For online purchases (card-not-present transactions), the merchant takes on all of the fraud risk. This means that the banks do not have much incentive to protect against fraud. The merchants must go on the information they have, which probably doesn't include the card holder's verified phone number.
Sift Science has been successfully protecting online businesses for over a year, and it turns out that machine learning is (unsurprisingly) a good tool for this sort of classification problem.
What about implementing a 2FA system for larger purchases (online or off), implemented in an app on the consumer's phone like google authenticator or sms? Swipe your card at checkout, if amount is > $XX (or otherwise suspicious according to current models), prompt the buyer for a one-time code from SMS or an app. I use the same system when logging into gmail, my bank account, etc - I'd have no problem (and would even welcome) a similar system when using plastic. It's at least a lot more convenient than having the txn declined and your card disabled until you call their security hotline. This way, thieves would need to steal your card and your phone to cause damage.