You have to wait for the investigation to complete to receive compensation if you’re hit by fraud on a debit card. Credit cards don’t share that issue. If you’re poor or living paycheck-to-paycheck, debit cards are potentially a risk to your livelihood.
As someone who has been hit with fraud on a debit card and a credit card, the process to recover money from fraud on a credit card is so much easier and more hassle-free than a debit card.
The big difference is that with a debit card, it's your money that is hit by fraud. The debit card is basically just a proxy. You have to go file a police report. You have to hope the bank will give you the money back.
When the credit card gets hit, it's the credit card company's money and they will seemingly chase the fraud to the ends of the earth to recover it.
This depends heavily on the country you’re in. In the UK banks are required to refund you within a single business day if they don’t have any evidence that the customer isn’t trying to defraud the bank themselves.
They try to squirm out of that of course. But in general getting your money back isn’t too tricky even with a debit card.
Oh yeah. I should definitely caveat: I am in the US. I think banks here are required to cap your loss to $50 USD if you report unauthorized fraud within two business days. But still, the onus is on you. Meanwhile, virtually all credit cards in the US offer $0 liability protection. Which means at most you pay nothing.
2 business days is a lot more strict than credit cards, which at the very least would not blink an eye at 2 weeks.
Er what?
You don’t even pay for the fraudulent credit card transactions in the first place! There’s no money for them to return!
> The big difference is that with a debit card, it's your money that is hit by fraud.
I kind of disagree. I think what's happened is the bank would prefer you to believe that. Imagine I kept my money at the bank, and deposited $10000 with the teller. Immediately afterward a robber follows in and steals that $10000 from the teller. Does the bank say "oh no Mr. TheChao! A robber stole your $10000!". I mean, no? The bank got robbed. Just because the bank's digital security is more tied one-to-one to dollars and its easier for a robber to steal from "my till" doesn't mean it was me who was robbed. It's the bank's job to stop that.
This was also the subject of a brief sketch on That Mitchell and Webb Look:
> Bank official: Sit down Mr. Coleman, I'm, I'm afraid I've got bad news about your account.
> Mr. Coleman: Really?
> Bank official: I'm very sorry to say that someone's stolen your identity.
> Mr. Coleman: Oh God! Do you know who it was?
> Bank official: Well -- they said they were you, but uh--
> Mr. Coleman: Of course. So, um, what happened?
> Bank official: Well it was on the bank website, someone logged in, and committed identity theft electronically.
> Mr. Coleman: I see. Did they take anything else?
> Bank official: Uh, no.
> Mr. Coleman: Oh good, so all the money's still there...
> Bank official: What?
> Mr. Coleman: Well: it's just my identity that's gone -- none of your money?
> Bank official: Well no, they did -- they, they, emptied your account. It's identity theft, they took all the money.
> Mr. Coleman: That sounds more like a bank robbery.
[continued] -- see https://www.youtube.com/watch?v=CS9ptA3Ya9E for the full skit.
Just as a handy thing to chuckle over and then link others to, if the topic comes up again.
Eh when you deposit money with a teller, it gets added to your account, which is in physical terms probably just a big storage and a database who has how much.
But in the case of debit card, the card ties the money to your account. It is actually that.
It's as if someone would steal from a personal safe at the bank.
Except that you have strong statutory rights and commercial agreements between your bank and the card networks making it very likely that you’ll be made whole.
> likely
> will
Which is why the credit card is still the better option. Especially given that the max liability on a credit card is always $50 if caught within the first 60 days, while the max liability on a debit card is $50 only if caught within the first two days, then up to $500 if reported after up to 60 days.
They may post a provisional credit when I report the fraud on the debit card or they can wait up to 10 days to do so. With a credit card, no money has left my account and I get the final say on whether I want to part ways with my real money. If the bank really wants to fuck me over by saying it's not fraud, I get to make it as unprofitable as possible for them, which includes forcing them to sue me if they really want the money.
