
| HTTPS padlock meaning | Data is encrypted in transit between your browser and the site |
| PCI DSS governing body | PCI Security Standards Council |
| Chargeback time limit (typical) | 60–120 days from the transaction date, depending on card network |
| 2FA second factor options | SMS code, authenticator app, hardware key, or email code |
| CVV storage rule | Merchants may not store CVV/CVC after authorization under PCI DSS (PCI DSS v4.0) |
| Common phishing delivery methods | Email (most common), SMS ("smishing"), and voice calls ("vishing") |
Why This Vocabulary Matters When You Shop Online
Online shopping involves a web of invisible security systems — encryption protocols, authentication layers, fraud-detection rules — that most shoppers never see. But when something goes wrong, understanding the vocabulary helps you act quickly and accurately. Knowing what a chargeback is before you need one, or recognizing a phishing attempt before you click, can be the difference between a resolved incident and a compromised account.
This reference covers the terms you're most likely to encounter on checkout pages, in account settings, in retailer security disclosures, and in fraud alerts from your bank. Each definition is written to be practical, not technical. For a broader look at staying safe wherever you shop, see Online Shopping Safety From Start to Checkout.
| HTTPS padlock meaning | Data is encrypted in transit between your browser and the site |
| PCI DSS governing body | PCI Security Standards Council |
| Chargeback time limit (typical) | 60–120 days from the transaction date, depending on card network |
| 2FA second factor options | SMS code, authenticator app, hardware key, or email code |
| CVV storage rule | Merchants may not store CVV/CVC after authorization under PCI DSS (PCI DSS v4.0) |
| Common phishing delivery methods | Email (most common), SMS ("smishing"), and voice calls ("vishing") |
Core Security Terms Defined
The glossary below covers the terms most relevant to recognizing secure retail environments and protecting yourself from fraud. Encryption and authentication terms appear first, followed by payment-specific concepts, then the threat types most commonly used against online shoppers.
SSL / TLS
Secure Sockets Layer (SSL) and its successor Transport Layer Security (TLS) are encryption protocols that scramble data traveling between your browser and a website's server. When a site URL begins with "https://" and shows a padlock icon, TLS is active. This means payment details and login credentials are encrypted in transit.
Two-Factor Authentication (2FA)
A login method that requires two forms of identity verification — typically your password plus a one-time code sent to your phone or generated by an authenticator app. Even if someone steals your password, 2FA blocks them from accessing your account without the second factor.
Chargeback
A forced transaction reversal initiated through your card issuer when a charge is disputed — for example, due to fraud or an item that never arrived. Chargebacks are a consumer protection mechanism, but they are subject to deadlines and documentation requirements set by your card network.
Phishing
A fraudulent attempt to steal sensitive information — passwords, card numbers, account credentials — by disguising a message or website as a trustworthy source. Phishing typically arrives via email, text, or social media and often creates false urgency to prompt quick action.
Spoofing
The act of disguising a communication's origin to appear as a legitimate entity. Email spoofing makes a message look like it came from a known retailer; website spoofing copies a real store's design to capture your login or payment details.
PCI DSS
The Payment Card Industry Data Security Standard is a set of security requirements that any business handling credit or debit card data must meet. Compliance is managed by the PCI Security Standards Council and helps ensure merchants handle card data responsibly.
Tokenization
A process where your actual card number is replaced with a randomly generated token for storage and transmission. Even if a retailer's database is breached, the token has no usable value without the system that generated it.
CVV / CVC
The Card Verification Value (or Code) is the 3- or 4-digit security number on your payment card. Merchants are generally prohibited from storing this code after a transaction under PCI DSS rules, which limits its usefulness to fraudsters who obtain stored card data.
Cookie
A small text file a website stores in your browser to remember preferences, session status, or browsing behavior. Session cookies expire when you close the browser; persistent cookies remain longer and can track behavior across visits for advertising or analytics purposes.
Man-in-the-Middle Attack
A type of cyberattack where an attacker secretly intercepts and potentially alters communication between two parties — for instance, between your device and a shopping site. Public Wi-Fi networks are a common environment for this threat, which is why HTTPS matters.
Data Breach
An incident in which unauthorized parties gain access to a system and expose personal or financial records. Breached data — including email addresses, passwords, and card numbers — frequently appears for sale on dark web marketplaces.
Virtual Card Number
A temporary, single-use card number generated by some banks or payment services for online purchases. The virtual number links to your real account but expires quickly or is limited to one merchant, reducing fraud risk if the number is later stolen.
HTTPS Is Necessary, But Not Sufficient
A padlock in the browser bar confirms your connection is encrypted — it does not confirm the site is legitimate or trustworthy. Fraudulent sites can and do obtain TLS certificates. Always verify the full domain name carefully before entering payment details. For more signals of a trustworthy store, see The Anatomy of a Trustworthy Online Retailer.
Understanding the distinction between a data breach and a phishing attack matters practically: a breach at a retailer exposes data the company already held, while phishing targets you directly to hand over data voluntarily. Your response to each should differ. If you want to understand how your payment method shapes your fraud protection rights, Debit Card vs. Credit Card for Online Purchases is a useful companion. Account security decisions — including whether to save card details with a retailer — also tie directly to how you register: Guest Checkout vs. Creating an Account walks through those choices in detail.
