the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.
The monkey could also fetch the secret question from the 3DSecure page and show it to the user, right? Or am I missing something here? How will adding more information to the login page make it more resistant against mitm?
In most cases the question is the default. The typical flow is the user tries to do a transaction - bank identifies they are not registered for 3D secure yet - a couple of questions and a OTP later - a 3D secure password is chosen. But the question remains the default one unless the user decides to take the effort of changing it.
> because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Rather than downvote it's easy to factually counter your argument: it's not because e.g. keyloggers or mitm attacks can compromise the account. Then afterward, the 2-factor auth is used against the customer as a smokescreen - basically banks say 'oh but we've got this very secure system, it can't be cracked'. Then you have to get into a very technical argument with the bank, which is either hard to win (because only 1 person involved understands, deliberate or not) or impossible (because most customers don't understand the details, and we can't expect them to).
This is not a hypothetical situation - this already happens in Western Europe! It's hard to hold banks or merchants responsible for fraud. Now they shouldn't always be held responsible, that's the first issue; but even in cases where they are (like when they guaranteed upfront that they'd take the risk of fraud, as they used to do in the early days of online banking/payment) their first line of defense will be vague 'our technology is tamper proof' arguments. Many consumer association websites are full of stories about this.
I think all your points are valid, but they're referring to a different problem - which is how get control back from the banks to the customer about chargebacks. This problems wasn't introduced by 3D secure, it was always there and it was always just as bad. If you want to replace 3D secure with something that's better, I'm all for it, but this post implies that we should get rid of it as well.
Comments
NO - 3D secure is not good for the customers.
the system has no safeguards for vulnerabilities like man-in-the-middle,etc. attacks. Yet it gives credit card companies, the right to deny chargebacks to customers (whose credit card was stolen/hacked) because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Man-in-the-middle attack are made less likely because the 3DSecure page where the user is asked to enter a password also contains challenge question that was originally added by the user at the time of setting up 3DSecure for his/her account. The user should be able to recognize that this is not the bank's website when the challenge question is not his/her own.
The monkey could also fetch the secret question from the 3DSecure page and show it to the user, right? Or am I missing something here? How will adding more information to the login page make it more resistant against mitm?
In most cases the question is the default. The typical flow is the user tries to do a transaction - bank identifies they are not registered for 3D secure yet - a couple of questions and a OTP later - a 3D secure password is chosen. But the question remains the default one unless the user decides to take the effort of changing it.
> because they can now wash their hands off the matter ("hey only the customer knew the second password... he must have been careless with it, not us")
Seems pretty valid argument to me.
Rather than downvote it's easy to factually counter your argument: it's not because e.g. keyloggers or mitm attacks can compromise the account. Then afterward, the 2-factor auth is used against the customer as a smokescreen - basically banks say 'oh but we've got this very secure system, it can't be cracked'. Then you have to get into a very technical argument with the bank, which is either hard to win (because only 1 person involved understands, deliberate or not) or impossible (because most customers don't understand the details, and we can't expect them to).
This is not a hypothetical situation - this already happens in Western Europe! It's hard to hold banks or merchants responsible for fraud. Now they shouldn't always be held responsible, that's the first issue; but even in cases where they are (like when they guaranteed upfront that they'd take the risk of fraud, as they used to do in the early days of online banking/payment) their first line of defense will be vague 'our technology is tamper proof' arguments. Many consumer association websites are full of stories about this.
Thanks for not downvoting (and explanation). I certainly wasn't trolling with my comment.
I think all your points are valid, but they're referring to a different problem - which is how get control back from the banks to the customer about chargebacks. This problems wasn't introduced by 3D secure, it was always there and it was always just as bad. If you want to replace 3D secure with something that's better, I'm all for it, but this post implies that we should get rid of it as well.