About That Three-Digit Security Code (CVV) ...
#1
Original Poster




Join Date: Aug 2001
Location: Tha OC
Programs: Outgrew all status except AA: Plat for life (the program's); Costco: Ex Plat
Posts: 677
About That Three-Digit Security Code (CVV) ...
"NO."
That's my answer whenever someone at the other end of a phone asks, "May I have the three-digit security code?"
If I'm here, then I'm not there.
My card is here, with me.
Not there.
CNP stands for "Card Not Present."
As in, not present with the merchant trying to run my card.
What is the purpose of a security code, appearing only on the original card, if it must be given out to anyone who asks?
I don't see why this code should ever be given to a human.
Its only legitimate use is online, at a SECURE website, where it is captured but not saved to be read later.
So why does everyone ask for it?
Because no one says no?
Anyone who hears that code over the phone, together with your account number, billing address, and expiration date, has everything they need to go shopping -- or sell it later to a thief.
Why is this practice allowed by the issuers, and how do we stop it?
Defeats the entire purpose of the code.
That's my answer whenever someone at the other end of a phone asks, "May I have the three-digit security code?"
If I'm here, then I'm not there.
My card is here, with me.
Not there.
CNP stands for "Card Not Present."
As in, not present with the merchant trying to run my card.
What is the purpose of a security code, appearing only on the original card, if it must be given out to anyone who asks?
I don't see why this code should ever be given to a human.
Its only legitimate use is online, at a SECURE website, where it is captured but not saved to be read later.
So why does everyone ask for it?
Because no one says no?
Anyone who hears that code over the phone, together with your account number, billing address, and expiration date, has everything they need to go shopping -- or sell it later to a thief.
Why is this practice allowed by the issuers, and how do we stop it?
Defeats the entire purpose of the code.
#2
FlyerTalk Evangelist




Join Date: Jan 2005
Location: home = LAX
Posts: 26,111
Even if it's the bank you called about the card?
Or do you make an exception in that case?
I've had some bank recently (can't remember which one) ask me for that code to verify that I actually had the card in hand. But since I called them, I didn't see a problem with giving it. (I also called them from home, where there was no one to overhear it.)
...
Meanwhile, even without the CVV, someone who hears your account number, billing address,a nd expiration date, has everything they need to go shopping at many places online.
So I would be wary of buying things over voice phone with a card (that's not already on file with company) in a situation where people can overhear, no matter how much or little information they ask you. Because if that information was good enough for them, it's going to be good enough for any thief that overheard what you were saying and made a record of it.
And thus I don't see what CVV makes worse. It's already bad enough if they get everything other than CVV. All CVV does is extend the number of places they can use your card info, but even without the CVV they can use your card info at lots of places. (And someone who's into stealing card info they overhear probably knows where they can shop with however much of the info they got.)
Or do you make an exception in that case?
I've had some bank recently (can't remember which one) ask me for that code to verify that I actually had the card in hand. But since I called them, I didn't see a problem with giving it. (I also called them from home, where there was no one to overhear it.)
...
Meanwhile, even without the CVV, someone who hears your account number, billing address,a nd expiration date, has everything they need to go shopping at many places online.
So I would be wary of buying things over voice phone with a card (that's not already on file with company) in a situation where people can overhear, no matter how much or little information they ask you. Because if that information was good enough for them, it's going to be good enough for any thief that overheard what you were saying and made a record of it.
And thus I don't see what CVV makes worse. It's already bad enough if they get everything other than CVV. All CVV does is extend the number of places they can use your card info, but even without the CVV they can use your card info at lots of places. (And someone who's into stealing card info they overhear probably knows where they can shop with however much of the info they got.)
Last edited by sdsearch; Dec 14, 2017 at 6:37 pm
#3
Join Date: Mar 2012
Location: Boulder
Programs: AA Plat, CX Silver
Posts: 2,361
A transaction run with a CVV is still a CNP transaction.
While PCI is mostly toothless, mail-order merchants generally certify under the SAQ C standard, which requires that they do not store cardholder data.
Obviously that does nothing to stop a phone agent from scribbling down your details on a post-it note but who cares? You're not liable for it.
While PCI is mostly toothless, mail-order merchants generally certify under the SAQ C standard, which requires that they do not store cardholder data.
Obviously that does nothing to stop a phone agent from scribbling down your details on a post-it note but who cares? You're not liable for it.
#4
FlyerTalk Evangelist


Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,742
I wonder how OP will end up handling a gas station chain named after a certain type of quotation mark asking him to enter the CVV on the terminal. Especially if his car has almost no gas left and his card won't work at the pump for whatever reason.
(This exact thing happened to me this morning. Well, not the nearly running out of gas or the card not working outside, but the terminal inside did ask for it.)
Anyway, the physical store locations ask for it because they had to manually enter your card details for whatever reason--or their terminals don't have chip enabled and it's an additional security measure. Online stores ask for it because it shaves a bit off their card fees and is something that in theory only the cardholder would know, as it's supposed to be disposed of by the merchant after authorization. Really, we should do 2FA for online transactions but I imagine US stores/issuers aren't going to bother if we're going so far as to effectively get rid of all cardholder authentication for chip transactions.
(This exact thing happened to me this morning. Well, not the nearly running out of gas or the card not working outside, but the terminal inside did ask for it.)
Anyway, the physical store locations ask for it because they had to manually enter your card details for whatever reason--or their terminals don't have chip enabled and it's an additional security measure. Online stores ask for it because it shaves a bit off their card fees and is something that in theory only the cardholder would know, as it's supposed to be disposed of by the merchant after authorization. Really, we should do 2FA for online transactions but I imagine US stores/issuers aren't going to bother if we're going so far as to effectively get rid of all cardholder authentication for chip transactions.
#5
Join Date: Mar 2012
Location: Boulder
Programs: AA Plat, CX Silver
Posts: 2,361
I wonder how OP will end up handling a gas station chain named after a certain type of quotation mark asking him to enter the CVV on the terminal. Especially if his car has almost no gas left and his card won't work at the pump for whatever reason.
(This exact thing happened to me this morning. Well, not the nearly running out of gas or the card not working outside, but the terminal inside did ask for it.)
Anyway, the physical store locations ask for it because they had to manually enter your card details for whatever reason--or their terminals don't have chip enabled and it's an additional security measure. Online stores ask for it because it shaves a bit off their card fees and is something that in theory only the cardholder would know, as it's supposed to be disposed of by the merchant after authorization. Really, we should do 2FA for online transactions but I imagine US stores/issuers aren't going to bother if we're going so far as to effectively get rid of all cardholder authentication for chip transactions.
(This exact thing happened to me this morning. Well, not the nearly running out of gas or the card not working outside, but the terminal inside did ask for it.)
Anyway, the physical store locations ask for it because they had to manually enter your card details for whatever reason--or their terminals don't have chip enabled and it's an additional security measure. Online stores ask for it because it shaves a bit off their card fees and is something that in theory only the cardholder would know, as it's supposed to be disposed of by the merchant after authorization. Really, we should do 2FA for online transactions but I imagine US stores/issuers aren't going to bother if we're going so far as to effectively get rid of all cardholder authentication for chip transactions.
https://www.adyen.com/fr_FR/presse-e...nversion-rates
#6
FlyerTalk Evangelist


Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,742
We tried 2FA (kinda) for online transactions. US merchants saw 43% drops in conversions on average.
https://www.adyen.com/fr_FR/presse-e...nversion-rates
https://www.adyen.com/fr_FR/presse-e...nversion-rates
The more recent implementations work like what we usually think of as 2FA, where a one-time code gets texted or emailed. That along with a lot more merchant support (possibly mandated by card networks and/or the law) would probably result in a lot smaller of a drop, if one were to occur at all.
This is all likely moot, though, as banks in the US are reluctant to introduce any sort of friction whatsoever--either for in-person transactions or otherwise.
#7
Join Date: Nov 2015
Location: BNE
Programs: NZ*G, QF Bronze, VA Red
Posts: 563
The more recent implementations work like what we usually think of as 2FA, where a one-time code gets texted or emailed. That along with a lot more merchant support (possibly mandated by card networks and/or the law) would probably result in a lot smaller of a drop, if one were to occur at all.
#8
FlyerTalk Evangelist


Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,742
There's apparently a reason why that's not enough of an incentive, at least as of now. Increased online fraud may change those calculations at some point.
#9
Flyertalk Posting Legend Moderator: Credit Card Programs, American Express, Capital One, Chase, Citi, Diners Club, Eco Travel, Signatures




Join Date: Jun 2003
Location: Miami, Mpls & London
Programs: AA, IHG & Marriott Platinum; DL & HH Gold
Posts: 51,855
Because it is a security feature specifically designed for Card Not Present transactions which includes both telephone and internet. Security is not a binary perfect/useless outcome. If the code reduces fraud by any measurable amount policy can be established by comparing that savings to the implementation cost.
#10
Join Date: Mar 2012
Location: Boulder
Programs: AA Plat, CX Silver
Posts: 2,361
3D Secure isn't exactly 2FA, at least how it was initially implemented; it was more along the lines of a static password. Plus, there are enough non-supporting online merchants that it's easy to use one of those instead if one forgets that password.
The more recent implementations work like what we usually think of as 2FA, where a one-time code gets texted or emailed. That along with a lot more merchant support (possibly mandated by card networks and/or the law) would probably result in a lot smaller of a drop, if one were to occur at all.
This is all likely moot, though, as banks in the US are reluctant to introduce any sort of friction whatsoever--either for in-person transactions or otherwise.
The more recent implementations work like what we usually think of as 2FA, where a one-time code gets texted or emailed. That along with a lot more merchant support (possibly mandated by card networks and/or the law) would probably result in a lot smaller of a drop, if one were to occur at all.
This is all likely moot, though, as banks in the US are reluctant to introduce any sort of friction whatsoever--either for in-person transactions or otherwise.
#11
FlyerTalk Evangelist


Join Date: Aug 2001
Location: RSW
Programs: HHonors - Diamond; IHG - Diamond; Marriott Bonvoy - Platinum
Posts: 14,284
I rarely place orders over the phone, but don't recall having been asked for the CVV in those cases. Since much of the fraud has to do with snapping pics of both sides of the card by servers, they should have the CVV to enter to obtain their loot.
#12
FlyerTalk Evangelist


Join Date: Jan 2014
Location: San Diego, CA
Programs: GE, Marriott Platinum
Posts: 15,742
That type of fraud doesn't seem to be that common or else the card networks probably would have pushed back harder on the whole taking cards away at restaurants thing.
#13
Flyertalk Posting Legend Moderator: Credit Card Programs, American Express, Capital One, Chase, Citi, Diners Club, Eco Travel, Signatures




Join Date: Jun 2003
Location: Miami, Mpls & London
Programs: AA, IHG & Marriott Platinum; DL & HH Gold
Posts: 51,855
I sometimes pay medical bills by phone because there is no online option, and these days they do ask for the CVV.
I also booked a BA ticket that required a telephone booking for the return. The agent mentioned that their system would hold the CVV for one week, and they would have to contact me to get it again if the ticket were not reissued in that time. This also happened last year, they contacted me repeatedly for the CVV, but did not manage to take payment until we checked in at LHR
I also booked a BA ticket that required a telephone booking for the return. The agent mentioned that their system would hold the CVV for one week, and they would have to contact me to get it again if the ticket were not reissued in that time. This also happened last year, they contacted me repeatedly for the CVV, but did not manage to take payment until we checked in at LHR
Last edited by mia; Dec 16, 2017 at 6:43 am


