| 3-D Secure has been a fiasco IMO. I can recall when we first tried 3DS in the US and it went over like a lead balloon. Let's jump out of the middle of checkout and go to a page which looks like they're trying to phish your bank account to continue, and by the way, you can just skip it. So customers did, and then merchants followed, except in countries that effectively required it because they cared about fraud. One of the major selling points of 3DS2 was basically "we can guesstimate fraud with magic black-box logic behind the scenes so most of the time the customer is not disrupted." But it's still lipstick on a pig because there are plenty of outs where you don't strictly need 3DS even in "countries that required it", and it's still window dressing around the idea that we're giving merchants an unscoped credential and hoping desperately it doesn't get misused or stolen elsewhere. When we finally decide we don't want to get lapped by India and Brazil in payment tech anymore, I hope the camel-designed-by-committee it spawns is a push-only paradigm. If I want to buy something, let Newegg render a HTML microformat that browsers can detect and turn into a big clicky link to my bank's website/app with a pre-configured outbound transaction. Just as easy for the customer as a stored card, with less risk of abuse/compromise. |
> I can recall when we first tried 3DS in the US
Exactly, it has been a fiasco in the US, but it's working quite well in Europe.
> When we finally decide we don't want to get lapped by India and Brazil in payment tech
They are indeed ahead, but they still work based on some kind of user authentication that's not a plaintext credit card number. That's the same disruption as 3DS, except normalized and a better executed.