<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Serguei Alleko Blog &#187; Electronic Payments</title>
	<atom:link href="http://alleko.com/category/electronic-payments/feed/" rel="self" type="application/rss+xml" />
	<link>http://alleko.com</link>
	<description>Blog about work and fun</description>
	<lastBuildDate>Mon, 02 May 2011 17:05:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>News in e-payment security</title>
		<link>http://alleko.com/2011/03/16/news-in-e-payment-security/</link>
		<comments>http://alleko.com/2011/03/16/news-in-e-payment-security/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 16:00:49 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[e-payment]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=635</guid>
		<description><![CDATA[I&#8217;ve written many times about how insecure the credit cards are. They&#8217;re stolen by thousands and often merchants are those, who have to pay the price. But credit cards are still the e-payment number one in the world. So, what are the current (2011) trends in making the electronic payments safer? Hardening the credit card [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2011%2F03%2F16%2Fnews-in-e-payment-security%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2011%2F03%2F16%2Fnews-in-e-payment-security%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I&#8217;ve written many times about how insecure the credit cards are. They&#8217;re stolen by thousands and often merchants are those, who have to pay the price. But credit cards are still the e-payment number one in the world.</p>
<p>So, what are the current (2011) trends in making the electronic payments safer?</p>
<ol>
<li> Hardening the credit card transactions security.
<ul>
<li>Some intelligent controls for the merchant self. Payment Service Providers help with dosens of different smart filters, like IP-address, credit cards issue data, etc.</li>
<li>Help from PSPs. They keep black/white lists of credit card numbers and trying to react on stolen cards faster then issuing organizations</li>
<li>Help from Credit Card issuing banks &#8211; <a href="http://en.wikipedia.org/wiki/3-D_Secure">3D secure</a>. This helps merchants to shift their financial responsibilities a little</li>
</ul>
</li>
<li>Alternative payments, like <a href="http://en.wikipedia.org/wiki/IDEAL">iDeal </a>or mobile payments. They&#8217;re much more secure technically. Additionaly credit cards are SO much simplier to steal that thiefs don&#8217;t care about cracking cryptho on Maestro-style devices yet.</li>
<li>A combination of a credit card and a e-banking cryptho-authenticator, check this one out <a href="http://scobleizer.com/2011/02/23/credit-card-of-the-future/">http://scobleizer.com/2011/02/23/credit-card-of-the-future/</a> Nice one from France!</li>
</ol>
<p>&nbsp;</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/03/16/news-in-e-payment-security/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/03/16/news-in-e-payment-security/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2011/03/16/news-in-e-payment-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How fast the credit card payments really are?</title>
		<link>http://alleko.com/2011/01/05/how-fast-the-credit-card-payments-really-are-2/</link>
		<comments>http://alleko.com/2011/01/05/how-fast-the-credit-card-payments-really-are-2/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 09:57:13 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[Ogone]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=604</guid>
		<description><![CDATA[It looks like the credit card payments in the Internet are immediate. You pay and the money are coming from your credit card to the bank account of the e-shop. Well, it&#8217;s only partially true. The credit card &#8220;cloud&#8221; promises that the money will come directly, but in reality this process is not that fast. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2011%2F01%2F05%2Fhow-fast-the-credit-card-payments-really-are-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2011%2F01%2F05%2Fhow-fast-the-credit-card-payments-really-are-2%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>It looks like the credit card payments in the Internet are immediate. You pay and the money are coming from your credit card to the bank account of the e-shop. Well, it&#8217;s only partially true. The credit card &#8220;cloud&#8221; promises that the money will come directly, but in reality this process is not that fast.</p>
<p>Let&#8217;s see how the process looks like from prospective of e-merchant, using <a href="http://www.ogone.com/">Ogone </a>as PSP.</p>
<p><strong> 4.jan.2011 around 14.05</strong><br />
- a customer buys something in the e-shop.<br />
- via Ogone service the credit card information is send to an acquirer and the acquirer &#8220;<a href="http://en.wikipedia.org/wiki/Authorization_hold">authorizes</a>&#8221; the payment. However Ogone doesn&#8217;t send the actual command to transfer the money</p>
<p><strong>5.jan. 2011 after midnight</strong></p>
<p>- scripts from Ogone are connecting to the acquirers and start the transactions from the day before:</p>
<p style="text-align: center;"><a href="http://alleko.com/wp-content/authorization.png"><img class="aligncenter size-full wp-image-621" style="border: 1px solid black;" title="authorization" src="http://alleko.com/wp-content/authorization.png" alt="" width="349" height="81" /></a></p>
<p style="text-align: left;">As you can see the actual payment happened 1 day later.</p>
<p style="text-align: left;"><strong>10.jan.2011</strong></p>
<p style="text-align: left;">According to our contract with the acquirer the money are coming to our account once per week every Monday. So the real money from this transaction will be transferred to the bank account of the e-shop only on 10 January. So much for the &#8220;direct Internet payments&#8221;</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/01/05/how-fast-the-credit-card-payments-really-are-2/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/01/05/how-fast-the-credit-card-payments-really-are-2/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2011/01/05/how-fast-the-credit-card-payments-really-are-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chronopay problems or who is your psp?</title>
		<link>http://alleko.com/2011/01/03/chronopay-problems-or-who-is-your-psp/</link>
		<comments>http://alleko.com/2011/01/03/chronopay-problems-or-who-is-your-psp/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 07:41:48 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[Chronopay]]></category>
		<category><![CDATA[PSP]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=588</guid>
		<description><![CDATA[Several days ago a Russian-dutch Payment Service Provider Chronopay had some security issues. It is not 100% clear what happened, but a number of credit cards were compromised. Apparently they&#8217;ve missed payment on their domain name, which allowed criminals to create a fake payment page and collect some credit card numbers. May be it&#8217;s true, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2011%2F01%2F03%2Fchronopay-problems-or-who-is-your-psp%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2011%2F01%2F03%2Fchronopay-problems-or-who-is-your-psp%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Several days ago a Russian-dutch Payment Service Provider <a href="http://www.chronopay.com/">Chronopay </a><a href="http://krebsonsecurity.com/2010/12/russian-e-payment-giant-chronopay-hacked/">had some security issues</a>.</p>
<p>It is not 100% clear what happened, but a number of credit cards were compromised. Apparently they&#8217;ve missed payment on their domain name, which allowed criminals to create a fake payment page and collect some credit card numbers.</p>
<p>May be it&#8217;s true, may be not, but I wanted to focus on the situation from prospective of a e-shop customer. What did Chronopay problem could mean for an average credit card user?</p>
<p>First of all, who is the Chronopay and why do they have the credit card information anyway?  People buy products from e-shops, not from Chronopay. It&#8217;s actually a bit ironic, but the role of PSP is to manage the operation and security of the credit card operations for the e-stores, so the latter could focus on selling their products &#8211; books, CDs, TVs, etc.</p>
<p>If you bought a CD in an e-shop, in most cases the e-shop had never seen your credit card number, it was managed only by Chronopay (or other PSP).</p>
<p>So, when you heard the news about one of the PSP loosing some credit card numbers, how to find out if you should block your card at your bank? How do you know, if your card was managed by Chronopay?</p>
<p>Well, this depend on the e-shops, you&#8217;ve used your credit card with. And any of them could have two different contracts with their PSPs:</p>
<ul>
<li><strong>&#8220;umbrella contract&#8221;</strong>, where the PSP is managing everything for a e-shop and transferring the real money just once per month to the merchant bank account. In this situation &#8220;Chronopay&#8221; should be clearly visible on the credit card statement.</li>
<li><strong>&#8220;normal contract&#8221;</strong>, suitable for advanced e-stores,  where the PSP is providing the technology and all the financial operations are performed directly with e-shop&#8217;s account by it&#8217;s acquirer. In this situation only the name of e-shop will be visible on the credit card statement. You should go to the e-shop itself and try to find any information about which PSP do they use. In most cases it&#8217;s clearly stated and even promoted.</li>
