TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: 2FA for Credit Cards?

30 点作者 funerr将近 3 年前
I never understood the idea of CVC. Every website asks for it - so it seems like an extension of the card number. Why isn't there an app (or some digital way) to verify the card is mine, like authentication systems have 2FA? It will change for every transaction, unlike CVC.

18 条评论

iam-TJ将近 3 年前
There is. Strong Customer Authentication<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;3-D_Secure" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;3-D_Secure</a><p><a href="https:&#x2F;&#x2F;www.mastercard.com&#x2F;gateway&#x2F;payment-solutions&#x2F;security&#x2F;strong-customer-authentication.html" rel="nofollow">https:&#x2F;&#x2F;www.mastercard.com&#x2F;gateway&#x2F;payment-solutions&#x2F;securit...</a><p><a href="https:&#x2F;&#x2F;www.visa.co.uk&#x2F;partner-with-us&#x2F;payment-technology&#x2F;strong-customer-authentication.html" rel="nofollow">https:&#x2F;&#x2F;www.visa.co.uk&#x2F;partner-with-us&#x2F;payment-technology&#x2F;st...</a><p><a href="https:&#x2F;&#x2F;www.barclaycard.co.uk&#x2F;business&#x2F;business-matters&#x2F;fraud-and-security&#x2F;sca-deadline" rel="nofollow">https:&#x2F;&#x2F;www.barclaycard.co.uk&#x2F;business&#x2F;business-matters&#x2F;frau...</a>
评论 #32738210 未加载
评论 #32738143 未加载
评论 #32737698 未加载
评论 #32737688 未加载
pavlov将近 3 年前
I moved back to Finland after years in the USA, and found out that credit cards from Finnish banks now require a 2FA system for online payments. It works fine. The online purchase enters a short flow with my bank, they send a request to the bank’s app on my phone, I approve it there and the purchase flow returns to the vendor’s site.<p>Everything about banking in the USA was seemingly decades behind my experiences in Northern Europe, so it may take a while for American banks to figure out credit card 2FA… (They still regularly use paper checks in America. Bank transfers don’t exist. Many operations require a visit to a bank branch, of which there are absurdly many. I’m surprised they didn’t have mechanical calculators.)
评论 #32738335 未加载
评论 #32737868 未加载
评论 #32737878 未加载
评论 #32738128 未加载
评论 #32737693 未加载
评论 #32738706 未加载
评论 #32737725 未加载
评论 #32737641 未加载
rr888将近 3 年前
I&#x27;m not sure where you are but USA is very lax compared to the rest of the world. Obviously someone has crunched the numbers and decided a little more fraud that gets easily refunded means the customer is more profitable that strict security that could frustrate people. I&#x27;ve had a card with the extra Bank verification step and I stopped using it. Maybe the lower interchange fees in Europe makes the difference.
lucideer将近 3 年前
Took a trip to the US recently and was astounded at how many places charged my card without any PIN or verification requirements. The seeming normality of service staff taking your card out-of-sight is also unnerving - staff typically don&#x27;t even lay a finger on your card in Europe. The US is truly in the dark-ages when it comes to payment security.<p>It seems this is yet another example - didn&#x27;t even realise US cards didn&#x27;t have 2FA for online transactions.
评论 #32738106 未加载
评论 #32738178 未加载
评论 #32738109 未加载
评论 #32739772 未加载
评论 #32747009 未加载
评论 #32738155 未加载
martin-adams将近 3 年前
One thing to note is that payment systems are never supposed to store the CVC number, so a data breach shouldn&#x27;t include that number if the vendor does things correctly. This does make it slightly different to being a &#x27;longer card number&#x27;.<p>In the UK, they also have additional verification steps, which can cause some issue when they go async to a payment system that expects to get a verification immediately.<p>I&#x27;ve had Apple take payment twice because the 2FA verification text took too long to come through from a phone order for collection and I ended up buying the item in the store.
评论 #32737682 未加载
Signez将近 3 年前
You are looking for &quot;3D Secure&quot;; in Europe, it is required by regulation for all non-recurring online payments over 30 euros.
