>Successful auth is the issuing bank telling the merchant - 'yes, the customer has the funds and the money is yours for the taking via the capture request against this auth.' Which is a GUARANTEE. Yes, as a means of customer protection it expires if the merchant did not request the capture within a certain timeframe which is at least 2 weeks, 4 weeks in most cases.
That's a pretty shitty guarantee when the bank can deny settlement anyways, and FWIW mine seem to expire in 5 days.
>6 conf is a rule of thumb bitpay (and other bitcoin payment processors that I'm aware of) are following before GUARANTEEING the funds to the merchant. sure, if this is a P2P transaction and I was personally selling you $10 worth of merchandise I'd be ok with 1 conf, when talking 'industrial' scale payment acceptance things work just a little bit different.
Unless you're talking about transactions worth tens of thousands of dollars it's simply not worth it for an attacker to even attempt such an attack (not that it'd be very likely work anyway).
And last I checked bitpay is just fine with 1 conf transactions and will happily tank the risk for you. I'd assume the risk is quite small since I haven't ever heard of such an attack actually happening.
>And finally since you're claiming high tx fees are 'a far stronger guarantee of settlement than a cc authorization as it's way harder for the customer to reliably cheat you' - how would you cheat the merchant after the auth (let alone auth/capture) went through?
I could just claim that the transaction was fraudulent. I could contact my bank and forward them a fake email from you claiming that the auth was an accident (done this before, although not with a fake email).
Oh, and most shockingly... I could just use a stolen card!