מהו אימות לקוחות חזק?

Whenever you try to order food or add a new credit card to your account, you might be prompted to authenticate the transaction with your bank via a pop-up screen. This protocol is part of Strong Customer Authentication, a new regulation for the European Economic Area requesting banks to authenticate digital transactions. This authentication protocol adds an extra layer of security to all your online transactions.

What is Strong Customer Authentication?

Strong Customer Authentication (SCA) is a European and UK regulatory requirement to decrease fraud and secure online payments. Although the regulatory requirements are applicable to banks that issue credit cards, Uber had to build additional authentication into our checkout flow to complete transactions once Strong Customer Authentication went into effect.

SCA demands extra authentication protocol upon digital transaction with at least one of the following authentication types:

  • Something the customer knows (example: given PIN code or password)
  • Something the customer has (example: text sent to phone or hardware token)
  • Something the customer is (example: fingerprint or face recognition)

Banks will include some type of extra authentication (like the ones above) to most digital transactions in order to comply with SCA. The extra authentication is set up, controlled and approved by your Bank, not by Uber.

Banks will decline transactions that fail to be authenticated. If you would like to inform yourself about Strong Customer Authentication regulations and requirements, they are set out in the European Banking Authority and European Commission.

SCA—and the authentication protocol that comes with it—is subject to all transactions made with payment methods issued in the European Economic Area (EEA), and transactions made with them in and outside the EEA.

איך מאמתים עסקה?

הדרך הנפוצה ביותר לאמת עסקה מקוונת דורשת שלב נוסף בעת התשלום, שבו בעל הכרטיס מתבקש על ידי הבנק לספק מידע שישלים את העסקה (לדוגמה: סיסמה שניתנה לך, קוד שקיבלת בהודעת טקסט או אישור טביעת אצבע).

האם עליי לעבור את תהליך האימות בכל פעם שאני מזמין אוכל?

הפעולה תלויה בסכום ובתדירות העסקה ובמדיניות האימות של הבנק שלך. בדרך כלל, יהיה עליך לבצע אימות בכל פעם שתוסיף או תעדכן אמצעי תשלום חדש בכרטיס האשראי.

מדוע אני נדרש לאמת את העסקה שלי?

אימות העסקאות שלך (אם רלוונטי) יפחית את הסיכון להונאה או לסוגים אחרים של שימוש לרעה. בכל פעם שמתבצעת עסקה דיגיטלית, הבנק עשוי לבקש ממך לבצע אימות כדי לאשר את זכאותך. לא כל העסקאות דורשות אימות. לקבלת מידע נוסף על הצורך בתהליך אימות נוסף, עליך לפנות לבנק שלך.

איך אפשר לדעת שתהליך האימות מאובטח?

האימות יבוצע ויאובטח על ידי הבנק שלך. תהליך וסוג האימות (טקסט או טביעת אצבע, למשל) אינם בשליטתה של Uber, לכן אם יש לך שאלות הנוגעות לאבטחה, עליך ליצור קשר ישירות עם הבנק שלך.

מדוע נדרש אימות לקוחות חזק אם כבר יש אימות דו-שלבי?

כשאפשרות האימות הדו-שלבי מופעלת, יוצגו לך שני אתגרי אבטחה בכל כניסה לחשבון שלך ב-Uber.

אימות לקוחות חזק הוא פרוטוקול אימות לא אופציונלי שמטרתו לספק שכבת אבטחה נוספת, בייחוד בעסקאות הדיגיטליות שלך.

האם עליי לעבור תהליך אימות בכל פעם שאני רוצה להסדיר את יתרת הפיגורים שלי?

כן, בכל פעם שעסקה דיגיטלית חדשה מתבצעת, ייתכן שיהיה עליך לאמת אותה.

פטור מאימות לקוחות חזק

על פי תקנה זו, סוגים ספציפיים של תשלומים בסיכון נמוך עשויים להיות פטורים מאימות לקוחות חזק. לאחר ביצוע העסקה, הבנק שלך יעריך את רמת הסיכון של העסקה, ויחליט אם לאשר את הפטור או אם עדיין נדרש אימות.

תשלומים דיגיטליים אחרים, כמו PayPal,‏ Apple Pay או ארנקים דיגיטליים של Google Pay, אינם כפופים לפרוטוקולים של אימות לקוחות חזק.