What Can Be Done About Security of Debit Cards?
JumpDrive writes "I have been the victim of (Visa) debit card theft. I do not know where they stole or got the number, but it was used one day on the other side of the country and the next day it was used in Europe until they cleaned out my account. I had been monitoring my account online and immediately went to the bank and filed a claim. I was told at that time it would be 3 to 5 weeks for them to investigate the claim before they could return my money. Recently I tried to make a purchase with a debit card and was told that they couldn't use the card since it wasn't a Visa or MasterCard check card; this led to a discussion of why I no longer have a Visa or MasterCard check card. Which then led to the question of 'What can be done about it?' Currently I have a separate account for debit usage for my personal safety. But I also think that those producing these check cards should be required to advertise the hazards of having one of these cards (not in small print and maybe required in advertisement of these cards, similar to what is required with pharmaceutical drugs on television) and/or that if a debit or check card is issued a separate account should be required for its use, and users informed of the issues of placing all of their money in the same account that their debit card has access to. What other precautionary measures should be required or taken?"
The short answer? The banks will do nothing for you today.
The long answer: Nobody will do anything for you tomorrow, either.
Why? Because Visa does two things, only one of which makes money. First, they are in charge of defining financial card security through the PCI council, and they own and operate the secure network VisaNet, which carries authorizations from retailers to banks. Guess which one makes them money?
If Visa were to design and offer a cryptographically secure solution, one based only on smart cards for the customers and Hardware Security Modules (HSMs) at the banks, then I could safely route my charge authorizations over the plain ol' Internet. I wouldn't need to use the charge-per-transaction VisaNet. Visa would stop making money.
So instead of offering a secure solution, Visa and the PCI council say, "Merchants must lock down their systems, protect this data, follow these 12 steps, acknowledge that you are powerless over alcohol (oh wait, wrong 12 steps), and if you don't, we'll loudly blame you for allowing someone to see our non-existent security."
Visa owns the protocols used between merchants and banks. They could strengthen the protocols. They could prescribe encryption. They could require the deployment of chipped banking cards. But they do not, and have not for many, many years, despite a pathetic track record of security.
If you want the banks to be safe with your money, you ironically have to take charge of your own security. If you switch to using the green paper stuff, your losses will be finitely limited to what you carry on your person. If you want a more achievable answer in today's plastic world, DO NOT CARRY DEBIT CARDS. Debit cards do not offer you protection against loss. Credit cards are limited by U.S. law to a maximum of $50 liability to the cardholder. Debit cards losses are usually covered by the bank, but they are under no legal obligation to do so. For ATM access, most banks will honor your request for an ATM-only card instead of accepting their default ATM/Debit card. Of course, the use of credit cards requires personal discipline to always pay the debt on time, but otherwise you would see little difference.
John
I have set up my acct such that if there is an access made more than a certain amount of money and/or out of my local area, they call me/text me to call them and verify the transaction. I am not a frequent traveller, so this works out for me. Look up if such a facility is available with your bank too. Another thing, see if they offer some sort of fraud protection mechanism. Some banks do that. That takes off some of the time-delay/processing worries too. If you choose to use your debit card and not credit card mostly, also, move your money from checking to some savings account and keep very little ( subjective) money in checking. That may help too.
IAABG (I am a banking geek).
The rules for provisional credit on debit cards is very well established. They fall under Regulation E, section 205.11. The bank has ten days to get you a provisional refund, and can take up to 45 days in certain circumstances to complete their investigation and finalize the credit.
Make sure you get them a notice in writing! Once you do, they have ten days to credit you, and many banks will do it much faster. If the bank drags their feet, just tell them "I want provisional credit within the mandated timeline per Regualtion E".
Here's more on this topic:
http://www.bankersonline.com/technology/guru2008/gurus_tech022508c.html
http://usa.visa.com/personal/security/visa_security_program/zero_liability.html
http://finsolinc.com/Reg%20E%20EFTA%20Error%20Resolution%20Flowchart.pdf
The protection for misuse of debit cards is strong, you just need to know what to do. If your bank isn't responsive, Move Your Money to a smaller institution that cares.
You are paranoid. And ignorant. As long as you report the theft to your financial institution as soon as you learn about it, there are strong protections in place. It's simply not true that it's up to YOU to track down your money. It's up to your financial institution. They are required by law to credit you in the case of errors or unauthorized purchases, and are even required to issue a provisional credit in many cases before the investigation is complete.
A Visa Debit card carries the same protections as a Visa Credit card for signature based-transactions. PIN based transactions are still covered by Regulation E, which protects the consumer.
And there's no such thing as a perfectly good ATM card: with a skimmer, a fraudster can clone your ATM card and have your PIN. Fraudulent PIN based transactions are MUCH harder to refute. People call up all the time and say, "I have no idea how that person got my PIN number, I've never given it to ANYONE!" We (my bank) pull the ATM video, and sure enough it's their son/daughter. The consumer sheepishly admits, "Oh, well, I just told them my PIN once, months ago..." Given the choice between turning the video over to the police or rescinding the claim of unauthorized use, many people will choose the latter.
Banks must roll differently stateside, here in Australia my visa debit card has been compromised twice. Both times I was contacted by the bank (different banks in each case) before I even knew what was going on. They had a new card and number out to me in 3 days and the dodgy charges were refunded by the time I logged on to my internet banking to check.
Another time I was on my honeymoon and the resort we were staying at put a rather large hold of funds on my visa debit card. My bank rang me and said they had a large charge on my card and asked if it was ok.
Impressive all round.
Legally.
In most countries a bank account is legally a loan to the bank. Legally it isn't a safety deposit box where they store your money for you.
This means the money is theirs to do with as they please and they are graciously allowing you to use their credit instead, with the attached terms and conditions.
Deleted
A lot of the audit rolls in cash registers also record card numbers. And yet business is heard to say, "we only store card numbers in encrypted data marts." My ass.
http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&sid=635f26c4af3e2fe4327fd25ef4cb5638&tpl=/ecfrbrowse/Title12/12cfr205_main_02.tpl
I work IT in a community bank. I work very closely with our Operations and Fraud department. Here is what I can tell you about VISA debit card fraud. If you are a consumer, you are totally protected IF you report your debit card being lost, stolen, or compromised within 3 days that you became aware of it being lost, stolen, or compromised. The bank will also have a hard time proving when you found out you had a problem with your card. The bank HAS to give you your money back. VISA and Washington D.C. make all of these rules. The little known secret is that banks take huge losses on debit card fraud because the regulation coming from Washington D.C. totally protects the consumer. Most of the time in a fraud case, the bank isn't able to recover the money from the merchant and they have to refund the money to the consumer. Therefore, the banks lose money on VISA debit card fraud. As consumers, you really have nothing to worry about when it comes to VISA debit card fraud. You are totally covered. If you have a VISA business debit card though, you are not covered by the regulation and you are subject to taking losses in a fraud case. If you are a business owner, you better be REALLY CAREFUL when it comes to who has business debit cards tied to your accounts. In your case when the bank said 3 - 5 weeks to return your money, you should change banks. Go to a good community bank or credit union in your area. Somewhere that will recognize you as a person and not a number. Stay away from the large nationwide banks and regional banks. Especially the ones that are having loan trouble. They are trying to stay afloat by sticking all of their good customers with lots of account fees. I use my VISA debit card everywhere and never worry about fraud. You should do the same. I do suggest that you be careful using it on the Internet. As a computer security professional, I do recommend that you practice good computer security.... AV, Web Filtering, OpenDNS, Patching, etc....
This is what an American Express card is for, you use it for your daily purchases, and you pay it off at the end of the month, no interest or fees. (other than annual fee). You get up to 20 days of float on your money also if you were to keep a money market account that you write just your mortgage payment out of etc, and use your Amex to pay everything else. If place doesn't accept Amex, then I'd recommend Paypal's Mastercard debit card, you transfer money into it, so you're never going to overdraft it, and their fraud dept is really good, and they are prompt on their security investigations. Plus again, it pays you interest on any balance, and cash back on (credit) purchases. For my business I made my merchant account (credit card processing) account a totally seperate account than my primary checking, I siphon money off every morning to the business account. But, that way if someone does a chargeback for a a large purchase and they put an investigatory hold on my account, I don't have vendor, payroll, mortgage checks bouncing... then again, I don't anyway, because I deal with a local regional bank (only 10 branches) that calls me anytime there is any problem, and gives me a few hours to make it right. This is why you don't deal with the bank of america's of the world. With a small bank all money deposited (including checks for anywhere) are available for withdrawl immediately, any overdrafts are recorded at night, and you have until 11am the next morning to make them good without paying any sort of fee, should you overdraft, they will go ahead and pay the item, and nearly all the time refund your overdraft fee if you talk to them. This is one way to get small loans, as they will let you overdraft your account and pay it back a couple days later for just a $30 fee... yes $30 might be alot on a $2500 loan but comes in handy in an emergency. This is why you get off your lazy a$$ and go to the bank and make deposits, INSIDE the branch, not the drive through. You get to know your bankers, and they get to know you. My bank offers free remote deposit capture, including they will give you all the hardware, but I still go into the bank about 4 times a week, just to make myself known.
According to my credit card merchant agreement (for Visa and Mastercard) I am not allowed to offer a discount for cash or other forms of payment, I am also not allowed to charge a surcharge for their cards and I am also not allowed to ask for any extra Identification. I am surprised that Visa and MC are not enforcing that in all countries (we are in Canada).
For Bank of America customers, this service is available as well.
Reply to That ||