The whole point is that you can't skim the CVV2 from the magnetic data and then use it to make purchase.
(Yes, there are probably a lot of retailers breaching their PCI-DSS compliance by storing the CVV, but the point is they're not supposed to. Until we can do chip-and-pin or similar for online purchases, e.g. Apple Pay, the problem remains)
CVV: Not sure why it's on the back, but the point of this is that it's a number that's not raised, so it's not recorded when using a credit card imprinter (less common than is used now).
I assumed that it's a leftover from early days, before online card checks, so the merchant can check that the card is still valid (besides checking signature and ID or whatever). When introducing online checks of the magnetic swipe, expiry date was part of the data transmitted, and early phone/Internet payment systems relied on reconstructing the data present on the magnetic strip, to "fake" a swipe. Then it just stuck from there.
I believe it's a convenience thing for the end user, when issuing a new card - offer a couple of days "grace" - and arguably there isn't much risk associated with this practice: lost/stolen cards are always cancelled immediately.
That would break so much as most of the message formats and batch files use fixed width fields. It's probably the same for the databases underneath. Changing to alphanumerics sounds nice but the check digit algorithm would have to change from Luhn to Luhn mod n. More breaking changes.
Banking systems are one of the ultimate forms of legacy, which is why most of the security additions have been bolted on. Just look at 3D secure - they added an entire subsection to the message format and it was still just another single factor auth method that nobody wanted and everybody hated.
or just get rid of it. It was a relic from 20+ years ago when networks and computers were 1/100th the speed they are today. Let them enter invalid numbers. Let the server return an error (as it already does)
1. Use your real card number. I never do this. 2. Use a merchant-locked card number. I use this commonly for online pizza and other online shops I don't trust much. Once a merchant uses it, only that merchant can use it. 3. Use a one-time card. The number is used once and disabled. Good for one-off orders or skeezy purchases.
Overall I've been pretty pleased. I think the idea that card numbers should be disposable is awesome.
edit, i checked it out. so 1) its no open to sign ups, and 2) you have to have pretty stellar credit to even be considered. so that leaves out most people.
An object which signs every transaction it's asked to sign is an improvement (can only be in one place at a time) but still broken (evil terminals).
What we can agree on is that there should be strong authentication. Apple Pay is the best system I've seen. It creates a unique but static account number that can only be used with Apple Pay, which has strong authentication which is also convenient (Touch ID), so it can be mandatory. Thus it doesn't matter if the number gets stolen as it's useless without Apple Pay.
But payments in general are just totally effed and can't seem to move forward without some sort of fix. as a consumer its both amazing and incredibly frustrating. as a merchant it's essential. Imagine how much money netflix would lose if you had to auth payments every 30 days.