Comment by convolvatron
6 hours ago
this process of giving out your 'secrets' (ccn, exp, ccv, zip) to tens of people a day with no other real authentication is inexcusably insecure. and instead of trying to get on top of the problem for real (like an hsm), we have this very half-assed fraud detection and chargeback mechanism that costly, ineffective, and seems to just bury the real issues behind a facade of concern. its been decades that this has been going on, I remain confused as to what incentives the banks have to continue to prop up this farce.
I've used chargebacks much more often because of services not rendered than because of a lost card or because of stolen credentials.
The chip on a credit or debit card is an HSM.
And mostly irrelevant for online payments.
Their solution to that was a "security code" also printed on the card, lol
The number printed on the card, and the magnetic strip are not.
>with no other real authentication
Nowadays for the first purchase for a merchant it can require me to hold my card to my phone to prove that I have physical ownership of the card.
It's not common and usually doesn't benefit the customer to do that