How Payment Transaction Processing Works
blog.privacy.com
blog.privacy.com
In Europe, where debet-cards are the de-facto standard, most online shops use a payment aggregator, which forwards your payment request to your online banking platform of your own bank, which you then have to confirm. Sometimes using a cryptographic challenge/response from the chipcard, but more and more just by using your phone and banking app to scan a QR code and validate the payment there.
This completely side-tracks the insecurity of creditcards, there is nothing to steal.
After the code is processed, you get a request on your phone, with the merchant's verified name, the transaction amount, and the title of the transaction. You're able to deny this request, so it's perfectly safe to give your code to someone you don't fully trust, i.e. to let a child buy something, or if it's just more convenient if someone makes a purchase for you, but you still want to pay for it. That happens surprisingly often in families, where you're talking about a particular product, one person looks it up and is ready to purchase, but you're the one who actually wants it. You also don't have to worry about the security of the device you're entering the code on.
Of course, since entering a code is so easy, this often also works in ATMs and shops. You don't need fancy, super-secure hardware to process BLIK transactions, anything with a keypad and an internet connection will do.
Have to click the dangerous sounding "Open card to ALL internet purchases for 60 minutes" button every time I buy a game on Steam, otherwise my bank simply declines it. All Stripe gateways used to be like that, but fixed it two years or so ago.
I think Amazon.se rounded it somehow, last time it worked without 3D secure, which was surprising since .co.uk and .de usually required opening the card. I'd guess they are on the hook if any fraudulent transactions would happen though. Amazon's interface for dealing with failed transactions at least used to be horrible since you would actually get past the checkout, but then be forced to somewhere in the lists find the order and from there retry the transaction, instead of simply failing visibly at the checkout like any normal webshop.
This has started happening for me in the US with my Visa card.
Privacy and helps keep track of subscription expenses and helps me maintain/be aware budget and/or subscription increases.
The only downside occurs when you are trying to process a refund for a card that was already closed.
Not to mention that their product does nothing against tracking by the card networks themselves eg. https://datafloq.com/read/mastercard-applies-big-data-help-r.... If you want "privacy", your best bet is a prepaid card bought with cash.
Your bank still has access to everything (and they sell everything, of course) and the service itself also has access to everything. But all in all it is a good layer of insulation from merchants and vendors and has some useful features. Think of it like a VPN service for card payments.
They make their money from the same fee merchants pay to any other card issuer.
https://support.privacy.com/hc/en-us/articles/360012046114-H...
> Card issuers can afford to pay cash back because merchants pay an interchange fee on each transaction.
https://www.creditcards.com/credit-card-news/cash-rebate-cre...
I have not used them, no clue whether they are something to recommend.
I think this point is kind of sketchy.
>Go incognito with a unique credit card number. Virtual cards allow you to use improvised information at checkout to fight against hackers and protect yourself against data breaches—an important consumer safeguard right at the point of sale.
Does privacy.com allow you to put in fake billing addresses when you use their cards, and does that pass AVS? I really don't see how using a virtual card number is like "incognito" if you still have to use your real billing address, especially when you already have multiple credit cards.
All that does is push the burden of fraud management into consumers when it is clearly the fault of merchants, processors and credit card companies.
By implementing things like virtual cards or even PIN numbers, they are doing this to limit their own liabilities and push the burden onto consumers. Currently, consumers don’t need protection. The protection from credit card fraud is largely excellent, at least in the US.
We as consumers should not let this erode away by these articles trying to convince us that credit card fraud is our problem, not the credit card companies’.
Virtual cards are also good for the customer outside of general fraud, such as when you might have a stingy business that only cancels subscriptions over the phone or whatnot; the only downside is that technically the business can send those charges to collections, but even then most small collections charges aren't considered in credit decisions.
If this is the system they want, they should deal with the consequences. The burden of fraud, etc should rest on their shoulders, and it currently does. The more burden they put on our shoulders, the less it is for them. It’s like boiling a frog. When they implement PIN numbers, then they will be able to completely put the burden of liability on our shoulders. They want the convenience of quick payments with none of the liabilities.
What you’re talking about is presumably hundreds of virtual credit card numbers being distributed, which is even more of a burden for us. And then figuring out which number to cancel etc.
Credit card companies currently have a lot of incentive to catch fraud early because if you need to cancel a card, you will switch it to another card from another company, presumably.
