Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

3DS (Three Domains Secure) means that when you try to buy something online, the merchant sends you to your bank, who then authenticates you in some way. It's usually an SMS code, which means it's technically "MFA for credit cards".

Though keep in mind that 3DS was also rolled out with a liability shift; banks sold it to merchants as "if you 3DS validate a transaction it's never fraudulent and the customer can't chargeback". Which is obviously untrue if you're using SMS 2FA, which can be defeated. Good thing most American merchants forget to turn on 3D Secure...



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: