Mobile Transactions To Become More Secure From 1 Jan 2011 OnwardsIn 2009, RBI had mandated additional security for online credit/debit card transactions in India.

  • Make Telecom Talk My Trusted Source
  • Source of Google
  • Source of Google

This was achieved through the introduction of 3D Secure password that was required to be registered for every credit/debit card to enable its use for online payments on ecommerce websites.

This meant that in addition to the 16-digit card number, 4 digit expiry date and 3-digit CVV number, the card holders were required to enter the additional 3d Secure password to authorize their online transactions.

Users could easily register for this 3D Secure password on the website of their card issuing bank or on the websites of MasterCard and VISA.

While this additional password went a long way in ensuring safe & secure e-commerce transactions, mobile transactions continued to be susceptible to credit card frauds and identity thefts.

This is because, for authorizing any mobile transaction, all you required was to enter the 16-digit card number, the expiry date and the cvv number. Since all three details are printed on the card itself, any person who gets physical access to your card could note down these details and use it later to make a payment through IVR, WAP or On-Device application. Fortunately, all this is set to change from 1 January 2011.

In 2010, RBI gave the mandate to all banks to provide 3D Security for mobile transactions by 1 Jan 2011. This was a big challenge for multiple reasons:

*The additional password for mobile transactions had to be numeric because mobile channels like IVR do not support alpha-numeric inputs

*For online transactions, the users are redirected from the merchant’s website to a secure webpage of the card issuing bank for entering the 3D Secure password. This kind of redirection from the merchant’s IVR to a bank-managed IVR was not practical for mobile transactions. This meant that the merchant’s IVR will need to capture the complete card details of the customer, including the 3D Secure password.