Credit card madness.

Nov 08, 2004 33 Replies

The need to make doubly sure that the information you are accessing isn't compromised and isn't freely available to people who shouldn't be accessing it.

tim

In message , Chris Blunt writes

Cost, security and reliability.

If the internet is cheap and secure enough to allow me to log on to my bank or credit card account from anywhere in the world 24/7 and move thousand of pounds around, why is it not cheap and secure enough to allow a merchant to obtain a credit card authorisation from the card issuer 24/7?

Chris

In message , Chris Blunt writes

Why not just think abut it a bit more? You are describing a one to one link with only a tiny proportion of a banks clients on line at any one time.

This bears no comparison with a pan world network with 100s of millions of card holders, using many millions of retail outlets and connected to thousands of card issuers, the last two connections being on line continuously for much of the day. And the level of security would need to be very much higher.

You're basically saying "because we don't have the technology". You might have been right 15 or even 10 years ago, but not any longer. I'd say it's perfectly feasible for the larger merchants to be on line

24/7 and for the smaller ones who aren't to have instant phone access to someone who is.

Without a hint of irony, Ronald Raygun astounded uk.finance on 11 Nov 2004 by announcing:

A lot of them are. However, it's would be highly impractical to have a connection directly to each issuer. Who is going to inform every merchant whenever a new card range is allocated? Why not just inform them when a card

*scheme* is allocated and leave it up to the acquirer to forward the requests via VISA/Mastercard or whoever else?

The issue isn't that the merchant doesn't contact the issuer, it's whether they contact their acquirer and whether the acquirer contacts the issuer before giving the authorisation.

Without a hint of irony, Jonathan Bryce astounded uk.finance on 09 Nov 2004 by announcing:

The floor limit isn't 'generally' anything. It's entirely down to the merchant's agreement with their acquirer, and the merchant usually has a different limit per card scheme.

Range? Scheme? Merchants don't need to be informed of anything.

Every card has a unique number, just like every internet machine has a unique IP address. Merchants and bankers can be on-line to an authorisation network containing routers which shuffle authorisation requests around in real time to reach the correct issuer based on (probably) the first few digits of the card number.

It's really not rocket science. You simply need to get the bandwidth provision right to keep queue lengths below a few hundred milliseconds.

Without a hint of irony, Ronald Raygun astounded uk.finance on 11 Nov 2004 by announcing:

And just who is going to set this up worldwide? Why can't this 'authorisation network' that they're online to be their acquirer? Oh, because that's the way it works now, sorry.

It wouldn't take much. Similar infrastructure is already in place.

The acquirer isn't a network, it's just a node in the network. The acquirer could be one of the routers, though, and pass requests up the chain. Surely to go all the way to the issuer is more reliable because the decision coming back will be more definitive (certainly in terms of credit limits being breached) than if a decision is made en route somewhere based on some kind of risk assessment heuristic and random passing-along of only some of the requests in case the up-line is "too busy".

Its not just a one to one link. I can and do connect instantly to dozens of other systems all over the world every day. And there are hundreds of millions of other people just like me who also connect to millions of other systems every day. Sure, security would need to be ensured, but the technology to do that has been around for very many years already.

Chris

Without a hint of irony, Jonathan Bryce astounded uk.finance on 11 Nov 2004 by announcing:

What's their business case? What's the business case they put to the banks?

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required