@Jackalnxtwhere you need to input a static password and a dynamic password before completing the payment?
There are several ways for Online Payment Solutions like for example
Two-Factor Authentication > https://authy.com/what-is-2fa/
or Dynamic Passwords - Enforcing Authentication
https://blog.bio-key.com/dynamic-password-enforcing-authentication-otp
https://www.unicreditbulbank.bg/en/individual-clients/bank-cards/additional-card-services/dynamic-password-online-payments/
But at the end this is
all Content from the PSD2 Regulation.
I know for myself that the Content behind the Links is a lot of Stuff to read about it,
and if the PSD2 Regulation is really more secure, i don't know.
But i know one thing for sure, that Online Payment Methods are getting now more "slightly" complicated.
What brings more Security between the Companies and the Customers, can be a ***** in the Butt
for the one or the other single Individual.
I would like to give you an example. I'm Buying my Credits on iStripper via SofortBanking,
and it was always the case before as well.
My Bank provided myself the TAN's for this via Paper list in the beginning, then later via SMS
and now they are ***** me to use an App for my Smartphone to fetch my TAN's.
I have no longer the ability to receive my TAN's via the regular SMS this is now over,
at least on my current Bank.
The Reason for this is, that the App is transferring the TAN
Encrypted inside the App.
It is indeed more secure but it is more or less a little bit more complicated.
Because now i need a second separated Password for the App on my Smartphone,
beside my separate Password for my Bank Account.
The Funny thing is, my Bank is still providing the TAN's via Paper list, so if i want them
i have to get them inside my Bank from an Employee there,
including an Autograph and Liability for it, but understandable of course.
If i would chose these List method again they
will delete all my Account Data from the App
(which is Understandable), and if i would go back to the App again,
i have to make the whole Registration procedure for the App again inside my Bank
with an Employee again ... At least this is what they were telling me.
So ya, it makes things more secure, but also slightly more complicated. But like i was saying
this is all Content from the PSD2 Regulation from the EU.
So you should at least follow the Wikipedia Link which i provided earlier.
And just in case someone is missleading something, Totem has nothing to do with it.
But they have to follow these Regulations,
like every other Company which is providing an Online Payment Service.