Hacker News new | past | comments | ask | show | jobs | submit login

But then why bother using it at all? Do they assume that no one malicious could ever get into my account (for argument's sake)? If you're going to make me set a password, make me enter it each time I "use" your service. My gripe isn't with the vendors per sé, but with how Verified by Visa and SecureCode operate.

I'd much rather type an extra password during the checkout process instead of being charged $700 for hardware and Windows Vista DVDs (thieves aren't always the brightest).




> But then why bother using it at all? Do they assume that no one malicious could ever get into my account (for argument's sake)? ... instead of being charged $700 for hardware and Windows Vista DVDs

You're making an awful lot of assumptions you shouldn't be making.

First, 3DS doesn't provide you any more security than you really had before. It helps the merchant secure their transactions, however. But even if someone did charge $700 to your card, it's an easy phone call to get it resolved. Not only this, but I'm sure Newegg would require another check if something was amiss with the transaction. Any sizable operation will work to make sure that legit users can make purchases as fast as possible with as little hassle, but that doesn't mean it's not verifying things in the background.

So why would Newegg use 3DS? Simple. They want to verify that a new account is who they say they are, and not a stolen card. You're a legit user. You make a purchase. Next time you come back, you'll probably be making the purchase using the same billing address and the same shipping address. Even if you didn't make the order, you'll call up Newegg to complain, and they'll work to refund the order and resolve the matter as quickly as possible.

But you as a cardholder have always been safe. A simple call to the bank, and "No, I don't recognize the transaction" and you get your chargeback and you owe no money. However, with 3DS, you can't just say it wasn't you. If the merchant doesn't provide the service, then yes, you can still get it. 3DS for legit users prevents them from committing friendly fraud.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: