TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: 2FA for Credit Cards?

30 pointsby funerrover 2 years ago
I never understood the idea of CVC. Every website asks for it - so it seems like an extension of the card number. Why isn't there an app (or some digital way) to verify the card is mine, like authentication systems have 2FA? It will change for every transaction, unlike CVC.

18 comments

iam-TJover 2 years ago
There is. Strong Customer Authentication<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;3-D_Secure" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;3-D_Secure</a><p><a href="https:&#x2F;&#x2F;www.mastercard.com&#x2F;gateway&#x2F;payment-solutions&#x2F;security&#x2F;strong-customer-authentication.html" rel="nofollow">https:&#x2F;&#x2F;www.mastercard.com&#x2F;gateway&#x2F;payment-solutions&#x2F;securit...</a><p><a href="https:&#x2F;&#x2F;www.visa.co.uk&#x2F;partner-with-us&#x2F;payment-technology&#x2F;strong-customer-authentication.html" rel="nofollow">https:&#x2F;&#x2F;www.visa.co.uk&#x2F;partner-with-us&#x2F;payment-technology&#x2F;st...</a><p><a href="https:&#x2F;&#x2F;www.barclaycard.co.uk&#x2F;business&#x2F;business-matters&#x2F;fraud-and-security&#x2F;sca-deadline" rel="nofollow">https:&#x2F;&#x2F;www.barclaycard.co.uk&#x2F;business&#x2F;business-matters&#x2F;frau...</a>
评论 #32738210 未加载
评论 #32738143 未加载
评论 #32737698 未加载
评论 #32737688 未加载
pavlovover 2 years ago
I moved back to Finland after years in the USA, and found out that credit cards from Finnish banks now require a 2FA system for online payments. It works fine. The online purchase enters a short flow with my bank, they send a request to the bank’s app on my phone, I approve it there and the purchase flow returns to the vendor’s site.<p>Everything about banking in the USA was seemingly decades behind my experiences in Northern Europe, so it may take a while for American banks to figure out credit card 2FA… (They still regularly use paper checks in America. Bank transfers don’t exist. Many operations require a visit to a bank branch, of which there are absurdly many. I’m surprised they didn’t have mechanical calculators.)
评论 #32738335 未加载
评论 #32737868 未加载
评论 #32737878 未加载
评论 #32738128 未加载
评论 #32737693 未加载
评论 #32738706 未加载
评论 #32737725 未加载
评论 #32737641 未加载
rr888over 2 years ago
I&#x27;m not sure where you are but USA is very lax compared to the rest of the world. Obviously someone has crunched the numbers and decided a little more fraud that gets easily refunded means the customer is more profitable that strict security that could frustrate people. I&#x27;ve had a card with the extra Bank verification step and I stopped using it. Maybe the lower interchange fees in Europe makes the difference.
lucideerover 2 years ago
Took a trip to the US recently and was astounded at how many places charged my card without any PIN or verification requirements. The seeming normality of service staff taking your card out-of-sight is also unnerving - staff typically don&#x27;t even lay a finger on your card in Europe. The US is truly in the dark-ages when it comes to payment security.<p>It seems this is yet another example - didn&#x27;t even realise US cards didn&#x27;t have 2FA for online transactions.
评论 #32738106 未加载
评论 #32738178 未加载
评论 #32738109 未加载
评论 #32739772 未加载
评论 #32747009 未加载
评论 #32738155 未加载
martin-adamsover 2 years ago
One thing to note is that payment systems are never supposed to store the CVC number, so a data breach shouldn&#x27;t include that number if the vendor does things correctly. This does make it slightly different to being a &#x27;longer card number&#x27;.<p>In the UK, they also have additional verification steps, which can cause some issue when they go async to a payment system that expects to get a verification immediately.<p>I&#x27;ve had Apple take payment twice because the 2FA verification text took too long to come through from a phone order for collection and I ended up buying the item in the store.
评论 #32737682 未加载
Signezover 2 years ago
You are looking for &quot;3D Secure&quot;; in Europe, it is required by regulation for all non-recurring online payments over 30 euros.
