Site requests bank logins for online purchases
lolware.net
lolware.net
But it illustrates how deeply flawed the whole banking sector is that people are willing to give up passwords to third parties or paying insane fees to paypal. IMHO we urgently need a law that makes wire transferees instant, or this dangerous and incredible expensive layers grow for the disadvantage of everybody (expect paypal and sofort).
I think a lot of people (but not banks) would be very keen on having regulated fees for transfers. Of course, not banks.
> I don't understand why we don't do that here.
It really comes down to allowing markets to operate efficiently. Such regulation, in order to be work as intended, creates a price ceiling for the credit card market. This ceiling produces a deadweight loss (in this case, you would likely see it as either a reduction in the aggregate quantity of credit extended to consumers or the perks associated with using the card like fraud protection, ability to file charge backs, and customer support). On the whole (producer surplus + consumer surplus), you will observe such a loss.
Now what makes the government more capable of determining appropriate prices than market participants themselves? Allowing a competitive market to determine prices for credit services will drive the cost of the services to an efficient level. Given that governments are tasked with many pressing issues, it's reasonable to believe that they can only afford to put so many resources into assessing price levels for each regulated good or service. However, each market participant is able to focus solely on determining a price for the product offered. Even if the government can determine the optimal price level for the market, there is necessarily a lag time for the regulation to be passed and implemented, reducing the ability of the market to respond to systemic shocks and changing conditions.
Along different lines, if price regulations on credit card fees are acceptable, should the government install price ceilings on housing (causing reduced incentive to build more) and other markets? Should the price of all meals at restaurants be capped at $10 so more people can dine out? In the latter example it's easier to imagine the ramifications of a price ceiling, but the same market forces are at work.
> People like the rewards but that only works because the cost of those rewards is subsided by a price increase for everyone, even the people paying cash.
That's not true in specific, observable cases, and I suspect it's not true in general either.
To provide concrete examples, many gas stations and vending machines offer discounts for paying with cash instead of card, specifically to avoid the impact of fees on their prices. Additionally, vendors can choose to set minimum thresholds at which they accept credit cards, in order to mitigate the impact on their pricing and profitability.
In general, I assume the rewards are not truly subsidized by merchant fees. From my recollection of previous reading on the subject (I'd appreciate more accurate numbers if someone can provide them), merchants pay 3% to accept the credit card. ~2.5% of the fee is consumed by the cost of fraud. The remainder is split between the payment processor (e.g. Stripe), the issuing bank, and the credit card company. Clearly in a world of 2% rewards cards, a 3% fee does not allow for fraud protection, servicing expenses, and rewards.
My guess is that rewards programs only become feasible when you consider the interest charged on unpaid balances. Somewhere on the order of 50% - 70% of consumers carry debt on their credit cards. At 6% - 30% APR, this expense can reasonably cover the perks conferred by a credit card. If all consumers suddenly stopped carrying debt on credit cards, I suspect rewards programs would disappear rapidly.
[0] https://usa.visa.com/dam/VCOM/download/merchants/Visa-USA-In...
The card companies still appear to be making good profits.
http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%3...
Once a product or service becomes ubiquitous, people will sign on partly due to the social pressure of being left out - e.g. I might get a social media account just in case my friends want to chat to me there, or a credit card because it is the primary method for online payment.
Customers like this are not necesaarily as engaged with the product/service as the initial, enthusiastic ones. The difference in engagement creates a pyramid scheme of perverse incentives, where the companies create more and more benefits for their "engaged" customers and offload the costs to everyone else. Companies get really good at evaluating just how mich cost to offload without disturbing the largely unengaged customers.
This leads to the creation of a secondary market, where you compete on extra features for the engaged part of your consumer base. Here on HN, we proudly acknowledge this fact when companies cater to geeks and techies - if i like your product, I will convince my relatives to use it.
This practice ia not neceasarily malicious, but the cost ofnpleasing your engaged consumers muat naturally come from somewhere. When a credit company adds bonuses and incentives, they are not trying to serve the interests of all their consumers.
I don't know if government intervention is appropriate in this case, especially simple and heavy-handed rules like a price ceiling. However, in this case, the incentives of the government are more closely aligned with that of all the consumers, compared to the company.
(I hope this post was coherent, I rarely write on mobile)
I heard this is in the contracts between merchants and credit card companies. Merchants are not allowed to make prices more transparent to consumers or they will lose the ability to accept credit card payments.
