<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Safer Online Transactions in India</title>
	<atom:link href="http://www.pankajbatra.com/india/safer-credit-debit-card-online-transaction-india-rbi/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pankajbatra.com/india/safer-credit-debit-card-online-transaction-india-rbi/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=safer-credit-debit-card-online-transaction-india-rbi</link>
	<description>Information &#62;&#62; Knowledge &#62;&#62; Wisdom</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:25:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Hoor Banu</title>
		<link>http://www.pankajbatra.com/india/safer-credit-debit-card-online-transaction-india-rbi/comment-page-1/#comment-3805</link>
		<dc:creator>Hoor Banu</dc:creator>
		<pubDate>Tue, 27 Apr 2010 05:05:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.pankajbatra.com/?p=320#comment-3805</guid>
		<description>Hi... Could you please talk about the current scenario of ecommerce in India. I would like to know more about it as i am doing a project on online marketing</description>
		<content:encoded><![CDATA[<p><!-- google_ad_section_start -->Hi&#8230; Could you please talk about the current scenario of ecommerce in India. I would like to know more about it as i am doing a project on online marketing<!-- google_ad_section_end --></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Payment Security Expert</title>
		<link>http://www.pankajbatra.com/india/safer-credit-debit-card-online-transaction-india-rbi/comment-page-1/#comment-1465</link>
		<dc:creator>Payment Security Expert</dc:creator>
		<pubDate>Wed, 22 Jul 2009 08:31:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.pankajbatra.com/?p=320#comment-1465</guid>
		<description>RBI never sponsored or stated specific systems such as Verified by Visa or Mastercard UCAF/SPA in its directive. 

Before, the entire banking industry in India goes on this bandwagon, it is best to simply learn about the experience of cardholders and online merchants as it concerns these two systems. Just google ” verified by visa 2009 ” or go to this link : http://www.boingboing.net/2009/03/28/verified-by-visa-bri.html. 

VBV or UCAF/SPA static passwords can be easily phished. Once phished and used by fraudsters, it then makes it very difficult (not impossible) for the legitimate cardholder to dispute a fraudulent online payment made with his VBV or UCAF/SPA credentials. 

On the other hand, fraudsters can easily collaborate and share each other’s VBV or UCAF/SPA credentials and then dispute the charges with the issuing banks. The issuing Banks can never prove that the cardholder’s static VBV or UCAF/SPA’s credentials were not phished or compromised. 

It surprises me that India, the world’s technical resource, would copy the errors made by Banks elsewhere in the world that tried introducing VBV or UCAF/SPA. It is relatively simple for anyone to do a google search on Verified by VISA and realize that it has not been successful in other parts of the world. At least banks in other parts of the world and online merchants were not mandated to implement these systems. 

Be wary of mandated systems. A good security system never needs to be mandated.</description>
		<content:encoded><![CDATA[<p><!-- google_ad_section_start -->RBI never sponsored or stated specific systems such as Verified by Visa or Mastercard UCAF/SPA in its directive. </p>
<p>Before, the entire banking industry in India goes on this bandwagon, it is best to simply learn about the experience of cardholders and online merchants as it concerns these two systems. Just google ” verified by visa 2009 ” or go to this link : <a target="_blank" href="http://www.boingboing.net/2009/03/28/verified-by-visa-bri.html" rel="nofollow">http://www.boingboing.net/2009/03/28/verified-by-visa-bri.html</a>. </p>
<p>VBV or UCAF/SPA static passwords can be easily phished. Once phished and used by fraudsters, it then makes it very difficult (not impossible) for the legitimate cardholder to dispute a fraudulent online payment made with his VBV or UCAF/SPA credentials. </p>
<p>On the other hand, fraudsters can easily collaborate and share each other’s VBV or UCAF/SPA credentials and then dispute the charges with the issuing banks. The issuing Banks can never prove that the cardholder’s static VBV or UCAF/SPA’s credentials were not phished or compromised. </p>
<p>It surprises me that India, the world’s technical resource, would copy the errors made by Banks elsewhere in the world that tried introducing VBV or UCAF/SPA. It is relatively simple for anyone to do a google search on Verified by VISA and realize that it has not been successful in other parts of the world. At least banks in other parts of the world and online merchants were not mandated to implement these systems. </p>
<p>Be wary of mandated systems. A good security system never needs to be mandated.<!-- google_ad_section_end --></p>
]]></content:encoded>
	</item>
</channel>
</rss>