I will take the ding to my credit report and a lawsuit over actual money taken directly out of my account any day.
This is where you find out which banks suck, and which do not. I will say that while USAA is a long ways from perfect, when someone swiped my wife's debit card and took $5000 from our checking account, they put that money back within a day while the investigation was pending. No police report necessary, either.
I don’t thing Regulation E allows banks to require a police report before processing an unauthorized payment, nor can they outright refuse to do so.
Practically, Reg E is essentially as strong as Reg Z.
> Practically, Reg E is essentially as strong as Reg Z.
Not even practically, but that's beside the point. The point is that with regulation E, I am potentially put in a position where I have to work to get my money back; I have to file a lawsuit against the bank if I think their determination is wrong (and that's assuming there isn't an arbitration provision, but many people don't realize they agreed to binding arbitration).
With regulation Z, the bank has to work to get their money back. They have to file the lawsuit against me if they really want the money. And it's $0 liability under many circumstances mandated through the regulation, not just a revocable promise from the bank.
The underlying problem is that the whole concept of cards is insane. Basically, you go around telling every shopkeeper the code for your safe, and ask them to take however much cash you owe them out of the safe.
Sane ways to organize payments:
- Merchant gives you a bill-id. You input it into your bank website - where you see the bill amount being charged. You accept, and bank pays merchant.
- You give merchant your card number (that's the only information - no expiry, no ccv, no name). A notification pops up on your bank website asking if you want to pay what the merchant is requesting. You accept.
- You go to your bank website and obtain a random number, either allowing a single transaction or a recurring transaction. You give the merchant the number. After merchant charges it, no other merchant can charge the same number.
This would also solve a major annoyance I have with card payments, which is no way to link a particular purchase back to a transaction.
With checks, you write a check and can write down the check number with a note about what the payment was for. When the payment posts, the check number is part of the transaction. With a card payment, they charge your card and, sometimes days later, there's a pre-authorization with some obscure transaction description. So many scary transaction descriptions that make me think "wait is this fraud".
With this method, the approval flow would also allow people to add a blurb for what the transaction is for.
> You go to your bank website and obtain a random number, either allowing a single transaction or a recurring transaction. You give the merchant the number. After merchant charges it, no other merchant can charge the same number.
That's basically how Blik works in Poland. With the exception being that the number is random 6 digits randomly generated when you open the app, that is active for ~2 minutes. So you don't deal with the issue of very long and error prone numbers to copy.
Much better way to pay online.
https://en.wikipedia.org/wiki/Blik
Cards have supported strong, positive cardholder authentication at the POS (chip and PIN) and online (3DS) since the 90s.
It’s entirely the US credit card industry and its regulating bodies’ fault that it has made neither mandatory in the way that e.g. the EU did, and is in fact fighting any attempt to do so tooth and nail (please think of the conversion rate!!)
Can you guys still write a check at the supermarket checkout? No pin credit cards are small potatoes next to personal checks in terms of weirdness. But I wish we had that trust culture everywhere.
I've always had fraudulent debit charges automatically reverted. Typically the bank's fraud detection disables the card and you clear up the matter on the phone. Or they call you to verify if a suspicious charge outside your profile was actually yours. The banks aren't required to do this but they can choose to provide this level of service.
the cc fraud (and fraud protection) is THE main selling point of Visa/MC credit cards.
it is that different treatment of debit/cc fraud that pushes people towards high fee cc.
it is cc fraud protection that justifies high cc processing fees.
without cc fraud there is no need in visa/mc duopoly.
Eh... I guess YMMV, at least for a low amount it took me literally an afternoon, I just froze my card, walked to the bank, explained the issue, and they refunded me on the spot (also switched out the card for a new one). They said technically it could be clawed back after investigation but they never did.
Weird take, credit card debt is much more of a risk to that demographic than debit cards ever will be