11 ms·
Online card payments still suck
- Am4TIfIsER0ppos 4y agoThe government can always make it worse. The EU removed my prepaid card simply because I refused to get a phone for it which was expected to receive some sort of permission for each transaction.
- hocuspocus 4y agoSCA is a big improvement for most people. Some card issuers don't require it done via a phone if that's important for you.
- culturestate 4y ago> Some card issuers don't require it done via a phone And some (looking at you, DBS) toggle seemingly at random between requiring it via SMS or via their mobile app.
- hocuspocus 4y agoI meant neither by phone (SMS tokens don't meet the DSP2 requirements) nor a mobile app. The card issuer can send you a one time link to a web portal by email or using an iframe, where you log in and confirm the transaction.
- culturestate 4y agoInteresting. I've had cards with email confirmation flows (AmEx) but they send an OTP, not a link. I don't think I've seen what you're describing.
- rwmj 4y agoFor most, but not anyone like us who has no mobile reception.
- hocuspocus 4y agoYou don't need mobile reception with modern SCA. Presumably if you're initiating an online purchase, you have access to WiFi?
- rwmj 4y agoDepends on the bank ("acquirer"?) involved but some definitely need mobile. Paypal is one, so is my pension company.
- silvestrov 4y agoSeems like this article is only about United States without being aware of it. Many countries in Europe and Asia have much better payment solutions than the states.
- jonkoops 4y agoThis, we use iDEAL [1] here in the Netherlands since 2005 and it's awesome! You just scan a QR code with your banking app and pay. [1] https://en.wikipedia.org/wiki/IDEAL https://en.wikipedia.org/wiki/IDEAL
- ahopebailie 4y agoIt's actually about what is supported natively in Web browsers and what the vendors of those browsers have done to make it better. Sadly you are correct that the mentality of the browser vendors is VERY card (and US) centric so accommodations for other payment methods get very little attention. This is not a fault of the working group participants who have tried to push for everything from iDEAL to crypto but in the end it's pretty clear we're heading for a wallet-dominated world and we all know who those wallets will come from unless we push back.
- clintonb 4y agoI’m still not sure what the author thinks sucks about wallets like ApplePay or GooglePay. They are the most convenient options both online and in-person. Unless I missed a paragraph, the author never describes and ideal alternative.
- ahopebailie 4y agoOn the contrary I think both products are excellent. The issue I have is that we've taken 20 years to find a better alternative than raw card data in Web forms and as a result we're gonna be stuck with a choice of only those 2 wallets when we could have a had wallets as diverse as websites if we'd been able to work together on a solution that was appropriate to the Web platform.
- clintonb 4y agoCan you share more of that vision? As a well-off US consumer, things are fine. It takes me seconds to pay in person. It takes seconds to pay online using either of the wallets or via almost-direct entry with 1Password. I get that I/we have ceded control of funds flows to card networks like Visa and processors like Stripe. Even if I didn’t work for Stripe, I would be okay with this as a merchant due to the convenience. What am I missing? What do you envision is better for consumers and/or merchants?
- ForOldHack 4y agoOf course they do, but then again, I may not know, since I have not done ONE in about 6 years, when Paypal lied to me, and they suck worst of all. No more. Thanks.
- fragmede 4y agoFor a comparison, spend $5 or $10 that was gonna go to a lotto ticket or starbucks coffee and instead, buy an NFT. Just experience the UX of the web wallet system. It's weird, for sure, and unfortunately it's wrapped up in crypto (because of the emotional baggage people have with crypto), but the UX is interesting. Some lessons from there could be applied to online card payments and traditional banking to make them suck less.
- prezjordan 4y agoLike what?
- fragmede 4y agoAccounts are the first thing that come to mind. right now, I have an account at my bank, and I need to meet certain requirements to have that account. Web3 wallet accounts have no such requirements, and creating a whole new account is just a click away. To make a payment, because my web wallet is already linked, I just select which wallet I want to make a payment from. No need to type out my credit card number. Apple pay has some of the similar convenience, but that's vendor locked and a dead end.
- valdiorn 4y ago"right now, I have an account at my bank, and I need to meet certain requirements to have that account." Hello, my name is money laundering. Why do you think the bank has those "requirements"? Do you think they just hate their customers, or do you think the government enforces this regulation onto the banks to prevent money laundering? Because it's definitely the latter. ... and it's already coming for crypto.
- deleted 4y ago[deleted]
- pavlov 4y agoCreating an empty crypto account is just a click away. But, as a new user, how do you move funds into the account? You must go through an exchange which is subject to the same KYC and anti-money-laundering regulations as a bank. So it's not actually any easier. After all, banks can also create any number of additional accounts for you in their internal system once you're a customer.