</ul>
<p>Have a save payments and good year 2011!</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/01/03/chronopay-problems-or-who-is-your-psp/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2011/01/03/chronopay-problems-or-who-is-your-psp/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2011/01/03/chronopay-problems-or-who-is-your-psp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Luxembourg as online offshore zone</title>
		<link>http://alleko.com/2010/11/02/luxembourg-as-oline-offshore-zone/</link>
		<comments>http://alleko.com/2010/11/02/luxembourg-as-oline-offshore-zone/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 17:44:18 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[luxembourg]]></category>
		<category><![CDATA[VAT]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=577</guid>
		<description><![CDATA[A lot of Internet companies, dealing in Europe are trying to reduce their VAT. Opening a company in Luxembourg is a good choice, they have just 15% and they&#8217;re respectable European country, nothing like strange islands, which could be covered by occasional tide wave. However, you have to consider a lot of additional problems, such set-up [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2010%2F11%2F02%2Fluxembourg-as-oline-offshore-zone%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2010%2F11%2F02%2Fluxembourg-as-oline-offshore-zone%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A lot of Internet companies, dealing in Europe are trying to reduce their <a href="http://en.wikipedia.org/wiki/European_Union_Value_Added_Tax">VAT</a>. Opening a company in Luxembourg is a good choice, they have just 15% and they&#8217;re respectable European country, nothing like strange islands, which could be covered by occasional tide wave.</p>
<p>However, you have to consider a lot of additional problems, such set-up could create:</p>
<ul>
<li>Lux bureaucracy is very slow. If you think you can start up your e-shop in a couple of months, think again.</li>
<li><a href="http://en.wikipedia.org/wiki/Acquirer">Credit Card aquireres</a> don&#8217;t like Lux start-ups much, they could ask huge amount of bank guaranty in case you default and all your credit card payments have to be charged back.</li>
<li> <a href="http://en.wikipedia.org/wiki/Payment_service_provider">PSPs </a>don&#8217;t like Lux companies either, although they don&#8217;t care much, because they don&#8217;t have any financial risk. But they may also ask for additional guarantee for payments for their services. In countries like Germany or Netherlands you could just give your bank account, and this will be enough.</li>
<li>You still have to somehow support European local methods, like <a href="http://en.wikipedia.org/wiki/IDEAL">iDeal </a>or <a href="http://en.wikipedia.org/wiki/Elektronisches_Lastschriftverfahren">ELV</a>. It&#8217;s possible by opening accounts in all those countries, but it takes time and money.</li>
</ul>
<p>Of course, if you&#8217;re making millions with your shop 6% of additional turnover is very important.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/11/02/luxembourg-as-oline-offshore-zone/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/11/02/luxembourg-as-oline-offshore-zone/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2010/11/02/luxembourg-as-oline-offshore-zone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ABN AMRO Saldo for iPhone</title>
		<link>http://alleko.com/2010/05/18/abn-amro-saldo-for-iphone/</link>
		<comments>http://alleko.com/2010/05/18/abn-amro-saldo-for-iphone/#comments</comments>
		<pubDate>Tue, 18 May 2010 11:22:37 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[ABN-Amro]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[e-banking]]></category>
		<category><![CDATA[Saldo for iPhone]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=323</guid>
		<description><![CDATA[One of the advantages of modern electronic banking is a very high security. Its provided by a very strong 2 factor authentication. You must have a small computer (authenticator) in order to generate cryptically strong (supposedly) random passwords. (pic is from abnamro.nl) I&#8217;ve described about e-commerce application of this authentication in my post about IDeal [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2010%2F05%2F18%2Fabn-amro-saldo-for-iphone%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2010%2F05%2F18%2Fabn-amro-saldo-for-iphone%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>One of the advantages of modern electronic banking is a very high security. Its provided by a very strong 2 factor authentication. You must have a small computer (authenticator) in order to generate cryptically strong (supposedly) random passwords.</p>
