In this day why don't the credit card payment systems require multi-factor authentication for online payments? Why don't payment machines challenge you for PIN for payments?
In this day why don't the credit card payment systems require multi-factor authentication for online payments? Why don't payment machines challenge you for PIN for payments?
1. Lulling naive or hurried customers who like to think they're buying "from Amazon" into buying from fraudsters, and
2. Paying the fraudsters so quickly that the seller's account is closed before action is taken the fraud, and
3. Vetting sellers so promiscuously that the individual fraudster's cycle can continue.
In this light, Krebs diagram is deficient, because it omits Amazon from the loop. It's not "triangulation", the more accurate word would be quadrilateralization -- but spell-check says that's not a word.
https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...
You can keep adding on additional pieces of bullshit information customers need to remember all you want, none of it will matter as long as banks and credit card companies don't force businesses to treat them as actually sensitive information.
This is a protocol/product problem, it's wild that to make a payment all the crown jewels need to be put on the wire. It's about time that payment devices and the whole ecosystem adopts some sensible cryptography that, at minimum allows signing payment requests, and ideally keeps its keys private.
Although this whole problem is kind of already solved by 3DS2, albeit not in a great way.