I don't think its too tin-foily to assume that there are non-technical reasons why the credit card networks don't want one-time-use credit card numbers, and that PayPal would care more about its relationships with those networks than it does for a product that didn't immediately take off.
This is how the innovater's dilemma works. Big entrenched company, too scared to make changes that will jeopardize existing partnerships and businesses, upended by a nimbler competitor that doesn't have to care about those things. It'll happen!
The one-time PAN patents (and the merchant or tx-bound PAN) patents of the late '90s are largely expired at this point, so it is open art now. I see more and more companies starting to implement it more broadly (Citi, BofA, CapitalOne). It's nifty because you don't have the hefty "Verified by Visa" type integration (nor any of that SET stuff also from the 90s).
The last time I logged into my PayPal pre-paid debit card portal, they still had this functionality (sans Browser plug-in), but I don't recall seeing it on PayPal proper for a while...
The last time I talked to the MC folks (granted, it has been a long while), they actually thought it (OTP) was a nifty client-side (plus closed-loop) technique and was a nice (and orthogonal) add-on to the types of security that they are pushing vis-a-vis tokenization on the merchant side...
Yeah but in PayPal's case, they were all MasterCard numbers. And keep in mind that since one of the primary uses was to be able to Pay secretly with PayPal on a site that doesn't support it, the number would have to validate through the merchant's existing CC system. MasterCard was clearly on board with the process.
> MasterCard was clearly on board with the process.
They might have been when it started, but clearly something changed. If it was desirable, the moment PayPal decided not to continue, MasterCard would have started looking for alternatives. Since they didn't (and haven't), its pretty reasonable to assume they decided intentionally not to pursue it.
The two other functioning alternatives listed in this thread, getfinal.com and privacy.com, both Visa. Kinda says it all there.
My mastercard had the same feature sometime along the way that they advertised strongly to me on the website. I think I might have used it once, but it was too much of a hassle to log in to my account, generate the number, go back to the website that I was purchasing from, etc.
This is how the innovater's dilemma works. Big entrenched company, too scared to make changes that will jeopardize existing partnerships and businesses, upended by a nimbler competitor that doesn't have to care about those things. It'll happen!