Hacker News new | ask | show | jobs
by Vertrauen 3549 days ago
> 3D secure

As a customer, I hate 3D secure. When I get that shit thrown at me, I often just head over to Amazon and buy the same item there. Even if it is more expensive.

Reasons:

The 3D Secure form always looks so unprofessional it makes me shiver.

It often is loaded in an iframe so it could come from god knows where.

Often it plain out does not work. It aborts the transaction with "Transaction aborted" or something like that with no further info. So I sit there thinking "Uhm.. what now? Is my password wrong or what?".

Why would I input even more of my data into your damn form? The more data I give you, the easier you can mess with me. Now my CC card number and verification number is not enough anymore. Now you want my 3D "secure" password. What do you want next?

5 comments

I've used it via "verified by visa" with two banks in two countries.

In both cases, there is a custom phrase that I provide the bank, which is then provided on the 3D-secure page where i enter the sms OTP.

Honestly so long as they show me the phrase I gave them, I couldn't give two shits if it looks like it was designed in 2002, at least that keeps it consistent with the rest of their online banking page styles.

Here in Sweden, 3D secure is effectively synonymous with two-factor auth.

It's insane that, at this point, the banks don't just outright block any payment recipient that doesn't use it.

I can only talk from my experience, but with 3 different (french) banks it has been decent looking (paypal level), clear instructions and errors, let me retry 2 or 3 times if I type the wrong code.

The only issue is that I agree it shouldn't be allowed in iframes. The vast majority of ecommerce here uses it nowaday, except for sum under 20€ usually.

Most banks in Germany seems to have switched to text messages or generator apps for the 3D Secure code. A lot better experience and protects against simple phishing.
That's why there is Apple Pay on the Web. I bought a new iPhone so that I could use it instead of 3DS.