Can anybody confirm that?
I'm not sure where you're getting your info, but that's off by a factor of 2.
Credit cards work great for consumers, just not merchants.
But you are right about credit cards, it's not that much.
Right now I'm more or less fored to use paypal. They offer a very similar service. I'm paying a tiny bit less than 10% of my income directly to paypal.
Some small merchants offer cash discounts, but that's comparatively very rare.
Edit: since you mentioned Paypal, I agree that they're horrible to both merchants and consumers. Stay far away if you can. (In fact, I'm curious why you're using Paypal instead of someone friendlier like Stripe.)
That being said, if you play it right you can actually make far more in rewards than the merchants paid. There's a whole subculture devoted to it: I routinely earn around 4-5% back, to the point that I prefer to pay my taxes via credit card even with the surcharge.
Stripe is meant as a suggestion for merchants, not customers.
Do they have to have all kinds of specialized fraud detection in place to prevent unknown IPs from transferring more than a certain dollar amount? It also just occurred to me that you probably can't have 2-factor enabled on your bank account.
But any transaction or change usually requires generating a single use pin with your debit card and a small card reader. Some also use your mobile phone.
Some banks dont require a code at all for known contacts. Some banks dont require a code at all for small amounts (under 50). Some banks send you a plain SMS with a one-time-password. Some banks send you an SMS with some additional information (receiver, amount) and a one-time-password. Some banks ask for a one-time-password from a dongle. Some banks ask for a one-time-password by entering a challenge code into your dongle and then the dongle generates the new one-time-password. etc.
What I am trying to say is, there is no real standard. The best method I've come across so far is a device in which you insert your debit card, enter your pin, then scan a QR code on the computerscreen and the device will actually show you the receiving IBAN + amount. After pressing OK you get a challenge that you have to enter on the website.
Also in the Netherlands the banks have an API they can use called iDEAL which does the same as "SOFORT" but instead of having "SOFORT" log in to your account, your actual bank immediately transfers the funds and sends an OK to the vendor.
It makes me really angry that bank security isnt standardized and that good systems like iDEAL dont find international adoption. Luxembourg is trying to develope its own version of iDEAL e.g.
But then again ... you just handed your banking credentials to some shady fintech startup.
https://support.coinbase.com/customer/en/portal/articles/194...
It didn't take long to realize how incredibly dangerous that was, and leave.
Banks should provide API access for services like this because it mitigates significant security issues.
The issue is that lots of merchants (particularly in the EU) simply don't want to deal with the fees associated with credit cards so come of up with lots of creative ways to externalize the cost of fraud to consumers.
Of course you constantly get your money stolen. You just don't notice because the loss is distributed evenly. That's why they are so expensive.
I'm suprised people use such a low tech system. I wouldn't even accept such authentication system for my throw-away reddit accounts, let alone for money.
The huge benefit of them is that almost all those security risks are externalized. If someone uses my credit card fraudulently, I don't pay any of the costs. Basically every alternative (Verified by Visa, etc.) is about shifting those liabilities back to the consumer.
You do pay them, but in small undetectable increments all the time instead of random surprise large losses.
If you are purchasing online, all my credit and debit card payments require me to enter 3 random characters from my (previously set up) password.
Not sure what the system is like elsewhere in Europe/worldwide.
Doesn't this mean your password is being stored unhashed?
Not true (notwithstanding that it increased to £30). Some people (myself included) have opted for a chip-and-signature card instead of chip-and-pin, because it is harder for the bank to push the cost of fraud onto me that way.
It's been only seven years (I think?) since chip-and-pin was introduced. It's amazing how quickly all the checkout staff have forgotten what to do when their till tells them to check the card signature. Also almost none of them actually have a pen to hand.
I've seen a lot of people in the US not sign their card and instead write "ask for ID", which seems like a much smarter move!
Australia also has direct person-to-person/business money transfers, but without the one-time-use pins. That this company would even ask for a bank login is terrible and unnecessary.
We do, Sofortüberweisung just acts as a man in the middle and passes through all TAN requests from the banking website to the client. They can't transfer money out of your account without your consent, but they can do just about anything else that doesn't require a TAN.
Not sure about Germany, in the US this is a "technical" issue with the way consumer banking settlement is implemented. The notification of the intent to move the funds is almost instantaneous, the actual clearing takes days in some cases.
