I used to work for a small ecommerce webdev shop. I’ve worked on sooo many shitty insecure shopping carts over the years I simply know not to trust basically any small website asking for my card. Completely unencrypted, storing CVVs, sending CC details as GET parameters, I’ve seen it all. It’s painfully common!
If a company is not a huge name, and is handling your credit card info themselves, they are mishandling your credit card information in one way or another. I guarantee it.
Having been through PCI compliance, it’s no joke. It’s really not worth doing yourself in my strong opinion.
Not to be snarky, but a huge name is no guarantee of safety. See: Target, Equifax.
If trusting one entity can already be insecure, having to trust dozens of them is nuts.
Handing a merchant credit card details "feels" like handing them a blank Check and trusting them to not take more than they should because of the risk of them losing the data.
Edit: The digital hash should say where money comes from, to who, for what purpose, time, auth code and so on.
I live in Denmark, and they have a system of phone banking here called "Mobile Pay" it works kind of like that. Where you transfer money to the merchant public phone number and show them proof of sending.. However it only works for in-person payments where you can swing your phone to show.
Seconded. At the risk of simply rephrasing everything you just said:
It's a pity the banks and credit card companies just refuse to innovate.
When I buy something from an online vendor, they should never get my full card details. PayPal ameliorates things (you can generally trust PayPal), but really there should be no need for PayPal. The banks/credit-card companies should provide a convenient way to authorise the payment, in a way that doesn't trust the vendor.
Here in the UK, we already have chip-and-pin, and card readers (the kind that show unique numbers - they're used for online banking), but we're still stuck with the trust-the-vendor-or-use-PayPal model for online payments.
Using card-readers for online payments would also help with credit-card theft.
I agree, but I also have a counterexample:
"Oh, you bought SOFTWARE?? All those pretty marketing pages about our amazing safety and protection system do not apply to virtual products. We agree this vendor totally screwed you over, but it's not our problem."
(this was a few years ago, may have changed)
edit: It eroded my trust in the company completely. I don't really have an opinion of their technology.
At a glance it seems software products are now covered - https://www.paypal.com/il/webapps/mpp/ua/useragreement-full?...
If their online banking password policies are anything to go by — Halifax and especially Nationwide — then very definitely no thankyou.
Nationwide asks you to set three pieces of memorable information. You can then log in with any 1 of those 3, at your option. https://onlinebanking.nationwide.co.uk/AccessManagement/Logi...
This seems obviously stupid to me, but I'll accept that Nationwide knows better than me if HN says so.
Well of course I trust my bank. No escaping that. The point is not to have to trust the vendor.
> online banking
I wasn't suggesting a payment system based on signing-in to online banking.
Your complaints about online banking security may be valid, but aren't the same issue.
Google Pay follows this standard. Apple Pay has a similar, but Safari-specific, API.
The alternative, telling the user to manually go to their bank and generate a token for amount X, would lead to so many people not bothering, and to so many lost sales. Or copy-paste errors, because users are dumb.
Many just don't turn it on because it's another step and they don't have issues with fraud, as well.
Adyen works with your shop no matter how PCI compliant and well-built, so you can have it in the checkout or the separate payment page. Interestingly you can also pay by paypal via Adyen.
I have found the online login bit for merchants to be as flaky and naff on Adyen as other payment gateways of yesteryear - forever timing you out and not letting you in, just really bad UX as banks seem to prefer.
I don't see these blockchain based payment systems as fundamentally solving anything in online payments needed for ecommerce, the Adyen tool kit is pretty large and bits such as the 'token' are not needed in real life, or some of the stranger mobile payment solutions that also promise to change the world as much as the crypto-coin 'promises'.
Just because a vendor doesn’t NEED to store your CC doesn’t mean they’re not out of sheer ignorance or incompetence.
As a reply you'll get some kind of token that you can use to actually charge the credit card (or SEPA, or whatever else).
It's a secure way of handling payment without the "we're now redirecting you to some payment site" which BY THE WAY Paypal themselves offer in the form of their Braintree payment services.
Think about java updates and a certain antivirus product as a great example of insane greed :)