tiggity

And 3DSecure (in its VBV incarnation) is a bad thing (IMHO) as it encourages users to accept javascript / content from sa different site thsn the one they started their purchase on.

And if someone has "forgotten" their password, then all you need is card details (that you could have acquired illegitimately) to assign a new VBV password.

It g9ives the illusion of security but encourages bad security practice by users.

I avoid VBV sites whenever possible