I think the US has the problem that it had to set up that way when clearing was done physically (due to the size of the country) and it's now very costly to change, for very little benefit to the banks.
Not saying that Faster Payments are not a good thing, but they would probably cause problems for banks if most money would be moved by it. It works well because the major source of cash management is done due to card payments, direct debits and Bacs. So the normal cash buffer a bank holds throughout the day is sufficient to do fast transactions.
[1] http://www.paymentsuk.org.uk/sites/default/files/publication...
with one time password it does work.
In the USA, you give them a number (which is written on each check anyway) that allows anyone to empty your account if so they wish, with absolutely no passwords or anything else.
See https://www.ideal.nl/demo/en/ for a demo.
Quite efficient, but I think there's fees for the merchant in this case.
I suppose the merchant decides wether to use this or not by trying to find a balance between user experience and fraud risk.
In our case I think the limit is set right above the usual purchase amount (we sell movie tickets). It's low enough that a fraud wouldn't hurt us too badly and there's not much incentive for it either. Also, most of the clients don't have to fiddle with 3dsecure (in my case I would have to cary a fob around, which I never do), so it's a better experience for them.
If someone tries to buy a lot of tickets at once, they are more likely to be doing something fishy so we use 3dsecure.
Do they offer any non SMS options?
An incredible pain. I hate it. ApplePay for the web is far superior.
I suspect it depends on your bank. Back when i used Crédit Agricole, i was indeed forced to do SMS auth, which is inferior.
Most of the time, non 3d secure purchases take a little more time to go through and if the amount is higher than your regular spendings or the charge happened to be in the middle of the night, banks ask for confirmation via SMS anyway. If you go with 3D secure, it just works instantly.
All banks provide virtual credit card numbers with predefined limits too though.
With 3D Secure, you provide the normal card data (i.e. card number, expiration, name, CVV/CVC) to the merchant and are then redirected to an authentication form from your card issuer. There, you'll be asked to either provide a password or, as you described, input a confirmation code from a text.
With Sofort, you're entering your login data to your e-banking account on a login page served by Sofort. They, in turn, use it to log in to your e-banking using a simulated browser and send a wire transfer. You lose control, however, of what else they do: once they are logged in to your e-banking, they can check your previous transactions, send other transfers or they might change your mailing address...
The only downside is if you don't have a local bank account (i.e. as a foreigner) you can't use it.
2FA is done by a) paper code b) passcode generator fob or c) mobile signature, which uses your SIM which holds an RSA key (it doesn't use SMS):
It's nice and works well. All would be great if it weren't for the fact that it's only offered by some banks (mainly cooperatives I think) and only accepted by some shops. Why the German banks have tried to sue Sofortüberweisung out of existence instead of implementing their own universal system that undercuts Sofortüberweisung's merchant fees (0.9% + €0.25 per transaction) is beyond me.
Well, they are trying with wasting 300 millions so far on Paydirekt.
Their rates are still over credit cards though...
It's a good compromise that works almost everywhere.
It was a long time ago but I had the impression that they used some kind of legitimate connection to your bank (with TAN check and my original banking interface) and were only notified about the success (or failure) of the transaction while never receiving the sensitive credentials themselves.
Of course I may be wrong.
I've never used that and only one person I know did use it ever. And even that person felt rather uncomfortable about it. So I don't think it's very common.
A year ago or so it was also exposed that sofortüberweisung doesn't only do the transfer, they actually retrieve details of all recent transfers.
For my bank the transfers of the last month would be accessible right away, for example.
Honestly, I (German as well) didn't believe 1ris right of the bat and went to their website to prove someone wrong on the internet. Oh my was I wrong (apologies, 1ris). Horrible idea.
I wonder who is interested not to already have this. I can't be the first person with that idea.
For a German it is common to have a "check account". The underlying system is called "girocard". It contains a module for paying in stores (electronic cash) and another one for withdrawing money from cash dispensers ("Deutsches Geldautomaten-System"). In addition to that most banks offer their customers access to "maestro" (some debit card service from Master Card) and V-Pay (same as maestro but from Visa). Credit cards are only popular among the younger population as they need them to buy things online (iTunes, Google Play, etc...). However the "check accounts" come with a different kind of insurance. You can read quite a lot about that online, my personal experience is the following: If somebody steals (no matter how) 200€ from your credit card the bank will cancel the transaction immediately, if the same happens with your "check account" you need to go to court to get it back.
Having this system you might imagine why our online-banking is overly complex: You have to login with a username and a password[=PIN] (for some banks you have a fixed username, at others you can choose one). Afterwards you are allowed to send someone money. Therefore you require another one-time-password[=TAN]. This TAN can be obtained in multiple ways: 1. Snake Mail (Just a printed TAN list asking you for a random free TAN), 2. Snake Mail (A printed TAN list asking you for a specific TAN at a given index), 3. Snake Mail (A printed TAN list asking you for a specific TAN at a given index and returning a verification code, that is also printed on the list), 4. Mobile TAN (TAN via SMS), 5. Push TAN (TAN via Banking App), 6. Photo TAN / QR TAN (Optical System which works with pub/priv key to verify your transaction), 7. Chip TAN (Special device that uses the chip in your card to verify your transaction).
After you verified your transaction it takes up to three days before the recievers bank notifies the reciever that he got the money. The real joke is, that everything regarding payments can be transmitted in real time. However some banks make use of these days to generate more interest.
End of the story: If you want to pay something online and you want to recieve it quick you need to either use a Credit Card or some proprietary system that your bank might support (see paydirekt, giropay). As both might not be available for some users they either have to wait for 3 days for their money to arrive at the reciever or use a untrustworthy service like sofortüberweisung (which scans all your transactions and predicts your accountability [Disclaimer: If I remember correctly, German Ref. http://www.pcwelt.de/news/Datenschuetzer-alarmiert-Sofortueb...).
For example, a number of online shops show items as being "in stock" despite having an empty warehouse (or no idea if their supplier has anything in stock). It's possible to transfer large sums, and then have to sit around waiting for a month or two while the shop decides what to do, all with close to zero repercussions for the shop themselves.
If you've paid with a credit card instead of a bank transfer, it's simple enough to kick off a chargeback. (well, not as simple as in other nations, but a short form and a quick chat with a moody call centre rep).
As a recent example, I had a ~5,000zł purchase go wrong (to a well-known Apple authorized store) after the payment was successfully taken, but the store's website had an error and failed to process. Trying to get a response out of the payment processor or the shop was like getting blood out of a stone; the only thing that worked inside of a reasonable timeframe (I gave them a week to even reply to me on phone -or- email) was a chargeback.
While I can live with unfavourable rates, give me the UK's consumer protection laws any day of the week!
I am wondering why you consider borrowing costs for a mortgage in PLN to be gigantic. I just checked and the total annual rate looks to be around 3.3%. Is that what you consider gigantic?
I've lived in Poland for over five years now. It took me some time to get used to operating procedures here. It is different than in the US, which is what I was used to. There are things that are worse than in the US, and there are things that are better. It is not as horrible as you make it seem.
Like everywhere, you have to know how to maneuver. A person having just arrived in the US may not know what to do when faced with bad service. Things that tend to work there is insisting to talk to a manager, and threatening a chargeback. Both will be difficult if you don't speak English.
In Poland, depending on the situation, threatening to report the company to UOKiK (the consumer rights groups) works really well. This will be difficult if you don't speak Polish.
I've had bad experiences in both countries. These were few and far between, both in the US, and in Poland.
Regarding the bad experience you've had... Could the delay in replying been to language difficulties, or were you communicating with the store in Polish?
P.S. You're right on about many retailers listing stock they don't have. Lot's of just-in-time types of stores. It comes down to finding reputable retailers. Not once though have I had a situation where something was not shipped. I've made hundreds of purchases online.
Lowest I've seen is 3% plus base rate. If you typed "poland mortgage rates" into Google, you might be seeing the same infobox as I am, which references a US-based credit union. Taking Millenium Bank as an example, the calculator on their site offers 3.6% - base not included - for 25 years on a house value of 1,000,000zł with a loan of 700,000zł. That seems gigantic to me, and over 25 years it's just painful.
In a way, this kinda illustrates my frustration with the country; you really need to read the fine-print.
> threatening to report the company to UOKiK
Which I severely resent having to resort to; the companies should want to offer great service, and not have to be beaten into it.
Thankfully, since I've been here, I've seen a great increase in the quality of customer service. The Polish people I've met seem to fall into two groups though: either they'll complain; or they'll put up with absolute nonsense for months on end. It's such a shame.
>Could the delay in replying been to language difficulties, or were you communicating with the store in Polish?
