Monzo Labs: Improved Card Security

It’s £30 for the trial which you don’t have to take part in. £100 will be the ‘limit’ when it rolls out to everyone.

3 Likes

That makes some sense. I used to live in Sweden, and they had online PIN verification at point of sale for years before EMV chips came along. On the other hand, terminals in Germany also support contactless & PIN, and Germany barely had card payments historically, never mind online POS PIN verification - so that one feels kinda stranger.

A couple of clarifying questions:

Surely they were already storing card PINs for ATM PIN verification? Do you mean that they didn’t need to start doing online verification at point of sale?

But regardless of whether they support it, such cards, when used in a market like the UK, will not get a contactless & PIN experience, since the terminals here don’t support it, correct?

Conversely, UK issuers can presumably support contactless & PIN in ‘supporting markets’ should they wish to, and, indeed, Monzo already does this if I understood a previous answer correctly? Or is this not really a specific configuration on the issuer side - if the terminal supports contactless & PIN, and the card supports online PIN verification, contactless & PIN will work?

1 Like

i have turned this on and am happy to test.
most UK banks already do this, and the big difference is Monzo are telling us the limits/trigger to insert card for PIN

the terminal normaly beeps twice instead of once so you know
A - its not read your card properly
B - you need to put card in for PIN.

in most cases the limit is high so customers do not get affected as after a few
small transactions you do a big one (over £30) us PIN - card counter resets and the customer is none the wiser…

Great. Anything to reduce the amount of verification would be fantastic.

They sure seem to. It’s happened to me once or twice when abroad recently in the EU.

1 Like

Ok, I want to block offline pin transactions!!! And require online pin verification everywhere.

I thought the 14th September deadline had been extended by 18 months as per:

For the UK at least…

The extension is for e-commerce transactions only.

7 Likes

This is one thing that’s pained me from the start with Monzo and other ‘new’ banks. Contactless and card transactions take longer to authorise than what I was/am used to. With my HSBC card it’s literally instant for the majority of reasonably priced transactions without an authorisation wait.

Apple/Google Pay has the authorisation delay regardless of Card bc they’re forced online too.

Super noticeable on old terminals which seem to dial to authorise.

It’s a choice we made to enable real-time notifications, otherwise we only get informed of the transaction a few days later.

We think the extra control and security customers get from notifications is worth the trade-off of slightly slower contactless transactions.

31 Likes

Ugh… this is such a PITA even with a £100 limit. It just reminds me of a solution to help legacy banks which dont have things like real time notifications to alert you to unauthorised purchases.
I know you guys dont have a choice but the thought of having to use a pin every £100 is a proper pain as we regularly use contactless just under the £30 limit.

2 Likes

Use mobile payments :grimacing: that solves that a bit

So this effectively makes contactless pointless as you’ll regularly have to enter you pin. What a complete waste of time and a great way to ruin what was a great flow.

File this in “f*ckwit solutions” like





4 Likes

Apple and Google will be the winners here

5 Likes

Just some quick initial thoughts.

I think as the trial is only £30 this could be quickly hit (especially hitting the pub after work after a long day, :joy:) and having to work out how much you’ve previously spent and whether it’s over £30 or not (not even when drunk) is going to be annoying. So initially people may say they’d rather the ‘number of times used’ limit. But real world with that limit being £100, this would be the preferred option.

This is going to be annoying and actually slow down the payment process and cause queues, although I think it’ll have less of an impact if the £100 limit was used and not the 5 transactions limit used. It is ridiculous we cannot just be asked to enter a pin for a contactless payment that’s over whichever limit as in other countries rather than have it declined and then having to start the whole process again. Is this a MasterCard thing? And why are they not being pressed to allow this or is this a regulator thing‽

Less face it, we as Brits do find the whole declined thing embarrassing as that’s just who we are so anything that can limit this would be good.

Also, how will this work when using Monzo (and other cards) with Curve as I do. Will I be dealing with 2 limits, and potentially different limit reasons, and potentially having to face 2 declines because of limits on Curve and Monzo‽ I cannot cope this early in the morning, lol. :exploding_head::exploding_head:

Firstly, first known sighting* of the interrobang on the Monzo Community. Congrats!

More substantively, I’d suspect that Curve will have to implement something similar - unless not being a bank means different rules? :thinking:

Perhaps more interestingly, the hand off between Curve and Monzo is effectively, I think, an e-commerce transaction. I wonder how SCA will affect that, and other electronic wallets, over time? :thinking: :thinking:

*now watch me get proved wrong!

7 Likes

On seeing that term, my brain first went to thinking it was some sort of Mitchell and Webb game

2 Likes

It would absolutely have to be done by exceeding a max value rather than by frequency of transactions or it will make the cards useless for public transport in places like London!

TFL isn’t included in the limit

1 Like