संसृति कुमारी ([info]zoeimogen) wrote,
@ 2009-01-30 11:12:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Current mood: annoyed

McDonalds
So, this morning I was running late and thought I'd get a McDonalds on the way into work. Despite the diet, I barely ate yesterday so I figured this was justified. Besides, I like their coffee and I'd not had time for my usual cup that morning.

I had no cash on me and the cashpoint nearby I usually use wasn't working for some reason, so I thought I'd pay by card. Mistake. It seems that a couple of low-value transactions on a couple of US-based websites, Ancestry (Checking out my grandparents details for Irish Passport application) and Intermail (tikitag, which the uknotters reading this will recognise...) had caused my card to be flagged as suspect, and they wanted to talk to me next time I used it.

The next time I tried to use my card was on a site that didn't support 3D Secure so coudln't pass on a message to me, which triggered a further flag which meant I coudln't get into online banking this morning. Finally, we get back to McDonalds. The flag on the card was for them to talk to me, but McDonalds don't do that at all and their automated system not only refused the request but did not pass on the message for me to ring them.

Result: Card cancelled as nicked. Didn't work in online banking, nor to dial up to telephone banking.

Moral: Don't use debug cards for micropayments in places like McDonalds. I'm not sure they're really supposed to just dump potentially difficult transactions without passing on messages but it seems they do. I'd have thought in this day and age it woudln't be too hard to display a message on the PIN pad from the bank - perhaps it did, I wasn't paying attention the first time and the staff member just pulled the card out and reinserted it without asking me.




(5 comments) - (Post a new comment)


[info]suzyscottdotcom
2009-01-30 11:42 am UTC (link)
Surprised you didn't scream at them...

GIVE ME BACK MY McCARD!!!

(Reply to this)


[info]darkwaterfairy
2009-01-30 01:13 pm UTC (link)
totally not surprised. :(
see my entry from a fortnight ago about how hard it is to report a dodgy acting website. They surely had a phone number or email on record for u so could have contacted u but choose not to.

Self-service Merchant bankers, the lot of them

(Reply to this)


[info]pungoose
2009-01-30 10:59 pm UTC (link)
3D secure is an attempt to look like phishing, and can foxtrot oscar.

Dear banks: Kindly stop fucking around, and give us RSA-style tags already.

(Reply to this) (Thread)


[info]zoeimogen
2009-03-01 06:50 pm UTC (link)
(Yes, yes, I know it's been a while - playing catchup on email)

Apparently 3D secure is capable of doing challenge-response using a C&P card reader of the style used for online banking and this may happen in the near future.

Of course, as has been pointed out, this is far from perfect for the end users of such systems. For one, the Bad Guys now have a convenient way of figuring out if you're giving the right PIN when they mug you for your card.

(Reply to this) (Parent)


[info]pungoose
2009-01-30 11:04 pm UTC (link)
lol! "debug card"! It took me ages to work out what that meant. Damn autofingers... (well, they have their uses) (Yes! Those!)

(Reply to this)


(5 comments) - (Post a new comment)

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…