Some banks, require that you use the token generator you've gotten to log on and manage your bank account while most other use a seperate password for the Verified by Visa/Mastercard SecureCode thing.
Other things "you have" in popular 2FA solutions are quite different, for instance your mobile phone number identity (for SMS) or your Google Authenticator.
I'm super sketched out by the program as it appears to be run by a third party rather than Visa/Mastercard.
[1] http://en.wikipedia.org/wiki/Transaction_authentication_numb...
It's a good idea, certainly, just a partly lousy implementation. Some banks will offer the option of sending you a TAN via SMS instead (so your phone is the "something you have"), but usually for a fee.
In Finland one bank (Nordea) uses one-time passwords so you get a pad with passwords in the mail (they automatically send new ones when you're about to run out) and you need to use them sequentially to log in, only the numeric "username" is static. Then when you try to transfer money you also need to input a challenge-response from the same pad.
IIRC another bank (Danske Bank) allows you to set a static username and password but you must also enter a challenge-response from a permanent pad to log in and to initiate transfers as well.
Can't speak about the others but they should be about the same.
Americans apparently just use a static username and password which is pretty mind boggling.
In the UK we tend to have a static username and password then either a hardware device, or a "Enter characters 1, 3, 8 from your secret information". (Where the secret information is 8-10 characters long and you're requested to enter from random offsets each time.)
I've used both systems, and entering three characters from the secret information is the least hassle, but not as reassuring as the hardware token.
I lived in the US for 6 months and was surprised to find that my American collegues found it less safe to use a bank card (with PIN) than a CC. Their arguments were that 'if someone gets your card AND PIN, they can do anything' as opposed to someone stealing JUST your CC and then he can do anything... Yes seems much safer.
We also have zero liability for unauthorized CC charges. So even if someone were to do that, the bank would be on the hook, not the user. Banks rely on a lot of computer analysis to determine whether a charge should be allowed.
It's much more of a pain to get money back into your bank account after it's been withdrawn. So although it's technically true that a bank card with PIN is more secure, to the end user, it's not any better.
Not at all the token system the parent describes.
For example, in India, by LAW, all domestic online transactions go through two-factor authentication. For one of my cards, I need to enter a secondary password while for another I need to enter a pin texted to my mobile. The second option is a hassle though, especially when I am travelling abroad and my standard mobile number is not functional.
For international transactions, this does not apply and the card details are enough for the transaction to go through. I guess there is no standard agreement between countries which Visa, MasterCard or Amex can implement (these are the only payment networks I use).
When I make online payments, I get redirected to a page where I have to answer a question/answer I've set-up a priori.
The two-factor authentication is optional. I enable it to feel more secure. I don't make too many online payments, but I do at least 5-6 times per month.