Entirely in Polish.
>It comes down to finding reputable retailers. Not once though have I had a situation where something was not shipped. I've made hundreds of purchases online.
Five years ago, I would've said exactly the same thing as you. Then I bought a house, needed an oven, fridge, washing machine etc. etc. etc. all of which - from many different shops - had issues one way or another. I also had the same experience buying tires online recently, despite having thought I'd learned my lesson.
I love being here, and the country and people are great. On a practical level, though, it's not always as rosy as it's sometimes made out to be.
Edit: while I'm ranting, an anecdote: tried to buy a new nice-ish hoover online a few weeks ago. Looked up prices, and all the major players have it - Saturn etc. - and I see a small shop that's an authorized retailer for the brand and figure "Sure, I'd much rather give my money to you than the massive companies" went ahead, and hey presto, I receive every automated order received/packed/sent email from them, only to have the owner contact me a few days later and admitted he had a problem in his supply chain. Fine, these things happen, he promises delivery a week later, and I go with it. Of course, their website still listed the same damned thing in stock and, of course, there was another delay after that week. Cancelled the order, gave my money to Saturn mutter mutter grump grump and had the hoover the very next day. GRRRRR.
Sitting with a 10.x% mortgage right now in sunny South Africa. It's all about perspective. Then again, we're on-par to paying the thing off within a few years, but plenty of people carry their mortgage around for up to 30 years, or more with re-financing.
Here wire transfers still take 1 day minimum. (Except your transferring within the same bank). Doesn't matter if you send the payment in the first or last scheduled transaction window. For the receiver it won't show up till the next day.
Our bank cards won't double as credit/debit cards either. We still have to get an extra card if we want to perform VISA payments. And NFC is still not wide spread. (though that might be a good thing)
I also like how integrated Polish banks are with public services. You could issue a tax or social insurance payment directly from online banking. Granted on the backend it's still just a normal wire transfer but that most banks have an easy to use form for that is great.
I still have my mBank account and feature-wise (and UI wise) it's light years ahead of what my local German bank offers.
I guess here in Germany when it comes to banking we're the victims of early innovation and have to cope with entrenched old standards instead of adopting all the nice new tech.
Here in the UK transfers also arrive within seconds 24/7 and debit cards can be used for online payments. No idea why transfers in Germany need 1-3 days (depending when you submit it) in a time when there's no manual work involved.
...in Germany nearly 80% of transactions are still cash - lots of places that simply don't take cards
Reading this thread that now makes more sense. We have it pretty good in the UK with contactless and chip & PIN (although I hear the Dutch have it better). I always feel the US is so backwards when I visit and they do the stripe & sign thing.However, I still think there are many reasons cash should always be accepted. I won't repeat them here as they're covered in the post.
Nowadays we're switching to chip & sign.
I've heard that we are a test bed for some technologies, given that the sample size is small relative to the world. An example of this was Pokemon Go, which was AFAIK release first here in NZ (and Australia).
In .nl they have iDEAL, as someone already pointed out. In .in, we have to integrate with each bank individually, and there are several aggregators that do this for you, and you don't have to sign an agreement with each bank.
Which is not surprising considering the banks have their own similar scheme giropay/paydirekt and not allowing competitors doesn't seem that fair.
> IMHO we urgently need a law that makes wire transferees instant
SEPA Instant Transfers are coming 2018
PSD2 coming 2018 requires bank to provide API access to third parties as well, so this is basically a solved problem.
Basically, banks provide an API (similar to OAuth? I guess) where the merchant only asks the bank for a specific amount of money, and the authentication and authorization of the payment happens only directly between the customer and the bank.
Why would this be so hard to so in other countries?
I.e. when you're ready with your shopping cart and click "pay", and give your credit card number, then next thing is a redirect to the bank's page (where you really should check the URL and SSL certificate...), you give your OTP for bank login, and this authorizes the credit card payment, you get a redirect back to the seller website and complete the transaction.
Yeah, we are really training people to be vulnerable to phishing scams, aren't we.
The advice I give is that if you didn't type the URL of the bank web site into the address bar yourself, it may not be your actual bank you are talking to.
And as I understand the customer cannot charge back the payment later.
> IMHO we urgently need a law that makes wire transferees instant,
Why not just use card processing systems like Visa? Are the fees too high or are there privacy concerns with sending personal data to USA?
