Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unless they're using the card online, when they only need my address (which isn't the hardest information to uncover).


In canada, if i want to use my debit card online i have to log in to my online banking after i make the purchase to confirm the transaction.


I usually have to do the Verified by Visa stuff too, but my understanding is that it's almost entirely optional for a merchant to require the extra information. Payment can still be made even without a CVV.

And even if verified by visa were compulsory, it would still be possible to create a Direct Debit payment using the account details, which are frequently written on the card, and the address.


(American) I experienced something like this the first time in my life yesterday when buying Skype credit. After entering my info at Skype, I was redirected to a "Verified by Visa"[0] page that made me type in my bank credentials.

I wish this sort of thing was universal.

[0]: https://usa.visa.com/personal/security/vbv/index.jsp


Here's a scenario:

I'm in a dodgy internet cafe with a key logger somewhere in Thailand.

I need to book a flight and the airline insists on my "Verified By Visa" credentials.

Who do you think my bank blames (even though they state that they won't) when somebody goes on a shopping spree with not only my CC # and my security code, but also my VbV password?

As another poster mentioned: It's offloading the risk to the card holder.

Something like a token, or two factor authentication would be a lot better.


Verified by Visa has a pretty bad design flaw: the recommended implementation uses an iframe to load the page that prompts for your password, so it's not obvious if that iframe is legitimate or a phishing attack.


Also, VbV unloads a lot of the security burden to the consumer: http://news.ycombinator.com/item?id=1909862


Verified by Visa (AKA '3D Secure') is a huge pain, and in all bank implementations that I've used in the UK it's trivial to reset the password.

My current account is with LloydsTSB and they now don't bother asking for your 3D Secure credentials and just go straight to the 'accepted' callback, because it pissed off so many of their customers.


At least in Sweden, most debit cards now require Verified By Visa/MasterCard SecureCode for online purchases, which means the theif would need either my bank RSA fob or a password.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: