Christian Graus wrote:
You shouldn't have to leave your site at all, unless you're using some sort of cheaper option with them.
Actually, there are systems like 3D-Secure (think Verified by Visa) that take you off the original site (albeit in an IFRAME!) to complete a transaction. This is proper expensive stuff that many banks now demand as part of the PCI compliance agreements they have with their merchants. However, you are right, it looks cheap. The problem is that Finance departments are demanding it because if they don't the merchant becomes liable for any fraud* (risk shifting by the banks). Marketing/Sales departments are resisting it because it will lose them sales (because it is anothe password to remember, and most people forget) * An agreement I've seen on a project I'm working on means that without PCI Compliance and 3D-Secure, etc. the bank can charge £25K + cost of fraud investigation + other costs to the merchant. The cost of implementing this extra security in the website is over £25K - Not a cheap solution!
Man who stand on hill with mouth open wait long time for roast duck to drop in