- mcv 4y agoI'm still disappointed every time I try to order something at a webshop and they don't support iDeal[0]. That's how online payment should work. Of course it's only a Dutch system, so it's not going to be supported by all international webshops (although Steam does), but if anyone has the scope to introduce a more secure form of online payment, surely it's Visa and MasterCard? Why don't they introduce an iDeal-like payment protocol that the whole world can use? Why do I still have to type those 16 numbers into a web form, when the banking app on my phone already knows what those numbers are? Why does anyone else need to know those numbers, and why are those numbers enough to authorise payment? Everything is wrong with that system, and yet credit card companies don't seem to have sufficient incentive to fix it. And yet they have too much power outside Netherland for anyone to introduce a better alternative. [0] Lego! Why do you not support iDeal? If Steam can do it, so can you.
- lotsofpulp 4y agoWhy should I care about credit card security? I have zero liability, and in 17 years of using them, I maybe had to ask the bank to issue a new credit card number once, and that would have been many years ago. I am sure tons of doctors' offices, hotels, online businesses, daycares, etc have my hand written card number and CVC code or whatever laying around, but even if someone did use it fraudulently, I would just click the dispute button on the transaction and I assume I would not hear about it again.
- psychlops 4y agoWhen losses are socialized, fraud is someone else's problem.
- lotsofpulp 4y agoYes, which is a big reason to use credit cards.
- maest 4y agoYou're still paying for the cost of fraud, so it's not really someone else's problem.
- wwilim 4y agoIn Poland, we have this wonderful system called BLIK. You provide nothing except a single-use 6-digit code, then you confirm the payment in your bank's mobile app. It works in online payments, physical stores and ATMs, it supports bank transfers using just a phone number, and recently it's been upgraded to support contactless payments as well https://en.wikipedia.org/wiki/Blik https://en.wikipedia.org/wiki/Blik
- whizzter 4y agoSounds a lot like Swish in Sweden (and I think Vipps in Norway). It basically started as a user to user system that works by tying a persons phone-number so you can send momey to anyone you have a phone-number for. Quite quickly this system was adopted by small companies before it was made official and they quickly introduced a user to company variation, a tad costly but the ease of just scanning a QR-code to pay has made it a hit (The QR code always has a recipient, optionally with a sum and infotext also I think).
- bluedino 4y agoIt's odd that confirmation systems like you mention are almost never used in the US for ordering. Seems like that would solve the problem of delivery drivers stealing your food or iPhone.
- boring_twenties 4y agoSo, you can't pay if you don't have your phone on you, or it's not charged, or the network connection is spotty?
- Brajeshwar 4y agoWe Indians take it for granted, but UPI[1] is a brilliant system. We make payments for something as small as ₹1 if needed. Transaction of ₹10[2] for a cup of tea is a very regular and ordinary happening. 1. https://en.wikipedia.org/wiki/Unified_Payments_Interface https://en.wikipedia.org/wiki/Unified_Payments_Interface 2. ₹10 is roughly $0.12 (as of today).
- searchableguy 4y agoIt is great but require private defaults. Cred recently added support for adding alias instead of real name. Many UPI apps also associate your phone number automatically to your UPI ID so you are handing out your phone number whenever you pay.
- Brajeshwar 4y agoI've actually thought of this and have recently started going back to cash, and actual cards.
- smeeth 4y agoUPI has apparently inspired a similar system in the US called FedNow [0] which will launch in 2023. [0] https://www.frbservices.org/financial-services/fednow/about.html https://www.frbservices.org/financial-services/fednow/about....
- rwmj 4y agoTricky to buy a cup of tea online though. Is this like WeChat, one of the ubiquitous person-to-person payment systems used in China?
- zinekeller 4y agoNot Indian, but unlike WeChat (and AliPay), UPI is a government-sponsored interconnect so every bank can implement it. I'm not sure of the privacy implications though.
- piva00 4y ago
- franciscop 4y ago> "The security of your card details is only marginally improved" Please don't be ridiculous, I understand you have to instill fear in the people reading this for them to use your service, but the security of what you described before to today has improved by orders of magnitude: - I'm going to guess no HTTPS 20 years ago (it was formally specified 22 years ago). - Merchant employee has access to the raw data of your credit card. Lowest paid one probably, since it's manual data entry. - Send this data using email, which is not secure neither at the sending point, receiving point or transportation. - To the ordering service, again a lowly paid employee with access to the raw credit card data. - In none of these points, except the first, the payment amount was confirmed/verified by the client. - At none of these points the author of the order is verified to be the legit owner of the card. Today, sure it's still complex, but we basically have 2FA, card tokenization, client verification of payments, forced HTTPS, etc. which remove all of the insecure points mentioned above. Disclaimer: I recently joined Stripe, opinions my own though ofc
- hotpotamus 4y agoTook a quick look and SSL was 1994, so going on 30 years. Formal specification may have taken a bit longer, but I definitely remembered using SSL in the 90's.
- trentnix 4y agoYep. I remember it being recognized as essential for payments in 2002.
- Retric 4y agoYour timeline is off, Netscape Communications created HTTPS in 1994. So while it became a formal specification in 2000, browsers where already supporting it at the time.
- franciscop 4y agoTrue, I just searched when the standard was created, my point still remains that by 2002 most sites were probably without HTTPS though. Heck, I remember in ~2012 when I started programming about half of the login sites I used were without HTTPS!
