Verified by visa
Nov. 14th, 2004 12:11 amI had my first "verified by visa" popup today.
If this means nothing to you, what happens is: you try buy something online with your credit card. When you hit the submit button in whatever online shop it is, a popup window appears and asks you to confirm the amount. The idea is that the popup is securely connected to your credit card provider, so that they can have confirmation of the order direct from you rather than through the merchant. You enter a password so the provider knows that it's you they're talking to and they approve the transaction. A few days later your new toys arrive and several weeks later you have to pay for them.
I find myself unconvinced by the current implementation.
At least in the case of the place I was buying from the popup turned off all the window furniture and embedded the output from the card provider in a frame. That is to say, you didn't get to see the URL displayed by the web browser: you just had the text of the web page. So you can't tell from that that you're really talking to your card provider. (Any idiot can copy a web page.)
The mechanism includes a workaround for this: when you register you choose a password that the provider uses to authenticate themselves to you. But a crooked merchant could make the same request your web browser does, and redisplay the results to you with the numbers changed to what you expected, and then send your answer back to the card provider. (This is harder for a crook to do, but they only have to do it once.)
As far as I can see the only thing preventing such a man-in-the-middle attack on this protocol is the user checking the origin of the popup, which (i) has been made maximally inconvenient (ii) you're not told to do (iii) it uses a different URL from your bank anyway. (The same hostname turns up when you register so you do have something to compare with - but will it be the same in 12 months time?)
(I'm assuming that comparing apparent URLs is a sound thing to do, which is probably optimistic.)
I have a chip and PIN card too, now, but haven't been asked for the PIN yet, despite having gone to the effort of remembering it, and despite having shopped at at least place which visibly had the kit for it.
(no subject)
Date: 2004-11-13 04:24 pm (UTC)I've used my (chip &) PIN on two out of 5 cards so far. I suspect the other three probably won't get it...
(no subject)
Date: 2004-11-13 04:56 pm (UTC)(no subject)
Date: 2004-11-13 04:58 pm (UTC)(no subject)
Date: 2004-11-13 05:33 pm (UTC)(Even now it refuses to fall back to magstripe mode if there's a dead chip in a card - we had one of those today and had to ask the customer to pay with a different card.)
(no subject)
Date: 2004-11-14 03:18 am (UTC)(no subject)
Date: 2004-11-14 04:34 am (UTC)(no subject)
Date: 2004-11-14 05:12 am (UTC)I deliberately don't have my cards enabled at the moment, and that's the way I intend to keep things for as long as possible — ideally indefinitely.
(no subject)
Date: 2004-11-14 05:29 am (UTC)Yes. Chip&PIN and Chip&Signature cards are different. As I mentioned, there's an override procedure for Chip&PIN cards to fall back to accepting a signature at the moment; this involves a couple of keypresses at the PIN prompt and a swipe of the terminal supervisor card. I believe this feature is due to be removed in January.
(no subject)
Date: 2004-11-14 05:38 am (UTC)A more minor problem, but one that still bothers me, is that the new system means that my brother have to reveal his PIN to all his carers. He can't sign very well, but at least with a signature he has to be present in person to authorize transactions. There may not be very many people who don't have the physical dexterity to type in a PIN number, but there are certainly some.
I'm tempted to start insisting on paying for everything by cheque.
(no subject)
Date: 2004-11-14 06:46 am (UTC)(no subject)
Date: 2004-11-14 10:24 am (UTC)(no subject)
Date: 2004-11-14 10:27 am (UTC)(no subject)
Date: 2004-11-15 01:42 am (UTC)That's interesting to know, thanks. I get the impression from what you're saying that retailers are phasing out the technology to accept them, though? I shall try pestering my bank (Smile / Co-Op), but they do seem to be terribly gung-ho about how wonderful and amazing the chip and PIN technology is.
(no subject)
Date: 2004-11-15 02:37 am (UTC)(no subject)
Date: 2004-11-15 04:28 am (UTC)We don't need no steenking popup windows. I'm still at the stage of being rather disappointed when sites make me use JavaScript.
(Though, tangentially, I seem to have found a site which can circumvent Mozilla's popup-blocker by using Flash to open the new window.)