We decided to take out last month to review our 3D-Authentication service and how best to keep you safe. We found some interesting ways to extend this security mechanism to guarantee further that no unauthorized requests via the API requiring a debit on your Redbiller wallet happen under our watch.
So here you go
1. We now notify you via email when a 3D-Authentication verification fails. It is an indication that your API private key has been compromised and someone somewhere is trying to gain access to your wallet.
This notification comes as a way to help you to be on guard and take necessary actions into safeguarding your keys even more.
While we guarantee that no debits resulting from failed 3D-Authentication verifications can occur on your wallet, we strongly recommend that you regenerate your keys, as they can still be used to carry out other non-debit-related actions on your account, such as creating Virtual Bank Accounts.
2. To ensure that no unauthorized changes on your 3D-Authentication URL occur on your account even in the presence of a valid wallet PIN, we have disabled the Update 3D-Authentication URL feature on the Dashboard.
This is, however, exclusive to merchants who are yet to set their 3D-Authentication URL for the first time. Kindly contact [email protected] to request an update.
3. We have introduced a second layer to our 3D-Authentication service. It requires that you save the transaction reference number in the pointer you created in your hook upon initiating a debt-related request, let's say a bank transfer.
This means that while Redbiller checks for the existence of the pointer in your 3D-Authentication URL path, she will also confirm if its content is a 100% match with the reference number that was pushed along with your request.
This upgrade also requires that you (existing merchant) copy your 3D-Authentication Hook from your Dashboard at Business > Manager, and replace your private key with it in your 3D-Authentication URL.
Kindly contact [email protected] to request that this feature be enabled on your account.