Sure, the CC data can easily be stolen even now but assuming square gets popular, consumers then will have to "trust one more device" in addition to the card-readers used by merchants, any other place where you swipe the card, the waiter, etc etc.
And more so because its much easier to write rouge apps or malware-apps for smartphones than to hack the dedicated card readers. In case of a malware-app, the danger is not just limited to one merchant.
It seems to me that the real question raised by verifone is not being given enough concern.
Why can't the square card encrypt the CC data ?? with a private key that only square-app can make sense of?