- quickthrower2 4y agoApple pay coupled with fingerprint on iphone has been my most enjoyable experience both on the web and in person. There is still a CC under the hood.
- djschnei 4y agoIf only there was an instantaneous, nearly free (cost per transaction), opensource, anyone-can-access, infinitely scalable, infinitely interoperable, payment rail that we could start building solutions on top of...
- tombert 4y agoIf you're referring to cryptocurrency, isn't the average cost-per-transaction for something like Ethereum on the order of $40-$50?
- pshc 4y agoIt’s more like $1 these days due to the bear market, granted these remain high fees. Cheaper payments can be sent on a zero-knowledge Layer 2 like starknet or zksync. Beta services but usable (except the whole on-ramp off-ramp part). Once sharding is implemented, fees are likely to drop to sub-cent levels. Ideally payments would be anonymized on a privacy-preserving L3, but I don’t think those exist yet
- zeroclip 4y agoAztec is live on mainnet: https://aztec.network/ https://aztec.network/
- landemva 4y agoJust sending a payment is typically cheap for eth. Calling a lot of code can get expensive for the code execution costs, though L2s are available for that if you do it regularly.
- djschnei 4y agoNot Ethereum. Ethereum has a lot of massive problems. Not 'crypto' which is by and large a scam. I'm talking about Bitcoin with The Lightning Network. Most payments I make over Lightning, regardless of size, carry a fee of fractions of a cent. On an average day I make 50+ payments over lightning - on aggregate the fees add up to less than $.01
- 4y ago
- _trackno5 4y agoNo surprises here. Cards should've been deprecated as a payment method long ago. Brazil's Pix, Netherlands's iDEAL, Poland's BLIK, etc, are all better payment methods that follow a push model (i.e., the customer actively confirms the purchase on their phone) instead of pull model (i.e., I send my card details to the store and it forwards it to the card network). I really hope the EU gets its shit together and moves forward with TIPS[0]. I would love for this to become a requirement for all banks in the Eurozone. [0] https://www.ecb.europa.eu/paym/target/tips/html/index.en.html https://www.ecb.europa.eu/paym/target/tips/html/index.en.htm...
- charles_f 4y agoThat's all great till you don't have network, or you're abroad and need to shell out a $15 roaming day pass to pay for a freaking croissant. No thanks. At least the credit card networks achieved some degree of industry standardization. I can pay with my freaking phone and it requires my fingerprint to validate the payment. I'm not clear what lack of convenience you're referring to
- marcosdumay 4y agoWell, I don't see how any of those problems are a reasonable issue for online payments. By the way, most countries still have cash. What is important, because the credit card network is known for going offline once in a while.
- Kukumber 4y agoIf a website only offers me to put my Credit Card number, CVV, password, then it is a failure Stripe would have been good in the first years of internet commerce, now it is outdated, worse, it's dangerous
- unsignedint 4y agoUnpredictability of international online card payment is painful. Up until March, most if not all the transaction to Japan were working. Two out of three cards I regularly stopped working on March, and one card still works, except it get flagged at EVERY SINGLE instance of these purchase that I actually have to call the issuer to get it unblocked for transaction. (Doesn't matter where it is, doesn't matter how many times I've made purchase from the same vendor.) It seems like this is something to do with changes in 3DSecure; what's frustrating so much is that noone can provide me information what's going on, it's simply doesn't work.
- eraad 4y agoIf card networks, issuers, acquirers, processors and gateways used bitcoin as their settlement layer, most of the current issues would be automatically solved. They could focus engineering resources on creating better user experiences, anti-fraud, etc. Consumers can keep using their tokenized credit cards, debit cards, etc, but their money would be moved using the bitcoin time chain, instead of hundred of CSV files. Why haven't the W3C participants even mentioned bitcoin for standardizing web payments? I believe it's because of politics and business. Bitcoin can't be controlled and manipulated and it's not an easy truth to swallow. I hope this changes.
- colesantiago 4y agoBitcoin has failed as a means for payment and after almost 15 years nothing legitimate has come from it. All people have used for it is gambling, speculation and ruining the planet. Nobody, not even merchants are using Bitcoin for payments.
- andy_ppp 4y agoI didn’t think Bitcoin could handle that many transactions, never mind the environmental damage it causes…
- Timja 4y agoIt is surprising that in 2022 this is still a popular misconception, even on a site like Hacker News. The amount of transactions the Bitcoin blockchain handles does not impact how many transactions can be done in Bitcoin via higher layers like the Lightning Network. I think the reason is that secure and trustless payment methods are a new thing that only came up a few years ago, and nothing like it existed before in the history of mankind. There have been higher layers like banknotes that "represented" gold, but it always involved trust to use them. With cryptographic solutions like Bitcoin+Lightning, no trust is needed anymore.
- andy_ppp 4y agoYou’ve moved trust from the banking system into code. That might be a good thing. I will look into how the lightening network works to inform myself. The climate change and extreme volatility amongst other issues are still going to prevent Bitcoin being adopted for settlements.