Who Pays For Credit Card Breaches?
PetManimal writes "A scheme to steal customers' credit and debit card information at a New England supermarket chain highlights a little-understood fact about credit card security: Customers still think that the credit-card companies have to eat fraudulent charges, but since the PCI DSS standards were adopted, it's actually the merchant banks and merchants who have to pay up. And, according to the blogger writing in the latter article, it's a good thing." "The main reason PCI exists is that there are tens of thousands of merchants who don't understand the basics of information security and weren't even taking the very minimum steps to secure their networks and the credit card information they stored... PCI pushes that burden downstream and forces merchants to... put in a properly configured firewall, encrypt sensitive information and maintain a minimum security stance or be fined by their merchant banks... [T]he credit card companies have taken the bulk of the financial burden off of themselves and placed it on the merchants, which is where much of it belongs...'"
The merchant has to make a living, the credit card company too. The money for fraud can only come from the end of the chain: the customer. The only notable thing here is that all customers pay, not just the ones who use a credit card.
The merchant who accepts the fraudulent charge eats the chargeback, not the one whose site is hacked. How does this encourage information security?
So what about all the stolen credit card information. You actually think people who steal information from a grocery store are going to spend it on groceries! "Yeaaaah boy... them hams weren't on sale..". Please just take a look at the credit card ads that go around with people voice synching the people who stole their information. The merchants have NO IDEA and NO METHOD PROVIDED BY THE CREDIT CARD COMPANIES to identify someone beyond the basics. Sure the above ad talks about people scanning the information passed along a network but still. They are going to take that information and use it with another merchant who had NO PART in the original theft. It's punishing the wrong people. There is no 100% secure method in existence. Fraud should be laid on those who make a profit off using credit cards. That's definitely not the merchants as they are already being robbed by the credit card companies. Up to 8% of a total sale goes to them. Seriously... who's the thief. Merchants don't have the power, money, or infrastructure to track down these thieves. The Credit Card companies do. Oh wait we should leave this up to the police. Yeaaaa... I'm an application developer and I've worked with credit applications. While the merchant obviously needs to bare the responsibility of making their networks as secure as possible the ultimate responsibility should NOT lie with them. It should lie with the credit card companies for making it so easy to steal this information. The new scanable credit cards are the WORST. You just have to walk near someone with one and walla you have all their information you need unless it requires the 3-4 digit number on the back. Even then the method used to steal these credit cards would still work. If you put the burden on those that loan the money it makes it makes them develop more secure practices. The merchant can't tell the credit card company how to make their cards or their security.
www.timcoleman.com is a total waste of your time. Never go there.
Credit card companies are branches of banks (who else has money to lend?).
Depends what you mean by "credit card company". Mastercard & Visa are not banks, they just rent out their name to banks. It's the bank that issues the cards. Mastercard & Visa set some standards in their contracts with the the banks.
On the other hand, American Express is not a bank. They issue their own cards themselves.
Why are credit card rates so high?
They are high because they can be. Credit card rates are (generally) unregulated and determined by the free market. Many people with high credit card rates don't realize that there are many, many other credit options available to them.
Either get a credit card with a low interest rate, or get a line of credit and pay your credit card in full every month from your line of credit. Generally, lines of credit have lower rates than credit cards.
Well, of course I was exaggerating when I said "no one." But it's interesting to hear your view. :) I didn't realize newegg provided it.
As for the "address" info - a very well-written system put in front of the credit card processing networks will do a real postal database lookup on an address. That's nice. It's also exceedingly rare. What you normally get for address verification is what the credit card processing networks themselves provide: AVS, the Address Verification Service.
A few interesting notes on AVS:
1) It only validates the digits in the street address and zip code, nothing else. So 123 Fake Street and 123 Oak Street are exactly the same in it's eyes.
2) It never rejects a transaction. Even if the address is wrong, it's approved. It's up to the merchant to check the response from the credit card processing network that says "the address was right" or "the address was wrong" or a dozen values of "the address was kinda' right" and then void the transaction if the response is unacceptable to them.
2 is becoming a little less true recently, though - several issuing banks have taken it on themselves to reject the transaction even if the AVS standard says they aren't supposed to. I think this is a good thing.
The problem comes in if you're an online merchant, you've followed the credit card companies rules for online transactions (AVS and other fraud check devices) and you get a chargeback for a fraudulent charge. How were you supposed to do a better job at verifying the identity of the CC user? The CC companies should be on the hook if they authorize a charge that turns out to be fraudulent. They authorized it, not me.
None of your comments make sense for an online store. outside of standard card checking stuff, their is nothing we can do to stop fraudulent use, and we get screwed over and over again. We can't check a signature, can't suggest debit over credit to check PIN and can't make sure Wendy is really a woman. So, drop the attitude about 'education.'
Great. You hate it when merchants take extra steps to make sure it's actually you using the card. It's people like you that discourage merchants (and visa/mastercard) from adding extra security that would help ensure that thieves can't swipe cards and go to town.
The cake is a pie
Doesn't do a thing except waste time. You would catch more false positives before you catch an actual thief that forgot to learn to forge the signature.
If I was a milk and bread merchant and you mentioned to me that I was "harassing" you by asking for ID, I'd just make sure to process that transaction really, really, slow... maybe manually enter the numbers instead of swiping, checking the card with a magnifying glass to check for evidence of tampering, etc. The loss of a sale as you stormed off in a pissy huff would be worth it.
And yes, I would keep helping others in line as I "waited for authorization." Sorry, sir. The computers are a little slow right now. Maybe I'll try calling in for authorization. I'm sure that MasterCard won't put me on hold once they know that we have royalty in line here at the bodega.
--
dman123 forever!
Filtering out the -1s and 0s since 1999.
it's hard enough for small businesses, arbitrarily pissing off customers
As a small business owner, let me say,
Get the hell out of my store!
I don't need customers like you.
Things got a lot better around here once we started "firing" customers who were assholes. More trouble than they are worth.
You're 100% wrong. I AM a small merchant, and I haven't had to deal with asshats like you before (we deal with jerks... just not in this way). I would be happy to ask you not to come back to the store if you threw a tizzy about us asking for your ID. It's not worth the risk to us to keep assholes happy.
I don't respond to AC's.
If its my money, I'm making sure you are the guy who's name appears on that credit card. If I have any doubt, I'm checking you out before I accept a piece of plastic. I'm the one on the hook for fraud. Not you.
Don't like proving your identity? Then pay cash. We accept that always. Want to give a promise instead? Then get ready for some verification.
How come "checking id when you promise payment in lieu of real money" = instant fascism!! Oh No Everybody Panic!!! 1984!!! AAAAHH!!
And the terms of my contract with VISA are none of your business. Don't like that I look out for my interests? Hit the road, jack.
Both of those things are a violation of your agreement, you can't require ID and you can't arbitrarily refuse my card. Why is it so hard to live up to what you've agreed to?
Because it's virtually impossible to survive as a business without accepting credit cards, and if all credit cards have the same bs terms....
That number is written down on the credit card itself. Also, it's transmitted along with the credit card number itself, even if it's not stored. Why not using one-time passwords? You get a list of numbers and are asked for one if you want to do a transaction. The list is issued by post and then you didn't even need ssl for security.
The merchants can do little to enforce such a system, that's up to the banks and credit card companies; so it's their fault that most parts of the world are left with pretty insecure payment systems.