The status quo might mean that money can be clawed back after it's sent but identity fraud (or using someone else's credentials) should not be a problem in 2015, we've had SIM cards that can provide a secure method for identifying a physical device since the 90s. Why can't any payment processor come up with a decent alternative to having a magic number that you have to give out all the time that can be used to authorize arbitrary transactions? Maybe eventually every citizen will get a smart card of some kind and we can just use that.
If we were discussing how insecure IE 6 is and how it can get you hacked, then the fact that using Chrome to directly give your info to a shady site can have the same result (get you hacked), doesn't say anything for the relative security of Chrome vs IE 6.
http://blogs.wsj.com/corporate-intelligence/2014/02/06/octob...
You should have already (or very soon be) getting new credit cards in the mail with a SIM chip in them.
After October 15, 2015 credit card companies (instead of merchants) will be liable for financial losses due to credit card fraud where the consumer is forced to use the mag stripe. (In the US of course)
There are plenty of instances where you need to refund something the day after you received it, by which point the escrow money is long gone. Then the solution becomes "Hold transactions in escrow for 30 days" which isn't a solution.
And reputation systems don't work on the internet, especially when purchasing is involved. How do you competitively solve this problem?