评论 #32737798 未加载
detaroover 2 years ago
Verified by VISA, Mastercard SecureCode are exactly that.
评论 #32737732 未加载
评论 #32737365 未加载
InsomniacLover 2 years ago
The CVC essentially is an extension of the card number that is only required when making purchases when the physical card is not present.<p>The CVC is smaller in size and located on the rear of the card to defeat snooping via over the shoulder&#x2F;cctv&#x2F;cameras..
评论 #32738000 未加载
rojobuffaloover 2 years ago
I wouldn&#x27;t want it. In my 15 years of using a credit card I&#x27;ve had fewer than a handful of times where there was a fraudulent transaction on my account. The credit card company covered me, and in total I don&#x27;t think it has exceeded a few hundred dollars. And in that same time I&#x27;ve made thousands of transactions. The addition of a 2FA step for every one of those transactions would be an enormous cost increase on my attention and time.
blackoilover 2 years ago
In India, all online transactions require providing an OTP sent to mobile. Retails transaction require entering PIN on the terminal. You can make transactions below 5000 INR using NFC swipe, but that is optional and can be disabled.<p>UPI, India&#x27;s smartphone&#x2F;app based payment system also requires entering a PIN to make the payments.
sysadm1nover 2 years ago
The thing about 3-D Secure is that it uses your phone number to verify it&#x27;s &#x27;you&#x27; making the purchase, but if your phone is lost&#x2F;stolen and you get a new SIM, you&#x27;re locked out of making any purchases with any cards tied to your old number. You can always update your details on the card provider&#x27;s site so there is that. Another thing: SMS is not secure and a SIM-swap away from someone being able to make purchases in your name. I wish SMS just got deprecated as a form of verification. It&#x27;s 2022, come on, we can do this!
评论 #32738215 未加载
评论 #32738670 未加载
评论 #32738126 未加载
评论 #32738164 未加载
FernandoMaxover 2 years ago
Stripe provides SCA as a standalone product. They connect with the bank issuer of the CC, prompts the Challenge asked by the bank, and then Stripes sends if it&#x27;s ok or not.
eliseumdsover 2 years ago
Happens most of the time I spend a few hundred dollars or more with N26 (Germany), Revolut, ING Direct (Australia) and Nubank (Brazil). OTP via their mobile apps (or SMS fallback).<p>1. Ye, it&#x27;d be great if I could configure it to do 2FA on all online transactions. Does anyone know what exactly triggers 2FA?<p>2. I have an account with BTG Pactual (Brazil) and their virtual card gets a new CVC after each transaction, pretty cool.
评论 #32738279 未加载
rad_gruchalskiover 2 years ago
In Germany: 1) register a credit card for online transactions at <a href="https:&#x2F;&#x2F;www.sicher-online-einkaufen.de&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sicher-online-einkaufen.de&#x2F;</a>, 2) activate with an activation code sent by post, 3) every transaction or 1st of every recurring transactions has to be approved via bank&#x27;s online app (in my case Volksbank via touchid).
xaduhaover 2 years ago
First World problem, literally. I&#x27;ve read that swiping cards is still widespread and magnetic strip is mandatory and chips are optional, but I wonder whether people in USA still sign their cards.<p>Paying online without a code from SMS or push notification is an exception, usually happens when you save your payment method when buying something through a well known giant like PayPal or Steam.
billpgover 2 years ago
To everyone mentioning 3D Secure et al, I&#x27;ve only used them on the payments side, but it doesn&#x27;t resemble the 2FA systems that the original poster was asking about. What&#x27;s going on when the browser does stuff just before the payment is accepted?
egelloover 2 years ago
In Turkey, where I live, online transactions require 2FA. An sms is sent for you to enter the pin or a notification is sent to your online banking app asking for approval. I thought this was a standard procedure in online banking.
hiyerover 2 years ago
In India we have SMS-based 2FA for online card transactions, and a pin required for PoS ones.