The authentication requirement is a bit of a hassle (CC network should bear the fraud risk), but the part that seems absurd to me is that the integration is done as an iFrame. That means ordinary users are now trained to enter their banking credentials on random websites—the opposite of what they learned in years of phishing education.
Does anyone understand how it came to this?
As far as getting users accustomed to entering data in iframes, the average user won’t be able to tell what part of a site is iframe or not. And idk how much of a difference it makes if you can tell - any random site you enter your data could potentially steal it.