Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm the OP. Let me know if any of you out there have questions! Or, better yet, experiences with simplifying payments on your site good or bad.


The "40% higher conversion rates" for not requiring CVV is extremely suspect to me. Looking at the paper, it wasn't an A/B test, but comparing entire sites. There could be any number of variables causing a difference in conversion rates.

On top of that, there is no published date, but it does mention May 2007 being in the future. Six years is an eternity in the ecommerce space, and I have a feeling people are more familiar with what the CVV code is and where it is located today.


You're right that it's not proper A/B test, so it may be a case that correlation doesn't imply causation. Unfortunately, there's not a lot of research published with rigorous A/B testing for this kind of thing. If any of you out there would like to run an A/B test (and have us help detect fraud if you're worried about increases there), I'd love to help!


Of course, any increase in conversion also needs to balance the increase in declines you'll see by not providing a security code.


I think it's suspicious as well.

Fine, here's the thing, if the person can't find the CVV in the card, I don't want his business. Period


I have purchased stuff on sites that have greatly simplified their payment process to the point I did not need to type anything at all! I click "Checkout"; the site displays a QR code; I scan it with my smartphone, which decodes it and prompts "Send 0.123 BTC to xxx?"; and I click "OK". Done.

This is how the purchasing experience looks like with Bitcoin which, for merchants, solves the fraud problem. Hence buyers do not need to give any billing information.


>Send 0.123 BTC to xxx

How is 'xxx' determined?

Looks like a great place to install malware that overtops the sites QR with its own and sends the payment off to the wrong place.


'xxx' is read from the QR code. The attack vector you mention is no different than malware that intercepts your credit card number when typing it in.


Doesn't Verified by Visa and SecurePay by Mastercard solve this problem? Whenever I enter a credit card I get asked to enter an online password as well.

Of course, ideally every citizen would be able to sign anything with a public-private key pair, counter-signed by the state.


Verified by Visa is an extremely high friction mechanism. It requires registration the first time around for each CC, and also an extra password or some other authentication mechanism like a bank dongle. If significant people bounce off transactions due to needing to type in their address, or due to needing to flip over the credit card and read 3 numbers, I don't even dare to think of what the bounce rate is for these mechanisms.

It's especially bad since just about no websites I ever buy anything from use VbV / SecurePay. That means that I don't remember the authentication secrets off the top of my head, so unless I'm at home will likely abort the extremely rare transactions that really require it. I've maybe needed VbV once in the last year, and had to try 3 cards before I found one that I could use on the spot.


It's gotten better, but the implementations the first years were abysmally bad. You're in this somewhat skinned payment flow, and then suddenly you're redirected to an un-skinned page, that maybe has your bank's logo on it, that asks for your secret password, or asks you to log in to your internet bank. And you would be on some sort of unrecognizable third-party url, because the merchant redirected you to their payment processor's webpage, which through 3DSecure redirected you to your bank, which in turn redirected you to some partner they used for that, because the bank couldn't figure out how to do it in less than three years because making software is hard or something.

I think I abandoned every such purchase on reflex because it just screamed phishing attempt each time.

Extremely high friction indeed. Most merchants these days give me the option to skip it. Thank you.


Verified by Visa is incredibly obnoxious. Thankfully its very uncommon in North America. Seems to be much more popular in Europe (or maybe European sites just force VbV for my US-issued Visa).


Important to note that companies can turn off verified by visa but then they pay a higher transaction/processing fee. So many merchants dislike it significantly but then pay higher rates. Fun place to be. I wonder how Stripe will handle 3DS with their UK launch given I've heard it has as much as 80% penetration into online sales?


Verified by Visa is incredibly annoying to the consumer. I've abandoned payments because I forgot my password. Now I have it turned off completely.


How do you turn it off?


I haven't had to use it in a long time so my memory is fuzzy...but last I remember, when the actual Verified by Visa form pops up, there is an option to disable it.


I hated when Newegg started using Verified by Visa. The password requirements were so silly that I would always forget my password. I haven't been prompted to enter my VbV password at Newegg for some years.


I loathe 'Verified by Visa'. I changed credit cards so that I can avoid it.

It's thoroughly stupid and broken.


There's also an enhanced version of 'Verified by Visa' and 'SecurePay': at your bank you order OTP calculator/card reader and for every online purchase with your credit card, you are prompted for OTP passcode. This card reader costs about 30 euros. Mine looks like this: http://www.vasco.com/products/client_products/card_reader_di...


> Of course, ideally every citizen would be able to sign anything with a public-private key pair, counter-signed by the state.

State-verified identity for payments is your ideal case?

Have you heard of Wikileaks?


Kills fraud and also conversion and revenue. Such a pain.


How are you penalized if you don't collect the extra information (besides potentially higher rates as stated in the post)? Are there more frauds leading to chargebacks that may have been detected if the card merchant had more information?


If you were to use a really minimal payment form (number and expiration), it's likely that you'd get somewhat more chargebacks. However, you'd also get more revenue. Let's say your chargeback rate goes from 0.1% to 0.2%, but your conversion rate goes from 50% to 60%, then you come out way ahead.

In our experience, you can stop most fraud without putting up roadblocks for your users. Every site is different, but to give an example, we were able detect 90% of fraud for a site with a huge fraud problem without requiring any extra verification from the users.

The really key penalty to avoid is what is called an "excessive chargeback program," which usually triggers for chargeback rates that exceed 1%. You initially get a warning, and if you can't get your chargeback rate down, your payment processor has the right to shut you off. If you're in an excessive chargeback program, then I'd definitely recommend "playing it safe."

But otherwise, I think slimming down your payment form and carefully measuring the effect on fraud is almost always a smart business move.


> Let's say your chargeback rate goes from 0.1% to 0.2%, but your conversion rate goes from 50% to 60%, then you come out way ahead.

No, you don't. You need more information about the transaction then that. What if your profit margin is 1%? Then you've come out even, because chargebacks cost you the full cost of an item, but an extra conversion only nets you the profit on that sale.

Note: I assumed that the 0.1% and 50% to 60% were both percentages of potential sales, because it made the math easier. Otherwise, you have 20% x 1%=2% more profit and .2% x 120%-.1%=.14% more loss from chargebacks, so you have come out slightly ahead.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: