More information about the Underscore mailing list

[_] 3D SECURE

Oliver Humpage oliver at watershed.co.uk
Tue Dec 4 19:45:46 GMT 2007

On 4/12/07 19:11, "theUKdude" <theUKdude at theUKdude.com> wrote:

> We've been here before. People were up in arms about having to remember a
> pin number so they could shop at Tesco, instead of just signing a little
> slip of paper.

I wasn't up in arms about remembering a pin, I hated it (and still do) for
being utterly insecure. For a start, a large number of people type in their
pin without even attempting to hide it - I always want to just recite their
pin back to them when I'm behind them in a queue, but fear getting my jaw
broken or arrested.

Secondly, even if you're careful, look at what happened to Shell[1]: their
franchised petrol stations got infiltrated by an East European cartel who
installed their own C&P machines and snaffled thousands of card details,
complete with pins.

Signatures aren't great, but I still think it's harder to forge a signature
(assuming staff are trained to spot them) than it is to snaffle someone's
PIN - and the banks are a lot less likely to admit it's not your fault if
your PIN was used by someone else.

Anyway, back on topic, presumably the smaller sites will just start using
Google Checkout now?

Oliver.

[1] http://www.theregister.co.uk/2006/05/08/shell_suspends_chippin/