"You're trying to use a US based credit card to order delivery of some product to Europe, you must be a criminal."
"You're trying to use a US based credit card to order delivery of some product to Europe, you must be a criminal."
Personally, I actually like this approach. My US card being used to purchase from a UK vendor and shipping the merchandise to a UK address when the immediate history of my card usage makes it really clear that I'm not currently in the UK?
That's objectively suspicious. They checked with me, I said "I authorize this" and the deal was done with little fuss. That's a win-win-win in my book.
- it should be a transaction you've already confirmed through a 3DS2 check through a secured app
- you should contact them immediately if you lose capacity to authorize your transaction, before such transactions happen
- them phoning you doesn't help if someone already has your phone unlocked and can just say "yes", while potentially glancing at your personal and banking info on it. It's already over at that point if they secured step 1.
> you should contact them immediately if you lose capacity to authorize your transaction, before such transactions happen
I don't know what you mean by this. I never lost capacity to authorize the transaction. My bank just wanted to do it a different way in this case. But if I did lose capacity, how would I know until I try to authorize a transaction?
> them phoning you doesn't help if someone already has your phone unlocked and can just say "yes"
True, that's why they wanted me to call them, where they engaged in another method of identifying me.
I can't pay for crossover wine with the card I usually use for online shopping. I have to go through paypal.
The funniest thing I know was when someone got a new credit card and EVERY transaction he tried to make with it was refused because it was 'unusal'. Of course it was unusual, because the card was 2 days old and there wasn't any 'usual' transaction in the past.
Ie. just because you tried to use that card that tripped some detector, now your account is blocked from paying with any other cards, as are the accounts of everyone who live in the same street as you, everyone who uses the same browser as you, everyone with the same phone area code as you, everyone with a similar email address to you, etc.
The worst I've seen was someone blocking entire IP ranges due to fraudulent activity. Once their overall sales started declining, they realized they managed to ban entire university campuses because one fraudsters decided to use the dorm wifi for carding
Especially low margin businesses, where you might have revenue of $20 in a transaction, but a profit margin of just $0.20, fraud is really painful if you lose the complete $19.80. You're happy to turn away a lot of custom to avoid some fraud.
Classic example: Bank loans. They might only earn 1% of the principle, so a fraudster who runs away with the whole principle has to be really rare.
It's also a volume question. If you have low margins but high volumes, you might run a very sophisticated anti-fraud setup to walk the razor thin line around compliant chargeback and refund rates.
From the consumer POV of course it's all the same and annoying at that. But the plumbing behind the system has some insane blunt tools, some programs held together by excel-sheets and duct tape while others are super complex with blackbox rulesets.
You're entering a bunch of magical numbers. There is zero verification that you are in fact the cardholder. The store can't get its goods back once they have shipped. If the cardholder does a chargeback, you've just given away the entire order for free - plus a massive chargeback fee.
The vast majority of orders will be delivered to the cardholder's home address - or at least reasonably close. The vast majority of long-distance orders are fraud. Do you expect the vendor to just eat the almost-guaranteed losses?
Fraud like this isn't possible with payment methods like iDeal - which are essentially one-way bank transfers. You can order stuff to be delivered to the White House, for all the vendor cares. But the customers don't like it because they can't do a chargeback when something goes wrong with the order...
Looking at my data, in the last 12 months, only ~60% of my sales go to the person buying the product. I don't have any fraud or refund requests for the last 12 months, so... I'm not sure if "the vast majority" is accurate.
Hell, 30% of my Amazon purchases go to family members, or friends. Some in other countries because it is cheaper to buy something on Amazon and have it ship to another country than trying to buy it locally and ship.
This is not entirely true, this is location/bank specific.
For my card, I just have to perform additional verification whenever necessary, by using 3D Secure. Currently I authorise or reject from an application.
Before smartphones, I had to use a tiny electronic token generator keychain.
I remember implementing the technology on software that I worked at in the late 2000s, when it had another name.
2FA is available with some credit cards for some transactions, but until it's mandatory for 100% of transactions the problem still remains.
What? Could you explain further? Almost anything ordered online is long distance.
I think if banks offered fraud victim insurance for payments made with digital cash, cryptocurrency and electronic cheques as standard (above and beyond that which they are obliged to provide by law, which is often scant), then VISA and MasterCard would practically disappear within the decade. With apologies to anyone in the industry, good riddance ;)
Banks get interchange fees, consumers get chargeback protection and merchants got a stronger final settlement than cheques.
The last of those is the most important. Merchants happily ate high fees and chargeback risk in the late 20th century because cards had a lower fraud risk than cheques.
No modern payment system can compete because there’s nobody willing to eat the risk for everyone else.
British banks hate bank transfers because they so often are fraud liable, consumers hate crypto because they are so often fraud liable.
Those various payment schemes do have use cases, but it’s hard for them to compete at a grocery store.
Moreover, visa/mastercard were able to get big before payments became so important governments. This has a massive advantage in tourism and international payments.
India and the EU will never be able to agree on a common payments standard to make SEPA & UPI compatible, for example.
But even inside the EU, as soon as I leave Germany, my Girocard has to magically become a "Maestro" card to be useable.
> The vast majority of long-distance orders are fraud.
I'm calling bullshit on this one. Do you think Amazon, AliExpress, Ebay, Etsy, etc only ship to the city where their warehouse is located and never over any distance?
Someone living in NYC (and thus having their card registered in NYC there) is usually going to have it delivered to their home (in NYC) or their office (also NYC, or close to it). Someone living in NYC is very unlikely to order something for delivery in London. The location of the warehouse-of-origin is not relevant here.
> PSD2 in the EU solves this with MFA (you have to open your bank app to approve the specific card transaction).
Still not solved, unfortunately. With my EU-based credit card it seems to be a coin toss whether it asks for MFA confirmation or not.
Without any supporting data, "the vast majority" being fraudulent seems like a wild claim.