The issue is that lots of merchants (particularly in the EU) simply don't want to deal with the fees associated with credit cards so come of up with lots of creative ways to externalize the cost of fraud to consumers.
The issue is that lots of merchants (particularly in the EU) simply don't want to deal with the fees associated with credit cards so come of up with lots of creative ways to externalize the cost of fraud to consumers.
Of course you constantly get your money stolen. You just don't notice because the loss is distributed evenly. That's why they are so expensive.
I'm suprised people use such a low tech system. I wouldn't even accept such authentication system for my throw-away reddit accounts, let alone for money.
The huge benefit of them is that almost all those security risks are externalized. If someone uses my credit card fraudulently, I don't pay any of the costs. Basically every alternative (Verified by Visa, etc.) is about shifting those liabilities back to the consumer.
You do pay them, but in small undetectable increments all the time instead of random surprise large losses.
If you are purchasing online, all my credit and debit card payments require me to enter 3 random characters from my (previously set up) password.
Not sure what the system is like elsewhere in Europe/worldwide.
Doesn't this mean your password is being stored unhashed?
Not true (notwithstanding that it increased to £30). Some people (myself included) have opted for a chip-and-signature card instead of chip-and-pin, because it is harder for the bank to push the cost of fraud onto me that way.
It's been only seven years (I think?) since chip-and-pin was introduced. It's amazing how quickly all the checkout staff have forgotten what to do when their till tells them to check the card signature. Also almost none of them actually have a pen to hand.
I've seen a lot of people in the US not sign their card and instead write "ask for ID", which seems like a much smarter move!