This is exactly why the PCI Security Standards Council is a thing. They need to have someone straight up tell them something at least as serious as "fix this, or we will no longer take your credit card payments". Honestly, it's better off being "we aren't taking your credit card payments, you should know better. Fix this and go through a security audit and we might reinstate you".
I've sadly seen all sorts of stuff spring up around this in australia, like https://polipayments.com/Buy (which e.g. is one of the only ways a normal person can pay for a jetstar flight without a credit card surcharge)
https://www.americanexpress.com/au/content/credit-cards/abou...
It appears that AmEx offers both, I have a credit card Amex via my bank that has both a spending limit & doesn't have to be paid off each month (though I always do anyway). But I learned something today, thank you!
Here, Amex credit cards are far more common than charge cards, at least due to how regular banks can issue an Amex.
Fun fact, they have a limit to how many credit cards you have have with them (6?) But no limit on the number of charge cards they will issue you.
That's excluding AMEX cards issued by third parties.
"no one can see your bank details" it says on https://www.polipayments.com/security which is a fraudulent claim, yeah the hell you can, its being sent to your server, not my bank, this is crazy. It also says they don't cache anything -- all kinds of criminals claim they're up to no harm. POLi says they're up to no harm, why should I believe them? There is NO EXCUSE for using POLi vs. just paying with your bank, if a business offers POLi and not bank transfer directly or a credit card, i would never even remotely entertain doing business with them. NZTA is not a business though, it's a government agency. You can do it in person though (transfer ownership of a car for example), or by CC, so whatever, I don't understand who would ever use POLi, the naive? Hopefully they go bankrupt in the near future.
POLi is instant. Bank transfer is anywhere from 1 - 3 days. Until banks finally implement instant transfers, POLi will still be useful to some.
Is a paypal button really so hard?
Also, how are they not shut down? It seems a single user sending that screenshot to Amex should be more than sufficient to close any merchant account they have.
Not sure exactly how they services work under the hood, but it wouldn't be too dissimilar to just screen scraping.
https://en.wikipedia.org/wiki/POLi_Payments
It's discouraged by banks and you don't see it as much as you used to (in NZ anyway).
This ended very soon, because people here are quite sensitive for such practices and Financial Supervision Authority begin informative action as this was against the law.
But what was more important, people quickly realized that they could abuse this process. After such payment, they log in again to bank account and cancelled wired transfer (in most banks we can cancel wired transfer unless it actually leave your account few hours later), and then change their bank password. From point of view of shop, payment was successfull, they process order, but never get cash for it. This was the reason such payment systems ended very soon.
Like kybernetyk and other wrote, in Poland we have very modern banking system, there's no problem to make fast wire (up to 15min) using official banking systems or reliable payments systems - you authorize each transaction directly in your bank system without revealing your login details to the middleman.
Unfortunately that doesn't seem to change. The big banking networks have their own debit system that's not compatible with many international online payment systems. There is thus little incentive to switch to sth like Visa/Mastercard debit cards.
> It's because Germany has a very low credit card penetration rate and the German debit cards cannot be used to guarantee a transaction.
No, really: WHAT THE F&CK?!?
In Poland we have instant payments services for years already. Each of the services directs the user to their own bank's website (login form). Payment clears instantly and confirmation of the payment (which is machine processable) is sent to the shop in a matter of minutes and with no human employee whatsoever.
We have these systems working for years, and the use ranges from buying e-books through food to power tools and clothing in on-line auctions site.
Leads to me avoiding small shops when I'm there, not really sure if that's the desired effect.
Overall, if attention to this issue can stop one other company doing this, I'll be pretty happy.
I correct myself - maybe it does!
I've lived PCI for a while - I don't think this particular issue would fall under their purview. As per PCI-DSS doc, it is primarily concerned with the secure "acceptance, transmission and storage" of cardholder data.
If they use a 3rd party payment processor for their credit/debit card transactions, they will only have a very limited PCI scope (probably just SAQ-A) which will basically say "oh, make sure you send it to your processor over TLS" and don't peek.
This particular instance is probably one for the regulatory body, which in our case in Aus would likely be APRA.
In the meantime I've tweeted @AmericanExpress about this.
And doesn't it look suspicious if the logins into different accounts are made from the same IP belonging to the online shop? Some banks in my country even require SMS verification if you are logging in from new IP address.
