• evatronic
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 months ago

    I think you’re assuming that a merchant who collects card details for payment also stores those details. They do not. The information is immediately tokenized and a 1-way authorization token is returned to the merchant. It’s literally what that little spinny circle when you click “pay” is doing. It’s reaching out to the payment network, which is in turn, reaching out to the card issuer who is proxying it to the issuing bank and asking for authorization.

    At no point is your card number retained by the merchant. If the authorization code is somehow leaked, it’s literally only good for a single transaction, and can’t be used to generate future transactions.

    • FuglyDuck@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      4 months ago

      That’s great for PoS terminals.

      Websites are a bit different; you can elect to not store your details, sure, but they’re still running it. Further; you give your card details over the phone, it’s conceivable they can then use it online.

      Especially, for example, for food delivery. It’s best practice to not give details over the phone. Originally the whole point of the secret pin thingy (those 3 or 4 digits on the back that are printed and not embossed) were meant to allow you to give the number/name/expiry for the card and have something that prevents this. But these days, most delivery services will just use their website to ‘place’ the order for you.