Hacker News new | ask | show | jobs
by cfgghsj 1729 days ago
While I didn't work on indian regulations, I've worked directly on 2FA/OTP with recurring charges. For this regulation, the recurring charge must be initiated with an OTP code, but subsequent charges may happen automatically. There should also be an exception process to allow preexisting standing instructions to continue.

This article has details of the actual regulation: https://indianexpress.com/article/explained/explained-why-au...

1 comments

I believe it started that way but now everyone has just stopped recurring. I have already got email notifications from AWS (India), my phone provider, etc. that we have to pay manually from next month.
> everyone has just stopped recurring

Every one had two years to implement the e-mandate system.[1] What does it say about Amazon, your phone provider and your card issuer that they haven't been able to do it in time and decided, instead, to pass the buck to you, the customer?

[1] https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=1166...

Yes, because most services haven't met the full scope of the RBI circular yet - sending pre-debit notification, self serve mandate revocation, etc