Edit2: Sounds new in the US. This is not supposed to be a bragging/snarky comment. Just genuinely surprised as innovation usually come the other way around, from US to Brazil. So Congrats on the launch! Good job, sounds tough to launch it not being a Bank!
Not really - Paypal was doing it via their browser toolbar ages ago, back when toolbars were still a thing. They stopped offering this functionality back in 2009, I think. That said, it's not particularly common at US banks despite being a horrifically useful feature (Bank of America has it, but I'm not aware of anyone else).
I'm excited that I can hop on and use Privacy but it seems like it's more of a feature than a product.
Virtual citi cards are nice in theory, but the web app to make them it pretty cumbersome to use, and the desktop app to do it just feels super icky. They also have short expiration limits, so it's not great to use for subscriptions where you ideally set and forget.
Edit: the web app for Citi was also a flash app last time I checked (few months ago). That plus them not supporting 2FA for every login makes me not use it.
Bank of America offers this as "ShopSafe", but it's buried on the BoA credit card account page and it's a flash app. It's also not available from the BoA mobile app, at least not last I looked.
I came here to say this. It's really a great service, but it is not available for the iPhone (Flash) so I always have to use it on my laptop (trade one problem for another) which is kind of a pain. But I do use it all the time and highly recommended especially to avoid having to cancel subscriptions.
People are surprised when I point it at them because it is almost as if BoA does not want you to use it. Check the right side bar towards the bottom.
Ya I've been thinking about reverse-engineering it to write something like the privacy extension for a while... nice to see someone else put in the work!
Yeah, the TWiET podcast made a big deal recently about how chips are finally making their way to their cards. I couldn't help but laugh. IIRC, Norway had those since the late 80s. And in Australia, Paypass/Paywave is near ubiquitous now. I think the US is way behind in their banking infrastructure.
I used to work at the largest merchant acquirer in the US and it's funny to see people claim these features just now making it to the US were signs of innovation lacking within the US. However, the reason these features were necessary outside the US is because the risk model was more severe outside the US; there was no need to implement them here. I have a presentation from Mastercard somewhere from 2006 that showed the dates for mandatory chip&PIN around the world the didn't include the US b/c we didn't need it. At the same time, I had flip phones on my desk from Motorola and Samsung with NFC integrated.
Edit to add: This is not a tech issue, it is politics and the like.
Weird, because most of the data I can find shows that the US has one of the highest rates credit card fraud in the developed world. Australia being very far down the list typically, and yet we got chip & pin and Paywave/Paypass well before most other places
Before the internet, and before its pervasiveness (~2010), all, then most, of the credit card transactions were 'card-present.' The US still leads in fraud prevention for 'card-present' transactions. The US was optimized for these transactions, so the internet has been a bit of a hassle and or opportunity (e.g. paypal).
Paywave/Paypass is about convenience, rather than security. It is less secure than chip and pin.
Fraud was a lower risk to credit card companies in America because [1] they were better at detecting and preventing fraudulent transactions, and were better at passing on the costs of fraud to retailers and consumers.
My understanding (I wasn't in the fraud department) was that the US historicaly had better connectivity (leased ISDN lines), and was doing fraud detection in the 'cloud' (i.e. soft real-time). Most other countries had to rely on connectivity-free authorization and ISO 7816 was a better fit there (smartcards with onboard storage and authentication methods).
High level question about virtual cards and the implication of their implementation: 16 digits doesn't seem like a very high number of available cards, especially since at least two of those numbers are reserved (checksum and IIN number). At some point numbers are going to be recycled, right? Or am I massively underestimating the # of credit cards out in the world? It seems like if a large # of people get a new # for every transaction that it would use up the available namespace pretty quickly.
You only need the PAN to charge the card, and many banks will gladly accept charges on expired cards even if provided with an expiration date in the past.
I used to make new virtual numbers from Wamu for each online transaction, setting $ and time limits. Only later did I read that those "one-time" numbers could be charged more than once and the expiration dates didn't matter. That's why I skip this extra useless step these days.
That still gets you the ability to figure out who leaked your card number, and presumably a way to manually revoke the number without hosing the whole card.
Yeah, I was a user. It was called Private Payments and went back at least as far as 2000.
Here's an interesting article from 2000 [1], declaring it basically unnecessary because cards were safe in transit. Some of the quotes and rationale are hilarious. Definitely from the pre-breach-of-the-month era.
A few credit card companies offered this in the mid-2000s (Providian and Citi, possibly more), but it seems to have fallen out of favor in the intervening time. I liked to have it as an option, so I'm glad it's making a comeback.
Since no one has mentioned it, American Express had Private Payments from 2000-2004, which generated one-time credit card numbers that the merchant could charge for up to a month.
In Portugal we have had this service for many years and it works regardless of the bank (https://www.mbnet.pt in portuguese). Most people I know always generate one of these cards for online shopping, it's safer and easier to control.
That's indeed true! Although you still have the limitation of only being able to generate virtual credit cards of the same type of your "parent/real" credit card. For instance, with a Maestro/Mastercard you cannot generate virtual VISA's.
Disposable and merchant-specific card numbers have been around for decades but never gained much traction. Probably because the meager benefits do not overcome the poor UX.
I think it may be related with more difficulties on tracking what you're shopping (likes) and more hassle on setting them up for every thing you buy (considering disposable virtual credit cards), which more likely will keep you away from buying instinctively and is not the desired outcome.
Here(in portuguese): https://www.itau.com.br/cartoes/cartao-virtual/
Or am I missing something?
Edit: They launched it in 2002: http://exame2.com.br/mobile/tecnologia/noticias/itau-agora-t...
Edit2: Sounds new in the US. This is not supposed to be a bragging/snarky comment. Just genuinely surprised as innovation usually come the other way around, from US to Brazil. So Congrats on the launch! Good job, sounds tough to launch it not being a Bank!