syazaz Jan 5, 2016 @ 12:53am
Implement 3D secure
Dear VALVe,

Beginning this new year, all banks in my country now blocks Card-Not-Present (CNP) transaction unless the online store implements the needed extra secure system (3D secure) due to increasing fraud worldwide.

To continue using CNP transaction on non 3d secure, we need to opt-in by calling banks, however in my opininion I think it is better to stay opted-out to minimize the risks for example:
- if the hackers hack the steam server and stole our credit card information or
- when steam server failure occured such as when we log in with our credential but logged in as another person account. Some may try to use this chance to perform malicious transaction without owner consent.

I hope this can be implemented and HL3 will come out soon. Thanks.

Regards,
syazaz.
Last edited by syazaz; Jan 5, 2016 @ 12:54am
< >
Showing 1-2 of 2 comments
 KARR™ Jan 5, 2016 @ 5:46am 
The servers have been "hacked" in the past and credit card details exposed - however they are hashed and salted and are very hard to be extracted. Even if they gave them out in plain text, they do not store the CVV (3 digits on back of card) which should always be asked by anyone taking a card transaction.

The xmas "cache" issue where you saw a page for another user, was just that, you saw a page - you had no interaction with the account and weren't logged in AS that user. You couldn't make a purchase on their account as you were still logged in as yourself - just looking at a cache of someone elses page.

On the downside....

3D secure is also very poor on "worldwide" sites. Where users may have cards issued by banks who deal in more than one country.

It's also not on every card. The main Visa/Mastercard issued banks can use it, but there are dozens that can not.

As the site isn't on Valves servers and redirects to another site, you WILL get dozens of people not purchasing as it looks 'strange' to new users who don't know what it is!
syazaz Jan 5, 2016 @ 6:35am 
Hi,

Its actually just an example, I know about the encrypted info and page that shouldn't be cached. However I knew very little about 3D secure. Can you explain why its act very poor for site that accepting payment from worldwide?
AFAIK the bank will give a link to the server and the user get redirected to it. Once the user entered the information required, the bank will proceed with payment and give status to the server. (I only use 3D secure once or twice, not actually remember the flow).

As the last sentence on your post, every card owner should aware the card issuer, so its not a problem at all and not a strange; plus card that doesn't have 3dsecure enabled should proceed normally.
Last edited by syazaz; Jan 5, 2016 @ 6:41am
< >
Showing 1-2 of 2 comments
Per page: 1530 50

Date Posted: Jan 5, 2016 @ 12:53am
Posts: 2