happens, but it's automatically approved.)
It sends a text to my mobile for me to plug into the form to approve the txn -- thus, not like phishing in this case. But for a while this was a real nightmare because my mobile number changed, and I couldn't figure out how to convince my bank to store the new number (it turned out after many months and phone calls I was sending the requisite paper form to the wrong address for my type of account...).
There could be, say, an HTML5-exposed API capable of triggering "super-modal" forms (like OS UAC does) if-and-only-if the page is being served from a secure origin cross-signed by some "Web Banking Working Group Certificate Authority" that all the banks and OS makers are members of.
Unfortunately the banks have less motivation to invest in this as long as the costs of fraud are pushed onto merchants and all of the major players charge similar fees. If something like Apple Pay starts to catch on, perhaps we'll see that change once the banks’ main concern is avoiding a single vendor getting too much market share.
[1] https://c2.staticflickr.com/2/1218/1438197131_1e0d474266_b.j...
Another one uses a smartphone 2FA app.
For every transaction the customer must enter the OTP. It wouldn't serve much for subscriptions, though.
Good lord! Reading through this document is like reading a primer in how not to make a secure form.
[1]: https://channel9.msdn.com/Blogs/TheChannel9Team/Ben-Armstron...
with full 3d secure payments the liability shifts to the customer and you will have no liability. because the customer verified the payment him/herself by hand with the otp.
p.s. i am yet to read that link.
As I mentioned in another reply, "Verified by Visa" is a stupid joke. Which, fortunately, I don't think I've seen anymore in at least 10 years. The paper linked in the other reply to you provides more details of how stupid this thing is.
IIRC basically the first time you encounter it you get a popup asking you to create an account. Yeah, right, I'm on some random website and I'll just start entering all sorts of security information into a popup. NOT! I did some checking when I first encountered it, and decided it was legit. But 99% of people won't. They'll just say "fuck this, I don't need this shit". They will then go elsewhere.
I encountered it a few more times after I first signed up. And it would have maybe a 50% success rate of actually "verifying" my transaction. I'd enter the information and nothing would happen.
It's the antithesis of the friction-free way that Amazon does business. I probably use Amazon once every few years but they still have all my info saved. I don't have to enter an address, I don't have to enter a CCV, I don't have to enter a credit card number. It only takes a few mouse clicks to complete an order on Amazon.
So, which payment method would the average person prefer?
Edit: look at what Wikipedia has to say, it generally makes the same points as the paper. Why would anyone voluntarily want to use this? https://en.wikipedia.org/wiki/3-D_Secure#General_3-D_Secure_...
- https://www.maxmind.com/en/minfraud-services
So not a full list of factors, but some of them...