[12783] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Failings of credit cards

daemon@ATHENA.MIT.EDU (Nick Szabo)
Sat May 28 20:28:44 1994

From: szabo@netcom.com (Nick Szabo)
To: com-priv@psi.com
Date: Sat, 28 May 1994 13:50:01 -0700 (PDT)


Today, the dominant form of payment over the Internet is the credit
card.  When we send our credit card numbers out over the net,
we take our chances.  The folks with the backbone sniffers
need not confine themselves to passwords.  It's pretty easy to
pick out a credit card number from a data stream.  Furthermore,
do we know what spool files contain temporary copies of our
e-mail, and how many sysadmins across the planet have access
to them?  Hopefully the day will come when we'll get rid of crypto 
restrictions and be able to encrypt these sorts of things
without legal hassle.

But here's a more important issue: how do we trust the vendor on
the other end with our numbers?  Sure, if it's a well-established
company we can probably trust them.  But what if it's some
garage band selling their jam sessions via a web page?  What
if it's some business in some foreign country?  Do we know
if their local laws will protect us?   

If, one day, your credit card number gets posted in a 
Usenet group from Finland, and you've given it out to 
dozens of businesses, who do we blame?

Furtheremore, if credit cards are the only form of net.payment we lose 
the option to shop in privacy.  Do we want to have our names 
permanently linked to politically or socially controversial services 
because we once shopped for them over the net?  Do we
want to see the day when all kinds of intimate info starts
getting leaked onto the net in a big way, the cash-only backlash 
sets in, and our credit card customer base dries up overnight?
That day is coming.

The vendor also has to trust the number.  Many small
vendors are not in a position to check numbers in real time.
Even if they can check the numbers they can't truly 
authenticate the identity of the person at the other 
end over the Internet without a prohibitively complex
authentication system.  As it stands now, if Joe Cracker
wants to order net.goods on my credit, in many
cases he need merely get my card number and forge
mail to look like it came from me.  Credit card
fraud is already bad enough (over 3% of credit
card transaction volume and growing); the card companies 
will be quite loathe to serve Internet-based ordering if 
it starts happening here.

Finally, the credit card system, with its delayed
billing assumes billing dispute resolution methods.  
If a customer disputes a bill, the credit card company
should wipe it off, and the vendor should have good enough
records and authentication that he can prove the transaction
took place.  Again, this assumes jurisdictional uniformity,
accounting standards, and high per transaction costs, a
situation light-years away from somebody running a web
site on an network that crosses hundreds of jurisdictions
and dispenses files at $.50 a pop.   

This kind of multinational small business may be by far and
away the most lucrative market for Internet-based commerce.  Most 
other kinds of business can already be accomplished quite effectively 
via snail-mail, voice phone, proprietary networks, or non-financial 
Internet transaction.  Today, multinational business is 
synonymous with big business.  With cheap travel and
communications, that is changing.  With jurisdiction independent
transactions for small business over the Internet, it can change 
even more radically.  If the proportion of small to large businesses 
comes to be the same on a multinational scale as it is on a national
scale, this implies several trillions dollars worth of 
annual market growth over the coming decade(s) for multinational
small business: perhaps the hottest growth market of them all.  The 
primary tool needed to tap this market is a new kind of transaction system 
that is jurisdiction independent.

There are a wide variety of these net-based businesses that Visa, 
Mastercard & Co.  wouldn't touch with a ten-foot pole; but it 
would be perfectly reasonable to deal with them on a cash or 
other debit basis.   For example, individuals could make a 
few bucks in their spare time by running web pages, if
there was a seamless debit billing system.  Credit cards
just won't work for that.  If the Internet is to be a friendly 
place for international small business, we're going to have to 
do much better than the insecure, jurisdiction dependent,
high transaction cost credit card.

What about some of the net.transaction systems that are in
the works; how close do they come to the ideal of jurisdiction
independent transaction?  The CommerceNet system is fundamentally 
based around the credit card and other methods of payment heavily
dependent on uniform jurisdiction.  It authenticates vendors against
a public key hierarchy, which is prone to single-point
failure at the top of the hierarchy, where of course 
CommerceNet has placed itself.  No customer 
authentication is provided, as this would be prohibitively
complex, so the threat of credit card spoofing remains.
DigiCash the Netherlands is supposed to come out
with a pure-software digital cash product Real
Soon Now, and other such products are in the works.  Meanwhile, 
Pr0duct Cypher's "Magic Money" provides a nice public-domain
prototype for a digital cash system that Internet vendors can
integrate into their web servers.  The software digital
cash systems provide the potential for true privacy-preserving, 
low transaction cost, very low fraud transaction systems.

-- 
Nick Szabo					 szabo@netcom.com
"If you want to hit the moon tomorrow, aim for London today."



home help back first fref pref prev next nref lref last post