LaBanquePostale payments request bank password
gist.github.com
gist.github.com
The flow goes: Merchant -> Merchant Plug-In (MPI) -> Directory Server -> Access Control Server (ACS) -> Banks. The first two are under the merchant's responsibility domain (or payment processors). The Directory Server is under the payment network's responsibility domain. The last two are under the bank's responsibility domain. Thus, a "3-Domains Secure" name.
Despite the word "secure" in its name, the primary purpose of 3-D Secure is to protect the merchant. Transactions authenticated with 3-D Secure will be "liability shifted," making merchants less liable for chargebacks (e.g., banks are more likely to reject your chargeback claims).
To me it looks like it's another company than "La Banque Postale": "Worldline is a French multinational payment and transactional services company founded in 1974."
https://fr.wikipedia.org/wiki/Worldline
Whois of wlp-acs.com:
Organization:WORLDLINE FRANCE
Street:80 Quai Voltaire Immeuble River Ouest
City:Bezons
State:FR
Postal Code:95870
I think wlp stands for “Worldline La Poste”.
https://financial-services.worldline.com/en/home/solutions/i...
I do agree, it always annoys me to see services spread many stakeholders with no one clearly identified as the responsible for the service.
> The password they"re asking for is NOT your general ebanking password. It's not your Credit Card pin code either. It's a separate, THIRD password (mine is like a CC pin: 4 digits) that's dedicated to authenticating online purchases. Mine is viewable and changeable at will in my bank app & web site.
Source : I have an account in this bank
[0] https://www.visa.co.uk/partner-with-us/payment-technology/st...
After entering my password, I am redirected again to the merchant's payment confirmation page.
I'm not sure how this exists when it was common sense to tell people to not use their banking information on a site that's not the one of the bank.
[0] https://www.visa.co.uk/partner-with-us/payment-technology/st...
That comparison doesn't really make sense. Cookie banners exist to inform you about data sharing agreements. PSD-2 regulates how third party providers and banks can work together and providing more open APIs between banks and consumer apps.
That being said nobody is asking passwords for paying with cards (now if you're doing a payment through your bank that's a different issue)
In my bank (Swedbank) it’s tied to a smartphone app instead, called BankID[1]. So in order to pass the “3-D Secure” check I will open the BankID app and it will request me to verify my identity via either a PIN or FaceID.
There is an escape hatch where you can disable it for 60 minutes. Steam used to require going through that procedure, but they've implemented 3-D Secure for a while now.
Shopping at Amazon is a pain. They don't use 3-D Secure, and they don't even perform the transaction during checkout. Instead, they send a "payment declined" e-mail somewhere between a few minutes and a few days later, at which point I have to re-enter my payment details.
You usually only get the 2nd factor notification / approval on your mobile phone so you only enter it on the bank's app.
Banque Populaire. But others are no better. Société Générale is abysmal for example.
That said, I absolutely also hate having only a choice of a 6 digit pin on a UI that's intentionally designed to disallow any password manager usage. Plus they shuffle the inputs, make you change pin every n-usage/n-days. I really don't get the rationale other than it maybe avoids screen scraping, or keylogging?
Apparently just SMS is not deemed secure enough by law, so they have to have another authentication factor, and the only other factor they have if you haven't activated certicode is the regular account password.
Because as a client I'm not supposed to know anything about wlp-acs.com or adyen.com or whatever site the merchant site redirected me to.
Here the password they request is a lot more important than any one transaction would, as it allows full access to your accounts.
Have you set up the certicode system from within their banking app though? I believe the UI you’ve seen here is some kind of crappy fallback for when you don’t have Certicode enabled.
See also: https://plaid.com/
I found out that BoA is ok and that AppleCard is excellent. I heard horror stories about others (like they are calling you and asking for personal info, security is bad, etc.).
Sometimes when you are using a phone app they can send you a notification there, something they call Certicode Plus, but for everyone that has not activated it, they request the secret bank password.
I've tried to activate it yesterday, but maybe it takes additional time to switch to the new system even though they tell me it has been activated, and I'm still stuck and can't process payments without giving my secret code. And it has made me miss some aliexpress promotion.
From a security perspective it exposes them if any of the payment processor is compromised. In my case the payment processor was wlp-acs.com but sometimes it is adyen.com.
In normal usage, you don't give any information anymore to the payment processor yourself (now that SMS authentication has been deprecated by law).
The original implementation of it is flawed - the merchant is supposed to iframe the authorization page, which means as a user you have no way to tell whether the displayed page is legitimate. Somehow this insanity actually went ahead and is now part of the spec, so it's too late to change it.
The redeeming factor is that the authorization pages (controlled by the banks) usually only ever ask for an OTP or some relatively benign piece of information that by itself can't be used to break into the account (modern banks doesn't ask for anything at all and just polls the backend for an out-of-band response via a push notification), so as long as the user doesn't expect this page to ask for their actual online banking password it is safe as a fake page requesting such info will raise alarm bells (of course, that relies on the user being somewhat aware of the problem and the risks - not sure how much of this actually applies to the general population).
La Banque Postale here clearly didn't understand the problem, and decided to legitimize asking for their actual banking password on an untrusted website - this now opens them up for attacks where websites make a fake iframe to steal that password. The fact that it's a static secret also means it can be reused forever once captured, where as typical 3D-Secure implementations use time-limited secrets.
For quite a while uk banks have done it with weird URLs. The only bank I know that does this incredibly well is Monzo as their 3D secure URLs are all on veirfy.monzo.com