<p style="text-align: center;"><a href="http://alleko.com/wp-content/edentifier2.jpg"><img class="aligncenter size-full wp-image-324" title="edentifier2" src="http://alleko.com/wp-content/edentifier2.jpg" alt="" width="210" height="170" /></a><em>(pic is from abnamro.nl)</em></p>
<p>I&#8217;ve described about e-commerce application of this authentication in my post about <a href="http://alleko.com/2009/01/12/ideal-online-payment-method/">IDeal payment system</a>.</p>
<p>It doesn&#8217;t matter if your computer got compromised and somebody stole your passwords. They&#8217;re not valid anymore. And you can not crack the authenticator device remotely, it&#8217;s not connected to the Internet. One only cold steal it and try to guess your PIN. One of the reasons why computer viruses could target e-banking software is that old banks don&#8217;t use this type of authentication.</p>
<p>However just today I&#8217;ve downloaded an iPhone app called <a href="https://www.abnamro.nl/nl/prive/slimbankieren/iphonesaldo/introductie.html?pos=hpban_iphonesaldo_wk13">Saldo voor de iPhone</a> from ABN-Amro. This small app allows you to check the balance on your accounts without supplying the random passwords every time!</p>
<p>Surely, it&#8217;s not an open book and you jave to supply a pin-code every time you start it, but this pin-code is checked only locally!  And you can check your balance without using the authenticator. According to the web-site of ABN-AMRO the app is build according to the security standards of the bank. But they don&#8217;t say which ones!</p>
<p>So the hackers just have to hack the iPhone app and get access to your balance. Hopefully it doesn&#8217;t allow to send money without 2-level authentication.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/05/18/abn-amro-saldo-for-iphone/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/05/18/abn-amro-saldo-for-iphone/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2010/05/18/abn-amro-saldo-for-iphone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Certification</title>
		<link>http://alleko.com/2010/05/03/pci-dss-certification/</link>
		<comments>http://alleko.com/2010/05/03/pci-dss-certification/#comments</comments>
		<pubDate>Mon, 03 May 2010 11:02:19 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Ogone]]></category>
		<category><![CDATA[PCI DSS Certification]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=260</guid>
		<description><![CDATA[Just got an email from our credit card acquirer with suggestion to pass PCI DSS Certification. This certification ensures that companies handling the credit card numbers safely. Yes, you do need a special certification to handle very sensitive 20-digit numbers. And yes, it shows again how unsecure the credit cards really are. The cerfitication could [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2010%2F05%2F03%2Fpci-dss-certification%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2010%2F05%2F03%2Fpci-dss-certification%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Just got an email from our credit card acquirer with suggestion to pass <a href="http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard">PCI DSS Certification</a>. This certification ensures that companies handling the credit card numbers safely.</p>
<p>Yes, you do need a special certification to handle very sensitive 20-digit numbers. And yes, it shows again how unsecure the credit cards really are.</p>
<p>The cerfitication could be quete costly, 1-rst level means hundred thousands euros per year spend on security.</p>
<p>Fortunately I don&#8217;t have to do it, sins our e-shop is not handling any real credit card information. Everything is managed by our Payment Service Provider <a href="http://www.ogone.com/">Ogone</a>. This means that during the processing of an order we have to send client from the URL of our e-shop to some URL of Ogone. Ogone provide nice opportunity to keep the same look-and-feel as our e-shop, so most of the clients don&#8217;t notice anything.</p>
<p>This is also a disadvantage: clients who do notice the change of URL during payment for our products don&#8217;t like it. Because it may look like a phishing attempt. And this is one of the most basic precautions for online shoppers &#8211; check your URL for phishing! Well, at least all our URLs are SSL-protected with valid certificates.</p>
<p>I&#8217;m not sure what could be better solution for this URL changing problem. May be &#8211; becoming DSS compliant after all. Ogone provides technical API for those, who are compliant. So may be, one day.</p>
