The big difference is that with a debit card, it's your money that is hit by fraud. The debit card is basically just a proxy. You have to go file a police report. You have to hope the bank will give you the money back.
When the credit card gets hit, it's the credit card company's money and they will seemingly chase the fraud to the ends of the earth to recover it.
They try to squirm out of that of course. But in general getting your money back isn’t too tricky even with a debit card.
You don’t even pay for the fraudulent credit card transactions in the first place! There’s no money for them to return!
I kind of disagree. I think what's happened is the bank would prefer you to believe that. Imagine I kept my money at the bank, and deposited $10000 with the teller. Immediately afterward a robber follows in and steals that $10000 from the teller. Does the bank say "oh no Mr. TheChao! A robber stole your $10000!". I mean, no? The bank got robbed. Just because the bank's digital security is more tied one-to-one to dollars and its easier for a robber to steal from "my till" doesn't mean it was me who was robbed. It's the bank's job to stop that.
> Bank official: Sit down Mr. Coleman, I'm, I'm afraid I've got bad news about your account.
> Mr. Coleman: Really?
> Bank official: I'm very sorry to say that someone's stolen your identity.
> Mr. Coleman: Oh God! Do you know who it was?
> Bank official: Well -- they said they were you, but uh--
> Mr. Coleman: Of course. So, um, what happened?
> Bank official: Well it was on the bank website, someone logged in, and committed identity theft electronically.
> Mr. Coleman: I see. Did they take anything else?
> Bank official: Uh, no.
> Mr. Coleman: Oh good, so all the money's still there...
> Bank official: What?
> Mr. Coleman: Well: it's just my identity that's gone -- none of your money?
> Bank official: Well no, they did -- they, they, emptied your account. It's identity theft, they took all the money.
> Mr. Coleman: That sounds more like a bank robbery.
[continued] -- see https://www.youtube.com/watch?v=CS9ptA3Ya9E for the full skit.
Just as a handy thing to chuckle over and then link others to, if the topic comes up again.
But in the case of debit card, the card ties the money to your account. It is actually that.
It's as if someone would steal from a personal safe at the bank.
> will
Which is why the credit card is still the better option. Especially given that the max liability on a credit card is always $50 if caught within the first 60 days, while the max liability on a debit card is $50 only if caught within the first two days, then up to $500 if reported after up to 60 days.
They may post a provisional credit when I report the fraud on the debit card or they can wait up to 10 days to do so. With a credit card, no money has left my account and I get the final say on whether I want to part ways with my real money. If the bank really wants to fuck me over by saying it's not fraud, I get to make it as unprofitable as possible for them, which includes forcing them to sue me if they really want the money.
I will take the ding to my credit report and a lawsuit over actual money taken directly out of my account any day.
Practically, Reg E is essentially as strong as Reg Z.
Not even practically, but that's beside the point. The point is that with regulation E, I am potentially put in a position where I have to work to get my money back; I have to file a lawsuit against the bank if I think their determination is wrong (and that's assuming there isn't an arbitration provision, but many people don't realize they agreed to binding arbitration).
With regulation Z, the bank has to work to get their money back. They have to file the lawsuit against me if they really want the money. And it's $0 liability under many circumstances mandated through the regulation, not just a revocable promise from the bank.
Sane ways to organize payments:
- Merchant gives you a bill-id. You input it into your bank website - where you see the bill amount being charged. You accept, and bank pays merchant.
- You give merchant your card number (that's the only information - no expiry, no ccv, no name). A notification pops up on your bank website asking if you want to pay what the merchant is requesting. You accept.
- You go to your bank website and obtain a random number, either allowing a single transaction or a recurring transaction. You give the merchant the number. After merchant charges it, no other merchant can charge the same number.
With checks, you write a check and can write down the check number with a note about what the payment was for. When the payment posts, the check number is part of the transaction. With a card payment, they charge your card and, sometimes days later, there's a pre-authorization with some obscure transaction description. So many scary transaction descriptions that make me think "wait is this fraud".
With this method, the approval flow would also allow people to add a blurb for what the transaction is for.
That's basically how Blik works in Poland. With the exception being that the number is random 6 digits randomly generated when you open the app, that is active for ~2 minutes. So you don't deal with the issue of very long and error prone numbers to copy.
Much better way to pay online.
It’s entirely the US credit card industry and its regulating bodies’ fault that it has made neither mandatory in the way that e.g. the EU did, and is in fact fighting any attempt to do so tooth and nail (please think of the conversion rate!!)
it is that different treatment of debit/cc fraud that pushes people towards high fee cc.
it is cc fraud protection that justifies high cc processing fees.
without cc fraud there is no need in visa/mc duopoly.