MasterCard Ending Signature Requirements
consumerist.com
consumerist.com
This has absolutely nothing to do with us being in a so-called "digital age". Signatures have been completely ignored by virtually everyone except autograph hunters since basically forever.
The problem is that the person receiving your signature usually has no way to verify that the signature belongs to the person authorized to whatever it is you signed for. In the case of credit card signatures, the best they can do is try to match your signature to the one on the back of the card. I think I've had that happen exactly once in my life.
Even there, the possessor of the card can easily replace the signature on the back with another one with minimal forgery skills, or even scrawl something vaguely resembling the signature on the back of the card and get away with it. Nothing "digital" about this forgery or the lack of attention or care from the people receiving it.
Banks are really in the best position to verify signatures on checks that they get. They could potentially access a huge database of authentic signatures from previously cashed checks and do some sort of AI pattern-matching against the signatures they get before cashing them. But do they? I don't know. But I very much doubt it.
Besides, at least in my case, my own signatures vary pretty widely from other ones I've signed in the past. Sure, there's some resemblance, but they're far from exact copies of each other, and a forger wouldn't have to try very hard to sign a similar one after glancing at a sample.
When you call to dispute a charge, your credit card company contacts the original merchant. They can either request information from them about the purchase, or just immediately side with you (a chargeback). If they perform a chargeback, the money gets removed from their merchant account and deducted from your bill, and they get hit with a chargeback fee.
One of the reasons merchants collect the signature is to have more data to give to the credit card company during an inquiry, or so they can try to dispute the chargeback. If you claim you never made the purchase, having your signature on a slip helps the merchant with the dispute, as would having you on video signing for it. Credit card companies side with the customer a vast majority of the time, but if the merchant has reasonable proof that you knowingly made the charge (which might include that signed slip), the merchant can win those disputes.
Previously not having a signed credit card slip usually meant the credit card company automatically sided with the customer over the merchant. I doubt dropping this requirement will make it easier for merchants to win chargeback disputes, though.
I couldn't help noticing that my signatures were very very different on the first few papers I signed compared to the last few.
I think I was suffering from signature fatigue, but despite everybody exchanging passports and IDs, I wonder if I could come back later and "prove" the signatures on some of the papers were not my own - after all they look so different..
You can pretty much write your name any way you like; as you say it would come down to an argument of you saying it wasn't you and a reasonable arbiter deciding how likely it is that the pages you're disputing have been added after the fact
And even that "best" attempt is pathetic on the face of it. What, the person behind the counter at 7-11 is now supposed to be an expert in graphoanalysis? "In between cleaning the bathrooms and stocking Coke, you have to verify the authenticity of the signatures on these contracts."
Checks have very little metadata to help in identifying fraud. CC transactions have time, location, and behavioural patterns to aid in catching fraud.
If you didn't have signatures, it would be difficult to prove that someone was trying to steal your money if they paid with your card. They could come up with all kinds of excuses, such as "I thought it was my card", etc, to confuse the process.
With a signature, it doesn't matter if the person signs it mickey mouse, because it's not what is signed it's the act of signing itself which then puts fraud into play. They are signing that they are you, and at that point fraud is much easier to prove, since you can produce a video of them signing that they are you.
Also, the punishment is no longer dependent on how much they took or tried to take, because it's no longer about the taking of the money itself but about the fraudulent actions to do so.
Much of the financial system, particularly the older parts, are set up in the same way.. where security isn't about preventing the money being stolen, money can be easily corrected later (just edit it back into the account), it's about making it easy to catch and prosecute offenders. It's not difficult to rob a bank, you can just walk into a bank, ask for the money and they'll give it to you, it's difficult to do so and keep the money after-ward.
Security is provided by the legal system, not by ever stronger locks. I wonder if there's any way we can learn from that to improve security elsewhere such as online, or whether the international nature of the internet means that that model is broken. (For example see the SWIFT hacks, if they were carried out by NK then the legal system no longer works as a deterrent).
Somewhat related to "money can be easily corrected later", digital system designers increasingly accept their system will get cracked into and the main issue is how to recover from that (at least operationally).
+ It is a trade-off between costs of the fraud detection system versus money lost through fraud.
+ It is a trade-off between time it takes to do proper fraud detection versus losses by slower payment processes.
I don't know about papers in this direction. Would be a fun read. A bit like the effect of voluntary disclosure of evaded taxes like in this working paper: https://www.econstor.eu/bitstream/10419/110841/1/cesifo_wp53.... Is the net effect beneficial or does it lead to more tax evasion?
There's inherent difficulty in proving that it was actually you, but that gets handled as its own problem. Someone forging your signature could get you dragged into court for breach of contract.
It's worse than that these days because you normally put your signature on a totally-broken too-small stylus pad that doesn't look as good as your worst ever pen-on-paper signature. Even if I made my best effort at most POS machines, it couldn't be used to prove anything.
I know for a fact that Bank of America does this. I've been stopped on multiple occasions there after trying to cash a rent check from my girlfriend that I filled out and signed for her. It's kind of annoying but I'm glad theyre doing it.