<p>Today I&#8217;ve just send the form with all required information to the acquirer. Let&#8217;s wait for their reply.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/05/03/pci-dss-certification/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2010/05/03/pci-dss-certification/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2010/05/03/pci-dss-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why my credit card payment was rejected</title>
		<link>http://alleko.com/2009/09/25/why-my-credit-card-payment-was-rejected/</link>
		<comments>http://alleko.com/2009/09/25/why-my-credit-card-payment-was-rejected/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 17:00:30 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[credit card fraude]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[filtration]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=202</guid>
		<description><![CDATA[A lot of people are asking this questions: I&#8217;ve used this credit card many times successfully , but why I can not pay in this particular e-shop? Your payment could be filtered at 2 stages: 1. Credit Card Issuers Mastercard or Visa are checking the following data from your credit card: credit card number expiration date Name [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2009%2F09%2F25%2Fwhy-my-credit-card-payment-was-rejected%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2009%2F09%2F25%2Fwhy-my-credit-card-payment-was-rejected%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A lot of people are asking this questions: I&#8217;ve used this credit card many times successfully , but why I can not pay in this particular e-shop?</p>
<p>Your payment could be filtered at 2 stages:</p>
<p><strong>1. Credit Card Issuers</strong></p>
<p>Mastercard or Visa are checking the following data from your credit card:</p>
<ul>
<li>credit card number</li>
<li>expiration date</li>
<li>Name on the credit card</li>
<li>CSV-code</li>
<li>whether you have enough credit for your purchase</li>
</ul>
<p>Normally this should be enough, I&#8217;m authenticated and I&#8217;ve authorized this payment. A credit card can not give you more. But the amount of credit card fraud  in the Inthernet is so enormously big, so almost all the e-shops make additional checks.</p>
<p><strong>2. E-shop itself</strong></p>
<p>E-shop has much more data, then just your credit card information. Your registration data, your IP-address, your purchases, etc. They can control a number of different things:</p>
<ul>
<li>is your IP is in the same country as your reported home address?</li>
<li>is your IP in the same country as your credit card has been issued in?</li>
<li>do you order too many products, than normal user (or strange combinations of products. For example most of the vendors provide discounts on big amount of software licenses. So any user, who&#8217;s spending a lot of money on full price licenses in the shop is suspicious)?</li>
<li>have you bought something in this e-shop before</li>
<li>is your credit card number, IP, email address, phone, name or address are marked as &#8220;blacklisted&#8221; buy your Payment Service Provider?</li>
</ul>
<p>and many more things could be checked automatically when you buy something in a e-shop.</p>
<p>Then it&#8217;s up to e-shop and you to try to have business together. For example last week <a href="http://bol.com">bol.com</a> (the biggest media-site in Netherlands) has rejected my payment. Most probably because I&#8217;ve done in from Belgium with Belgian credit card, but specified delivery address in Netherlands. Bol.com asked to send prove of my identity (scan of the passport) for the clarification. In this situation I&#8217;ve just bought what I wanted (new <a href="http://www.sonystyle.com/webapp/wcs/stores/servlet/ProductDisplay?catalogId=10551&amp;storeId=10151&amp;langId=-1&amp;productId=8198552921665921180">Sony eBook Reader PRS-600</a>) from another e-shop and they&#8217;ve lost me.</p>
<p>But I don&#8217;t blame them of course. As I also have the same problems in my e-shop, I understand: it&#8217;s nothing personal, just business.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/09/25/why-my-credit-card-payment-was-rejected/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/09/25/why-my-credit-card-payment-was-rejected/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2009/09/25/why-my-credit-card-payment-was-rejected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New strategy against credit card fraude</title>
		<link>http://alleko.com/2009/09/19/new-strategy-against-credit-card-fraude/</link>
