logoalt Hacker News

vntoktoday at 2:38 PM1 replyview on HN

Wait, am I getting it right you're talking about collecting a prospective customer's card number and CVC over the phone, and then typing it yourself in a third party system?

Then it's trivial to settle: that's the big bad PCI DSS violation mouthful, so two to three things will happen. One, the customer's bank will reimburse them as soon as they complain that they have not authorized the fraudulent transaction that appears on their account. Product being sent, received, sent back, etc has no bearing on this. Two, you will be audited, fined $xx,xxx monthly and/or perhaps even get banned from the PSP layer. Again, sending real products has no bearing in this. Three, well the customer's own bank will be in touch pretty soon with yours to "settle things", as banks don't particularly like to advance reimbursements to their clients for fraudulent transactions. Hope you weren't using your own bank as a PSP as they kept receipts of everything you were doing (they just weren't looking until now).


Replies

wpietritoday at 2:46 PM

We're not talking about fraud, we're talking about telemarketing.

The case you describe is correct for fraud, but doesn't need any new law making "void and nulls contracts made by phone". That being epolanski's proposed fix for telemarketing.

show 1 reply