Mwave has identified online banking access as the quickest and easiest method to get access to your banking information. In order to access this information, it is required that you provide your username, password, and any security questions associated with your online banking account.
Well, one can't argue that they're wrong in making that statement. However, that's the reason we don't give random websites the credentials for our "online banking access". :-)
This was back in the pre-EFTPOS days when a store would have to keep a carbon copy of the customer card imprint (as well as their signature). We were told to guard those slips like gold, and dispose of them properly when not needed any longer, because with that information, we could in effect impersonate the customer elsewhere.
I would say that things have changed markedly these days, but I wonder if the legislation, especially here in Australia, has kept up with that, seeing as a customer's login credentials are effectively the same as having their signature which can be copied?
Well, that's certainly true...
Bank passwords alone wouldn't work on any of my accounts because it would detect a different computer and request secondary authorization. It does this by looking at the information the browser sent...and...oh...oh. Geez I hate security theater. Is there anything less secure than the information sent by your browser?
Verified by Visa is secure because it uses a shared secret (not terribly unlike how JWT works) for the merchant to redirect you to the bank (with information on what card you used), who verifies your username and password and that that is your card, who then redirects you back to the merchant with something that says "Yep, we verified them"
As being shut down is a genuine business risk they strive for legitimacy - id be surprised if it was in-country and operating without at least tacit agreement of banks. Even slow moving banks could counter against this type of browser automation technically - not to mention legal action. No large merchant would fancy negative security related PR either.
Honestly speaking - the payments industry is full of hacks like this. Look at US p2p systems built on ACH refunds. Or using 3D Secure for identity verification. Or processing pre-auths of 1 cents and rolling back to add a card to a wallet.
Banks are slow and competitive, schemes are just slow, central banks often take a wait-and-see approach. When they get their act together systems like this tend to be replaced or evolved into more sensible and durable solutions - but that can take awhile.
And in the meantime everyone tries every avenue possible to reduce fees or provide a better UX (in this case at the expense of consumer protection).
"Please note: Due to the rise of credit card fraud and for your security all credit card orders will be subject to detailed security checks requiring further documentation; that may include Driver Licence, CreditCard or bank statements. If your order does not meet our security check requirements, you will be contacted and further credit card security procedures will be implemented.
As part of our verification process we will utilise various procedures to ensure ultimate protection to the Credit Card holder. These processes may include but not limited to charging a small amount randomly under $2 requiring confirmation prior to approval; verbal verification via phone or a request for written Authorization, photo identification including valid Driver Licence, Utilities bill or the copy of the credit card or a request for your bank statement displaying the debit entry.
Mwave may also use a verification service powered by BankStatements.com.au, the Australian leader in automated bank statement data retrieval. Since 2013 BankStatements.com.au has provided secure, automated data retrieval services to over a quarter of a million Australians as part of their credit applications. "
In The Netherlands they are launching 'iDIN'. Which is a bit like OAuth 2.0, so it only provides the webshops with the things they need (and a bit more like age. So yay, privacy issues).
But, I had a couple of mildly negative experiences (slow to ship, items listed as in stock weren't, etc.) and I stopped buying from them.
This, though, is just crazy. I can't believe their merchant bank even allows them to do this.
With Jetstar, up until a few months ago, you could do your own bank transfer, but now poli is the only option.
I've met the CEO of bankstatements.com.au at a trade conference. Currently it's hard to get data feeds from banks - these guys are logging in, scraping bank statements and then providing them as digestable feeds.
Pocketbook is another Australian fintech that was recently acquired that do the same things with credentials.
The banks know they're doing it, it's against terms of service, but seem to turn a blind eye.
POLi seems to have more reputation but I still feel dirty the few times I've been strongarmed into using it.
When I moved to Oz and tried to buy something online, I was quite taken aback that I was being asked to enter bank login details on 3rd party sites directly. Felt completely unsafe, so haven't used it yet.
That is strange. I never begged for a charge back with any of my credit cards. When I say the transaction is fraudulent or not authorized by me, I get my money back. Always.
The merchant can then sue me, if he thinks different. Is that not what happens with all credit cards in all countries?
So I guess it's based on your routing number and whether your bank's online system has the proper framework to allow it.
[1] http://www.ecommercebytes.com/C/abblog/blog.pl?/pl/2009/2/12...
It probably reduces fraud chargebacks to nearly 0.
This is different; mwave is a retailer, all they're doing is receiving a payment.