QUOTE(!@#$%^ @ Apr 20 2023, 10:39 AM)
so for showmanship only? better remove it entirely.

OTP verification is to determine who's liable for the txn
unifi or its gateway is actually is at the losing-side if the txn is disputed by cardholder (or a fraudster)
without enforcing OTP verification, liability sits at the unifi/gateway/acquirer -- meaning, their fault for not checking OTP!

by enforcing OTP verification, liability will be shifted from merchant/gateway/acquirer to cardholder/issuer -- meaning, cardholder has verified the txn is valid.
hence, if there is a dispute later, it would be hard to prove yourself as "innocent aka it wasnt me". this includes disclosing your OTP to 3rd party, where issuer will shift the blame to cardholder because in any cardholder agreement, it's cardholder's sole responsibility to secure the OTP, no matter the situation.
yes, kinda one-side protection by the issuing bank. they just throw cardholder under the bus.
there are many frauds happening, not just cards, but also ewallets and even FPX (eg, how on earth you share your M2U/Clicks/HLconnect login to strangers?!)

with ewallets and fpx, you need to login (thus verified) but if fraud happens
after login, you're liable.
This post has been edited by cybpsych: Apr 20 2023, 10:54 AM