I think it is for just this reason that MC is ending the signature requirement. They’re ain’t defendin’ shit if they think they’ll convince anyone that the 100 pixel-wide smear was done by me and not someone else.
People forget buying things. Our legal system has a higher bar for falsely disputing a signature.
They tried to claim that it couldn't possibly be my card because they didn't match. After a few minutes of back and forth with the cashier I realized that I had already paid for my chips and smokes, so I just grabbed my stuff and left.
It was incredibly frustrating.
I haven't signed my cards in years. I know they technically say they are not valid unless signed, however it's not a problem around here: on the other hand, many stores will not sell anything with only signature validation any more (PIN+signature was never a thing here, and with PIN your card is not in the interests of cashiers).
Heck, back when you had to hand over your card for the cashier to swipe it, I'd write "check id" on the card's signature line, and I had maybe three people total ever ask me for my ID.
That's actually a violation of the cardholder agreement, FYI.
This was a long time ago btw.
And that's why most of the rest of the world uses pin numbers instead of this signature farce
Or, you know, ask for some ID. "but it violates the card agreement" card companies can go take a hike
Signatures have been all but obsolete for purchases in Europe for years; I can’t even remember the last time I used it here. Everything is contact or contactless EMV now, authenticated by PINs.
I guess the tap does defeat the pin as a security measure
Same problem at shopping malls in China, by the way (where the language makes the explaining even more fun).
When did you start paying with the PIN?
That's infuriatingly annoying.
Not really my experience. And I live and work in Europe, moving often all over the EU and sometimes outside it.
It is less frequent than before but still happens.
edit: huh, it's actually more than 6. According to Commonwealth Bank, it can be up to 12.
With a PIN based system, on the other hand, they're blocked from making the transaction to begin with.
The usefulness of signatures as a means of verification reminds me of the scene from The Fugitive where Kimble saves the kid's life by scribbling an illegible "doctor's" signature on a medical order: https://youtu.be/nxotPpVYVcc?t=95
Signatures are really only useful as an indicator that you agreed to something in entirety, it clears up legal grey areas.
So, when a judge asks "did you agree to this?", you can't say "I agreed to X not Y". Instead they can say "is this your signature?" and the intent is clear. It's really just a symbol of total agreement.
Last time I signed anything card related was 2012 (their card reader was malfunctioning). Oh and of course my 2017 US trip...signed lots of things there.
Enjoying the UK system. Especially their tubes & trains allowing contactless. Very convenient with a corporate card that pulls through to expense system. That way I know anything on there = I meant to expense that when I took the trip.
> “See ID”
> Some customers write “See ID” or “Ask for ID” in the signature panel, thinking that this is a deterrent against fraud or forgery; that is, if their signature is not on the card, a fraudster will not be able to forge it. In reality, criminals often don’t take the time to practice signatures. They use cards as quickly as possible after a theft and prior to the accounts being blocked. They are actually counting on you not to look at the back of the card and compare signatures; they may even have access to counterfeit identification with a signature in their own handwriting.
> In this situation, follow recommended steps listed above under Unsigned Cards
> Unsigned Cards
> While checking card security features, you should also make sure that the card is signed. An unsigned card is considered invalid and should not be accepted. If a customer gives you an unsigned card, the following steps must be taken:
> • Check the cardholder’s ID.
> Ask the cardholder for some form of official government identification, such as a driver’s license or passport. Where permissible by law, the ID serial number and expiration date should be written on the sales receipt before you complete the transaction.
> • Ask the customer to sign the card.
> The card should be signed within your full view, and the signature checked against the customer’s signature on the ID. A refusal to sign means the card is still invalid and cannot be accepted.
> • Ask the customer for a different signed Visa card
https://usa.visa.com/dam/VCOM/download/merchants/card-accept...
Sadly, very seldom does anyone even look to confirm it is even signed.
Methinks I'll try your solution. Thanks!
Be that as it may, your options are generally
a) show your ID anyway b) walk out without the stuff you came for
I doubt any merchant ever has been punished for violating the cardholder agreement in this fashion.
There used to be forms on the Visa and MasterCard site to report this specific violation. So, yes, I imagine some merchants were reprimanded for requiring ID.
My parents used this system. When they'd send me to the store with their card, I'd just say I didn't have my ID on me. Never had an issue. (Note: don't do this without the cardholder's permission.)
Disclaimer: I am not a lawyer. This is not legal advice.
Goodness knows what it cost but there was a giant campaign to get everyone to ensure they had a pin number on their cards.
And at the same time, you can use PayWave to just wave a credit card for a transaction with no PIN required - presumably for smaller transactions. Even so it was strange to go through this giant campaign of ensuring your card has a PIN and then not needing it. "IMPORTANT! Ensure you have a PIN on your credit card! (although you won't need it)".
https://www.lifehacker.com.au/2014/01/credit-card-pin-number...
I've wondered what sort of security issue PayWave is..... what if somehow a criminal got a PayWave reader and surreptitiously touched it to everyone's bag and pocket on a crowded train? Is there a possible exploit there somewhere?
http://www.theaustralian.com.au/business/financial-services/...
