The only other alternative recommended by payment gateway, would be to ask you to fax your passport. The point is, to prove that you really do process the card, not getting it through some shady sites.
Try registering an hosting account on many "managed hosting" company, you are required to fax your passport to them. I will be offended if somebody asks me to do so.
Uploading credit card image is definitely less evil than faxing your passport.
How to combat frauds with e-commerce transactions:
1. Pro-actively block Tor nodes and all hide-my-ass type of open proxy. To e-commerce merchants, tor node users are not freedom fighters, but fraudsters, every-single-one-of-them.
2. For credit card transaction, always check the return "credit card" country
3. Shopping carts need to track IP address. Fraudsters always can bounce from Brazil to UK to Italy in a single cart session.
4. Have to come up with a score system to determine fraud risk of transactions. Maxmind API seems to be helpful.
5. When in doubt, ask user to take a picture of their credit card, and upload to your site.
Try registering an hosting account on many "managed hosting" company, you are required to fax your passport to them. I will be offended if somebody asks me to do so.
Uploading credit card image is definitely less evil than faxing your passport.