评论 #32737798 未加载
detaro将近 3 年前
Verified by VISA, Mastercard SecureCode are exactly that.
评论 #32737732 未加载
评论 #32737365 未加载
InsomniacL将近 3 年前
The CVC essentially is an extension of the card number that is only required when making purchases when the physical card is not present.<p>The CVC is smaller in size and located on the rear of the card to defeat snooping via over the shoulder&#x2F;cctv&#x2F;cameras..
评论 #32738000 未加载
rojobuffalo将近 3 年前
I wouldn&#x27;t want it. In my 15 years of using a credit card I&#x27;ve had fewer than a handful of times where there was a fraudulent transaction on my account. The credit card company covered me, and in total I don&#x27;t think it has exceeded a few hundred dollars. And in that same time I&#x27;ve made thousands of transactions. The addition of a 2FA step for every one of those transactions would be an enormous cost increase on my attention and time.
blackoil将近 3 年前
In India, all online transactions require providing an OTP sent to mobile. Retails transaction require entering PIN on the terminal. You can make transactions below 5000 INR using NFC swipe, but that is optional and can be disabled.<p>UPI, India&#x27;s smartphone&#x2F;app based payment system also requires entering a PIN to make the payments.
sysadm1n将近 3 年前
The thing about 3-D Secure is that it uses your phone number to verify it&#x27;s &#x27;you&#x27; making the purchase, but if your phone is lost&#x2F;stolen and you get a new SIM, you&#x27;re locked out of making any purchases with any cards tied to your old number. You can always update your details on the card provider&#x27;s site so there is that. Another thing: SMS is not secure and a SIM-swap away from someone being able to make purchases in your name. I wish SMS just got deprecated as a form of verification. It&#x27;s 2022, come on, we can do this!
评论 #32738215 未加载
评论 #32738670 未加载
评论 #32738126 未加载
评论 #32738164 未加载
FernandoMax将近 3 年前
Stripe provides SCA as a standalone product. They connect with the bank issuer of the CC, prompts the Challenge asked by the bank, and then Stripes sends if it&#x27;s ok or not.
eliseumds将近 3 年前
Happens most of the time I spend a few hundred dollars or more with N26 (Germany), Revolut, ING Direct (Australia) and Nubank (Brazil). OTP via their mobile apps (or SMS fallback).<p>1. Ye, it&#x27;d be great if I could configure it to do 2FA on all online transactions. Does anyone know what exactly triggers 2FA?<p>2. I have an account with BTG Pactual (Brazil) and their virtual card gets a new CVC after each transaction, pretty cool.
评论 #32738279 未加载
rad_gruchalski将近 3 年前
In Germany: 1) register a credit card for online transactions at <a href="https:&#x2F;&#x2F;www.sicher-online-einkaufen.de&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sicher-online-einkaufen.de&#x2F;</a>, 2) activate with an activation code sent by post, 3) every transaction or 1st of every recurring transactions has to be approved via bank&#x27;s online app (in my case Volksbank via touchid).
xaduha将近 3 年前
First World problem, literally. I&#x27;ve read that swiping cards is still widespread and magnetic strip is mandatory and chips are optional, but I wonder whether people in USA still sign their cards.<p>Paying online without a code from SMS or push notification is an exception, usually happens when you save your payment method when buying something through a well known giant like PayPal or Steam.
billpg将近 3 年前
To everyone mentioning 3D Secure et al, I&#x27;ve only used them on the payments side, but it doesn&#x27;t resemble the 2FA systems that the original poster was asking about. What&#x27;s going on when the browser does stuff just before the payment is accepted?
egello将近 3 年前
In Turkey, where I live, online transactions require 2FA. An sms is sent for you to enter the pin or a notification is sent to your online banking app asking for approval. I thought this was a standard procedure in online banking.
hiyer将近 3 年前
In India we have SMS-based 2FA for online card transactions, and a pin required for PoS ones.