> Goodness knows what it cost but there was a giant campaign to get everyone to ensure they had a pin number on their cards.
I never saw this... It was widely reported in the media but use of signatures was rare enough that few people cared.
> And at the same time, you can use PayWave to just wave a credit card for a transaction with no PIN required - presumably for smaller transactions.
Not presumably, the maximum is $100 and when you reach the $100 limit you still wave, you just need to enter a PIN afterwards.
> I've wondered what sort of security issue PayWave is..... what if somehow a criminal got a PayWave reader and surreptitiously touched it to everyone's bag and pocket on a crowded train? Is there a possible exploit there somewhere?
It's not bulletproof but damage is pretty limited:
- If you use an actual portable payment terminal to process transactions on the spot, the fraud rate will be incredibly high and you're not likely to keep any of the money. The transactions will be reverse and you'll be fined and/or prosecuted.
- If you capture a token and try to use it, you have to do it before the actual owner does because if the bank sees tokens out of order it'll freeze the card.
- Banks have pretty good guarantees on contactless fraud.
Edit: And my Samsung Pay works contactless as well, and is linked to my bank account same as my MasterCard plastic - but with the added advantage of giving me instant electronic receipts.
Yeah, I thought about that too. On the plus side, Apple Pay works pretty much anywhere PayWave is accepted, and Apple Pay requires a fingerprint or face.
https://www.youtube.com/watch?v=HRXb-FZ6WFM
Basically - yes, it's more secure than just a credit card number, though if it works the same way it did in 2012 there's still all sorts of shenanigans you could pull.
McDonald's clearly cares about this. They have the fastest card readers around. I've always wondered if they are actually running the transaction in real time, or just collecting the card info and running it later, accepting the losses from the occasional bad read.
In the US, that signature is a on a line right next to the words "I agree to be bound by the cardholder agreement", or some similar language. If I had to guess, the signature was originally supposed to be a mini-contract that yes, you're going to pay back the card company for what they just paid on your behalf. I don't know if such has ever been been taken to court to be enforced, however.
Because that would be financial fraud for which they can go to jail.
Fraudsters = people trying to get free stuff, as well as merchants putting through bogus or altered transactions
This won't work if they've worked retail and realized that most cashiers don't check (it isn't worth it) and that most folks scribble their signature so sloppily - or with a line - that it doesn't seem to make a difference anyway.
(the NY subway ticket system is similarly archaic!)
A significant part of this is differences in credit card usage patterns. It's fairly common in the US for people to have a large number of credit cards (think ~10), not least because various stores have their own cards which get you discounts. From what I can tell, other places people have a much smaller number of cards.
If a person has 10 cards, and each of those card issuers wants their card to actually be used, the game theory is against them making the person try to remember a PIN to use their card. Even if you posit that they can solve the coordination problem and all agree that they will simul-roll-out a requirement to use a PIN (which is not trivial at all, given lack of widespread support in terminals), they all worry that with 10 PINs to remember the cardholder will just say "screw it" and stick to using only one or two cards, and it won't be theirs.
Yes, the cardholder can go through the trouble of changing PINs so they all match. But then you have to gamble on them doing that...
So that's one reason issuers haven't been pushing very hard for chip+PIN.
Next, credit card fraud in the US is currently limited through various Orwellian big data measures, whereas Europe was rife with credit card fraud when EMV was originally deployed, so the cost benefit analysis made it much more appealing in Europe.
Basically, path dependency is a thing. Americans routinely use checks to pay rent for similar reasons.
Physical credit card theft is a negligible source of fraud, it’s all about card cloning, which EMV does a moderately good job of preventing.
Prior to that event, I can’t think of any transaction we have had in decades here in the US where we were required to pay by check. Cards or electronic payments of one sort or another have almost always been available to us.
I live in France and my VISA and Mastercard cards have a chip which is universally used in Europe (France is at the low end of CC use, discovering contactless payments since two or three years. Germany is even worse. At the other side you have Estonia or Poland which could well be cashless).
There is still a place for a signature, which I leave empty or write "check ID"
Then again, even writing weirdly never really triggered a response...
If I was going to draw a bunny or a seagull, it would take at least several minutes, if not an hour or more. And even then, it would be horrible looking.
Living in Saigon Vietnam now, doing anything out of the ordinary like that always makes people smile.
Considering the price advantage changes week by week, the sole major differentiator in my routine is what payment methods they accept, and that makes me to go to the one with Android Pay almost exclusively.
I really hate how a year ago it seemed rollout was better than it is now. Every damn store and restaurant is trying to use their own app as a payment system rather than just using Android Pay, its bad enough that the local Burger King told me they the Android Pay no longer worked on the terminals and to use the app instead, which wasn't NFC based and required me to reenter my card info to start using it...
I was confused because the courier site showed a digital signature that wasn't mine and obviously I hadn't received the item.
It turns out the driver, running late presumably, had been signing deliveries well before delivering them.
[1] https://consumerist.com/2017/10/19/mastercard-ending-signatu...
[2] https://newsroom.mastercard.com/2017/10/19/no-more-signing-o...