Notice how they made the post on Feb 14, but show only data for Feb 1. Is it really surprising that the first day with the new system saw fewer transactions? Making claims that this move "permanently hobbles India's mobile commerce" based on evidence like this is surely unwarranted.
I really think 3D secure is a good move. All it requires is entering your internet banking password at the time of making the transaction. Is this really so bad for usability?
the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.
The monkey could also fetch the secret question from the 3DSecure page and show it to the user, right? Or am I missing something here? How will adding more information to the login page make it more resistant against mitm?
In most cases the question is the default. The typical flow is the user tries to do a transaction - bank identifies they are not registered for 3D secure yet - a couple of questions and a OTP later - a 3D secure password is chosen. But the question remains the default one unless the user decides to take the effort of changing it.
> because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Rather than downvote it's easy to factually counter your argument: it's not because e.g. keyloggers or mitm attacks can compromise the account. Then afterward, the 2-factor auth is used against the customer as a smokescreen - basically banks say 'oh but we've got this very secure system, it can't be cracked'. Then you have to get into a very technical argument with the bank, which is either hard to win (because only 1 person involved understands, deliberate or not) or impossible (because most customers don't understand the details, and we can't expect them to).
This is not a hypothetical situation - this already happens in Western Europe! It's hard to hold banks or merchants responsible for fraud. Now they shouldn't always be held responsible, that's the first issue; but even in cases where they are (like when they guaranteed upfront that they'd take the risk of fraud, as they used to do in the early days of online banking/payment) their first line of defense will be vague 'our technology is tamper proof' arguments. Many consumer association websites are full of stories about this.
I think all your points are valid, but they're referring to a different problem - which is how get control back from the banks to the customer about chargebacks. This problems wasn't introduced by 3D secure, it was always there and it was always just as bad. If you want to replace 3D secure with something that's better, I'm all for it, but this post implies that we should get rid of it as well.
I was able to reset it on the spot by providing my birthday and some information from the card (CVV and expiry date iirc). So really the only additional information someone needs to use my card now is my birthday (and that's without even going to the trouble of MITM).
And if they have your credit card, they probably have your driver license or other something else with your birthday. Either they stole your purse/wallet, or they're a merchant and could ask to see your ID when you used the card.
Agreed. Usability with 3D secure is not bad at all. Breaking the "subscription" model is actually a good thing in the current scenario, where the customer has very little control on when and how he unsubscribes to services, and businesses unscrupulously charge for subscriptions beyond the agreed-on date. This happened recently, when a web hosting provider tried to charge my credit card although I'd canceled - I got an SMS from the bank saying that the charge had not been accepted - how delightful it feels to be in control!
Because there are a few rogue players, should everyone be denied from using a subscription model. How painful will it be to actually subscribe to something and go through this slow painful process every month ?
Comments
Notice how they made the post on Feb 14, but show only data for Feb 1. Is it really surprising that the first day with the new system saw fewer transactions? Making claims that this move "permanently hobbles India's mobile commerce" based on evidence like this is surely unwarranted.
I really think 3D secure is a good move. All it requires is entering your internet banking password at the time of making the transaction. Is this really so bad for usability?
NO - 3D secure is not good for the customers.
the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.
The monkey could also fetch the secret question from the 3DSecure page and show it to the user, right? Or am I missing something here? How will adding more information to the login page make it more resistant against mitm?
In most cases the question is the default. The typical flow is the user tries to do a transaction - bank identifies they are not registered for 3D secure yet - a couple of questions and a OTP later - a 3D secure password is chosen. But the question remains the default one unless the user decides to take the effort of changing it.
> because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Seems pretty valid argument to me.
Rather than downvote it's easy to factually counter your argument: it's not because e.g. keyloggers or mitm attacks can compromise the account. Then afterward, the 2-factor auth is used against the customer as a smokescreen - basically banks say 'oh but we've got this very secure system, it can't be cracked'. Then you have to get into a very technical argument with the bank, which is either hard to win (because only 1 person involved understands, deliberate or not) or impossible (because most customers don't understand the details, and we can't expect them to).
This is not a hypothetical situation - this already happens in Western Europe! It's hard to hold banks or merchants responsible for fraud. Now they shouldn't always be held responsible, that's the first issue; but even in cases where they are (like when they guaranteed upfront that they'd take the risk of fraud, as they used to do in the early days of online banking/payment) their first line of defense will be vague 'our technology is tamper proof' arguments. Many consumer association websites are full of stories about this.
Thanks for not downvoting (and explanation). I certainly wasn't trolling with my comment.
I think all your points are valid, but they're referring to a different problem - which is how get control back from the banks to the customer about chargebacks. This problems wasn't introduced by 3D secure, it was always there and it was always just as bad. If you want to replace 3D secure with something that's better, I'm all for it, but this post implies that we should get rid of it as well.
One time I forgot my "Verified by VISA" password.
I was able to reset it on the spot by providing my birthday and some information from the card (CVV and expiry date iirc). So really the only additional information someone needs to use my card now is my birthday (and that's without even going to the trouble of MITM).
And if they have your credit card, they probably have your driver license or other something else with your birthday. Either they stole your purse/wallet, or they're a merchant and could ask to see your ID when you used the card.
3D secure is not very user friendly at all. Most users aren't setup with 3D secure details or have forgotten the necessary details to use it.
Perhaps it's a good idea in principle, much like OpendID, but in the real world it's a pain to use for everyone involved.
Agreed. Usability with 3D secure is not bad at all. Breaking the "subscription" model is actually a good thing in the current scenario, where the customer has very little control on when and how he unsubscribes to services, and businesses unscrupulously charge for subscriptions beyond the agreed-on date. This happened recently, when a web hosting provider tried to charge my credit card although I'd canceled - I got an SMS from the bank saying that the charge had not been accepted - how delightful it feels to be in control!
Because there are a few rogue players, should everyone be denied from using a subscription model. How painful will it be to actually subscribe to something and go through this slow painful process every month ?
I agree, but that is what I would do if I was an annoyed phisher, blogging about the new security system in my way.