Let them handle it.
All payment systems are moving in that direction: PayPal, any RTP like PayTM, cryptocurrencies, etc. You (the consumer) control the account and the transactions are easy to make. If you want to revert a transaction, you have to prove that you lost control of the account in a way that is not your fault. And even then you may not have a recourse other than going through the legal system.
(Self-custody has benefits and costs.)
There are also ways to avoid subjecting merchants to the responsibility of securing credit card data in the first place, like the Click to Pay initiative launched last year by Mastercard, Visa, American Express and now Discover. Merchants cannot lose data they never have.
Tokenized payments also work to help avoid giving data to Merchants, via services like Apple or Google Pay. Other PSP services can serve a similar role like Pay with Amazon or PayPal.
I don't personally use credit cards at all, for a variety of reasons. Virtual card #s on my debit cards are very desirable when it comes to online purchases, especially with vendors that don't accept paypal.
Reality, this is just an ad for a virtual card service.
Virtual cards are a crap fix (security through obscurity).
In reality, we need a new financial endpoint identification scheme for the masses that is not run by a cabal of self-interest laced with debt-usury dating from a period in US domestic history where interstate-interbank was a challenge (basically things ran on telex). We need to completely unbundle endpoint identification (ie. card number) from information visibly requested or exchanged for authentication (as proof of authorization to pay). Discussions of the status quo need to occur with the recognition that these systems are effectively, foremost, massive global intelligence gathering and economic sanction and seizure platforms and not just payments facilitators. China has completely surpassed the west in payment efficiency because they jumped credit cards straight to mobile payments like they jumped wired telephones straight to cellular. China is opening banks all over the world at a lightning pace.
Europe and much of the world is charging ahead with IBAN which is IMHO well conceived and facilitating settlement systems often ~instant and free. Years ago in the early days of Kraken I proposed an internet form IIBAN compatible with crypto settlement and arbitrary financial endpoint registrars. Unsure if it is still in use at Kraken, however, in general it seems big crypto is now against interoperability as like traditional incumbents - re: government sponsored regulatory ingress means their money now comes from gatekeeping. China meanwhile are creating their own digital currency system and have maintained interbank clearing directly run by the state, with existing digital payments via a tiny number of proxy commercial entities (ring any bells?). It's efficient and effective but comes with the issues associated with such a configuration: primarily "eat it or wear it", re: innovation. Still, it's light years ahead of the US in terms of the consumer: no debt, instant approval, foreign participation welcome, global reach, zero cost, totally pervasive, no cards or snail-mail required, friends-as-reputation, none of that card not present bullshit, none of that 'tell us if you travel' bullshit, none of that 'points' or 'annual fee/waiver', or 'full personal and economic profile including n-months of local income to play' bullshit.
They can be used at any online shop, have customizable credit limits and expiry dates, and you can enter whatever billing details you like. It’s a great solution. Payments still settle to your real credit card in the end, obviously, but the merchant never gets to see that info.
Similarly, my understanding is that Apple Pay (and probably Google Wallet?) do a similar thing: they roll a random virtual account number and pay with that.
Google Pay and Apple Pay sort of already do this. When you use tap&pay from your device, you're paying with a DPAN (device/digital primary account number), which was generated when you add the card to your phone (the number on your card itself is the FPAN (f = funding)). You can see the last-4 for this card within the App or when you pay at a store the the receipt shows you your last-4 of your card (it'll be different than your normal card.
I feel like the networks don't want new PANs per transaction, so you can get new ones, but the address space may not be large enough to high card # turnover.
Also helps merchants who offer refunds without receipts, as they can ensure the item was purchased from them at some point in the recent past.
Visa has support for the feature on the backend (they'll give you all the virtual cards you want) but you need a bank license to use it.
In my opinion the best benefits of privacy.com is that you can provide a fake name and address during signup (they will authorize it with any name/zip/addr). Good luck sending stuff to collections without my real name or address.
Mercury.com also provides a similar virtual card service to business banking customers, but unfortunately they don't let you use fake names/addresses like Privacy.com does (probably for good legal reason).
I'm not sure someone saying "cancelling a credit card doesn't cancel a contractual obligation," which is an objective fact, warrants a downvote either.
Even though the article was a blatant ad for privacy.com in all fairness just a few more clicks would have answered it.