Comment 1 for bug 632890

Revision history for this message
Jan Claeys (janc) wrote :

I just discovered this issue too...

My card does have an expiration date, but no "from" date and no 3 digits on the backside. There is no need for that sort of poor security anyway, as the Maestro transaction authentication (as used in Belgium, at least) involves a challenge/response based system that requires the customer to have the card ready _and_ know the pin code of the card, which obviously is *WAY* more secure than any info that's printed on the card.

It's also important to implement this correctly because Maestro seems to be the main implementor of debit cards in the context of SEPA: http://en.wikipedia.org/wiki/Single_Euro_Payments_Area
In theory (in practice it might take somewhat longer ;) ) everybody with a debit card (which is almost everybody with a bank account) in the SEPA should be able to use it for online payments in the EU and most other European countries by the end of this year. Provided that web shops implement this correctly... ;)

In Belgium and several other countries, most people don't have a credit card, so this is important if you want to
sell more music over here...