		<comments>http://alleko.com/2009/09/19/new-strategy-against-credit-card-fraude/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 09:02:28 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=195</guid>
		<description><![CDATA[After some extensive screening of credit card information in our e-shop I still could see from time to time people buying licenses in big amounts (which usually indicates fraud). A week ago I&#8217;ve decided to use proactive tactics. For every order, which looks like fraud, I&#8217;m sending an email: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Dear Sir/Madame, Unfortunately we’ve found [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2009%2F09%2F19%2Fnew-strategy-against-credit-card-fraude%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2009%2F09%2F19%2Fnew-strategy-against-credit-card-fraude%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>After some extensive screening of credit card information in our e-shop I still could see from time to time people buying licenses in big amounts (which usually indicates fraud).</p>
<p>A week ago I&#8217;ve decided to use proactive tactics. For every order, which looks like fraud, I&#8217;m sending an email:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Dear Sir/Madame,</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Unfortunately we’ve found problems with your order of Kaspersky products. There is a possibility that credit card, used to pay for the purchase, was stolen or misused.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">We’ve blocked your Kaspersky licenses and send information about this purchase to anti-fraud department of the credit card issuer.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">If you are the owner of this credit card, please make contact with us as soon as possible.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Sorry for inconvenience!</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Best regards,</div>
<p><em>Dear Sir/Madame,</em></p>
<p><em>Unfortunately we’ve found problems with your order of Kaspersky products. There is a possibility that credit card, used to pay for the purchase, was stolen or misused.</em></p>
<p><em>We’ve blocked your Kaspersky licenses and send information about this purchase to anti-fraud department of the credit card issuer.</em></p>
<p><em>If you are the owner of this credit card, please make contact with us as soon as possible.</em></p>
<p><em>Sorry for inconvenience!</em></p>
<p><em>Best regards,</em></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>This actually helped (at least for some time). I don&#8217;t see any big cases of fraud payments sins then. Now it&#8217;s just a matter of following this daily procedure.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/09/19/new-strategy-against-credit-card-fraude/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/09/19/new-strategy-against-credit-card-fraude/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2009/09/19/new-strategy-against-credit-card-fraude/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fraud with credit cards again</title>
		<link>http://alleko.com/2009/07/20/fraud-with-credit-cards-again/</link>
		<comments>http://alleko.com/2009/07/20/fraud-with-credit-cards-again/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 14:56:45 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[credit card fraude]]></category>
		<category><![CDATA[iDEAL]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=102</guid>
		<description><![CDATA[We&#8217;ve got again a number of products, bought via our e-store with stolen credit cards. Sins we&#8217;re sending our products &#8211; activation codes electronically per email, customers can supply bogus delivery address an still receive their code via a temporary gmail account. At this moment we have the following limits on our e-store: no credit [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2009%2F07%2F20%2Ffraud-with-credit-cards-again%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2009%2F07%2F20%2Ffraud-with-credit-cards-again%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>We&#8217;ve got again a number of products, bought via our e-store with stolen credit cards.</p>
<p>Sins we&#8217;re sending our products &#8211; activation codes electronically per email, customers can supply bogus delivery address an still receive their code via a temporary gmail account.</p>
<p>At this moment we have the following limits on our e-store:</p>
<ul>
<li>no credit cards from countries except Europa are allowed (our e-shop officially sells only in Benelux)</li>
<li>IP of the user must belong to the same country as the card issues (sorry, problems for Dutch guys, who went on &#8220;caravans&#8221; to Spain and decided to buy antivirus there)</li>
