Page is a not externally linkable
jamesa - 9:00 pm on Dec 20, 2002 (gmt 0)
Along with the transfer of liability away from the merchant, this is great news. :)
The good thing about this is that the PIN verification is not done on the merchant's server, so the merchant will never see the PIN. That was the problem with the CVC2 code: once you've given it out it's not private anymore - everybody and their brother will have it eventually. So it looks like a big improvement. Though, recurring billing will be a nightmare I'm sure.