Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So when you sign up for a CC the address is used by the bank/institution, but when you tell a merchant they don't even cross-check with the bank... ever? They'd have to, otherwise what's the point in asking for it? Maybe the bank only shares zip codes? If so, why not just ask the buyer for a zip code?

Every time you make a cc purchase online, the seller, if they get your details directly can then go out and use your details to make purchases of their own from your card. That's insane, let alone having your name and address details. No wonder cc companies get fraud.

If I am going to use a credit card, let me hand over the number, and then send me an email to confirm the purchase. Not sure what the flow of that would be and if/how to use confirmation codes. Also, the last thing I'd want is another "app". Maybe optional 2FA.

Thanks.

Crypto debit cards are on the rise anyway.

Another idea would be to have a once-only disposable CC number generator. New purchase, get new number. Also, when new numbers are generated, the bank can record the who/when/where of the request and it can be matched with the when/where/how it is used later, and how many times to get a clue if an account is compromised as a fallback protection.

Imagine if those numbers went on a blockchain for merchants to use. They could see if/when a number was already used, but not necessarily need to use/integrate with it - but the bank would. Crypto address generators are commonplace now but addresses are very hard to key-in. So the blockchain would be a security layer on top of the conventional transaction, which could work without it if need be.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: