Hacker News new | ask | show | jobs
by a_imho 877 days ago
Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.
4 comments

Then they store your credit card info in a database and leak it some time next year.
It's pretty annoying that they load all this pain and suffering onto the user who's just trying to make a purchase, when the company's database is often the weakest link.
This is fascinating to me. Why do we have to go through all these hoops with the bank and somehow, when the credit card # is eventually and ineluctably leaked, the thieves have no problem using it to make purchases, whiteout going through all these 3FA etc.

How is that possible?

Hence the virtual card. I can just discard it after a few purchases. Isn't this enough?
Captcha IMO is way worse in terms of user experience than 2FA. And the only 2FA that I don't detest are app push and TOTP.
Well pizza in particular often has a cash payment option, which I always use for that.
This would be enough to have me drive to the pizza place myself and pay cash.