Priceline.com get $1000+ CPM for deceptive links in the checkout process
blogs.reuters.com
blogs.reuters.com
The system right now relies on the honesty of the merchants. If all charges had to go through the consumer's approval first, then I don't think we'd see much of the free credit report scams anymore. Instead of having to call up a recurring (and unsolicited) biller, just decline all payments to the merchant and let the merchant figure out that they're not getting paid.
If I had the means, I think I would start a Bank 2.0. It would have a killer web interface, charge authentication through cell phones or control panel, and instead of dealing with loans and interest, I would probably make make money through Visa charges.
If the timeout on POS card terminals is long enough (about 30-60 seconds), it's enough time for a computer to call my cell, read me the amount to be charged, then wait for me to enter a PIN (not necessarily the same PIN you use on an ATM).
A bank could offer a web interface for me to authorize a list of "always allow" merchants and their charge limits so I don't have to re-authorize supermarkets and recurring subscriptions.
And finally, an interface to list "always deny" merchants.
I like the idea of cancelling an unwanted service by shutting off the flow of money, and then calling their customer support to notify them.
In fact, I think that should be a basic human right. I shouldn't have to argue with a Customer Retention Department (something that pisses me off just in the concept alone), I should just inform them (or let my bank inform them), that I'm no longer their customer.
Me: "Hi, I've cancelled my account."
Them: "I'm sorry, I'll have to transfer you to a customer retention representative."
Me: "No, you don't understand. I've already shut off payments, I'm just giving you a courtesy call. Bye."
However Barclays did make it a reasonably painless and speedy task (comparatively).
I'd be happy to go through a few minutes of inconvenience for a large purchase if it meant significantly greater security for my credit card.
1. The merchant shows a list of banks that support iDEAL (all major banks, currently 8)
2. You pick yours, the merchant sends you to your online banking environment
3. You log into to your bank account (with your username and password)
4. You review the proposed transaction
5. A transaction code is sent to your mobile phone which you have to enter (alternatively, a list with numbered transaction codes is sent to you using snail mail in advance, the website gives you the transaction code it wants which you'll have to offer; transaction codes are used only one time)
6. The transaction is made instantly and confirmed with the merchant. To the merchant's advantage, the transaction is irreversible.
The total cost can be as low as 45 cents for the merchant, with no fixed or upfront costs.
Digital cash allows you to send a long number which represents a single payment and can only be used for that single payment. Thus if the number represents you paying $100 to priceline.com, it can only be used for a single transfer of 100. If someone else tries the same number again, the bank will say, sorry this one has already been used up. In addition to being secure this system can provide absolute privacy.
So theoretically, it is possible but it has not happened. I think one reason is that credit card companies like having people's personal information and being able to see all their purchases.
This is how it works in Germany. You order something and the merchant provides their account number and an order number. You login to your online banking, and send the money. Done.
Fast, inexpensive, simple and secure. One big reason why PayPal and credit cards aren't popular in Germany.
I have heard cases of merchants that delivered products personally & received signatures getting chargebacks. If the transaction happened over the internet then police, CC companies & banks guaranteed to side with the customer.
It is at the point where it just stops a lot of commerce dead. For many companies fraud is far more expensive then credit card charges. Ironically, this is more the case in commodity industries where margins are pretty low anyway.
Just try ordering some easily resalable product (EG a phone) from an overseas merchant. I know one merchant who throws away any order that come in over the net & retakes the order over the phone because (a) it throws off a lot of the fraudsters & (b) phone-credit fraud goes to a less crowded desk then internet-credit fraud. He is willing to work hard & throw away 1/4 of probably legitimate orders to verify authorisation. There is no way for them to accept money in a way that is guaranteed to stay in their account.
Fraudulent merchants may have a lot of power in this situation but honest merchants are screwed.
If your bank 2.0 was real, you would have the support of most small-medium online stores of you had a logical trade-off in place: Consumers must verify payment / Payments are verified, they can't claim this transaction is "unauthorised".
Several card issuers already support either single-use numbers, where you get a number issued that works exactly one time for a maximum amount you specify, or enhanced authorization, where you have to verify through the issuers website every time an online charge is processed.
Oddly, almost no-one I've talked to is aware of the programs that already exist (and often for free) to help with fraud.
I used to get billed $1 per month on my PayPal account for something called "YOURSAVINGSCLUB". This went on for like 6 or 7 months. I called their number to "cancel" whatever it was they were charging me for, and they said they required my credit card number to cancel my account. Given I already knew they were dishonest, I wasn't going to give them my number again, just in case they didn't actually have it and relied on a third party for the billing.
Anyway, I tried to resolve it instead through PayPal but to do so involved a Fax machine, and everytime I started the process I gave up because it wasn't worth the time for the one dollar.
Luckily I think PayPal finally figured it out and cut them off, as I haven't been charged in 6 months or so.
i try and avoid using paypal whenever possible, especially for recurring billing.
These companies are basically running shady private tax schemes. No value-added.
I'm glad the senate report provides a list of the 'partner' commerce companies that have made over $1MM using these schemes. I'll be thinking twice about giving any of them my business. [PDF]http://commerce.senate.gov/public/_files/111609EXHIBITSTOSTA...
My parents used to have a business and even though it was a completely legitimate business they were constantly scared of chargebacks. They knew that even a small percentage of chargebacks can cause them trouble with the CC companies and offerred their customers money back whenever possible to avoid chargebacks. And again this was an honest business selling real tangible things to people that knew they were buying those things, not some online scam.
But now you see some companies use credit card billing for nothing but scams and somehow they are allowed to keep their merchant accounts.
What makes you say that? I wanted to rent a small car for a week and not one site quoted under $300. Priceline quote came in at $120 from the exact same car companies. It worked out great for me. Of course, I was very cautious about not signing up for 10 other things.
If there isn't, the simple thing would be to just ban this practice.