<li>There are strict limits on number of purchases and amounts</li>
</ul>
<p>And still they&#8217;re coming through! Some Dutch credit cards were stolen and used from the Netherlands (or via a Dutch proxy)</p>
<p>We&#8217;re sending all the money back, of course, we don&#8217;t want to be a <a href="http://alleko.com/2009/01/03/good-and-bad-in-credit-card-processing/">bad e-shop</a>. And when I was 3 days too late to do it, I had a visit from a fraud controller form our MasterCard/Visa acquirer. Better to be neat next time.</p>
<p>And of course, we don&#8217;t have any protection and virtually no fraude with <a href="http://alleko.com/2009/01/12/ideal-online-payment-method/">iDEAL</a></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/07/20/fraud-with-credit-cards-again/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/07/20/fraud-with-credit-cards-again/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2009/07/20/fraud-with-credit-cards-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intra-European payment and VAT</title>
		<link>http://alleko.com/2009/03/09/intra-european-payment-and-vat/</link>
		<comments>http://alleko.com/2009/03/09/intra-european-payment-and-vat/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 16:54:08 +0000</pubDate>
		<dc:creator>Serguei Alleko</dc:creator>
				<category><![CDATA[eCommerce]]></category>
		<category><![CDATA[Electronic Payments]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[Intra-european payments]]></category>
		<category><![CDATA[payments]]></category>

		<guid isPermaLink="false">http://alleko.com/?p=77</guid>
		<description><![CDATA[In every European country, if you buy something, you have to pay Value Added Tax (or VAT) It ranges per country from 15 till 25% per country. If you&#8217;re a private person, you just have to pay it, no matter what. If you&#8217;re a company or self-employed, you can deduct this tax via complex procedure with [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Falleko.com%2F2009%2F03%2F09%2Fintra-european-payment-and-vat%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falleko.com%2F2009%2F03%2F09%2Fintra-european-payment-and-vat%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In every European country, if you buy something, you have to pay <a href="http://en.wikipedia.org/wiki/Value_added_tax">Value Added Tax (or VAT)</a> It ranges per country <a href="http://en.wikipedia.org/wiki/European_Union_Value_Added_Tax#VAT_rates">from 15 till 25% per country</a>.</p>
<ul>
<li>If you&#8217;re a private person, you just have to pay it, no matter what.</li>
<li>If you&#8217;re a company or self-employed, you can deduct this tax via complex procedure with your accountant.</li>
</ul>
<p>This procedure becomes even more complex if your company is located in one European country and you&#8217;re buying something in another. In this situation you can ask from a shop, if they can sell it to you without VAT at all. </p>
<p>It is possible, but not all the shops provide this service. You can not just come to a supermarket, show your VAT-id from neighbor country and ask for non-VAT payment. It has to be a special &#8220;B2B&#8221; shop.</p>
<p>If you have a e-store, it&#8217;s also not very easy:</p>
<ol>
<li>You need to ask a VAT-id from all your customer and check it via official European Commission VAT-check web-service, called<a href="http://ec.europa.eu/taxation_customs/taxation/vat/traders/vat_number/index_en.htm"> VIES (VAT Information Exchange System)</a>. Finally something useful from European Commission! You can also <a href="http://ec.europa.eu/taxation_customs/vies/vieshome.do?selectedLanguage=EN">check a VAT manually here</a>.</li>
<li>Then your shop need to provide order without VAT tax and your CRM must understand it</li>
<li>(worst part) When your accountant has to provide a tax declaration for VAT, you need to represent every transaction separately, including information about client&#8217;s VAT. A lot of e-shops don&#8217;t provide this service because of difficulties of tax declaration</li>
</ol>
<p> </p>
<p>In general, if you&#8217;re located in one EU-country and want to go abroad, check it with your accountant, may be it&#8217;s not such a good idea.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/03/09/intra-european-payment-and-vat/" target="_blank"><img src="http://alleko.com/wp-content/plugins/add-to-facebook-plugin/facebook_share_icon.gif" alt="Share on Facebook" title="Share on Facebook" /></a><a href="http://www.facebook.com/share.php?u=http://alleko.com/2009/03/09/intra-european-payment-and-vat/" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://alleko.com/2009/03/09/intra-european-payment-and-vat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

