Also, we still haven't had an easy to use open tool set to make usage of Public Key Cryptography friendly to average Joes. No, GnuPG doesn't count - it's hard to use and cumbersome to configure it securely. You need to be a cryptographer or a mathematician to pick the right parameters in order to stay current and secure. Definitely not friendly even to most programmers.
Obviously, using government-controlled PKI for communications would be unwise, but there's very little risk to using government PKI for financial transactions as governments already have warrantless access to this data.
Even if you don't have to show government ID for every financial transaction, you need to show government ID (and, often, a lot more government paperwork) to open a financial account that can be used to make transactions. Your ability to move money is entirely predicated on the banks knowing who you are by linking your accounts to a tombstone government identity document.
Using PKI controlled by government to authenticate identity for transactions doesn't give government any more control over your affairs than it already has. All it does is add one more layer of authentication to the transaction process by allowing all parties involved to verify that their counterparty is the legal entity they claim to be.
Whereas the whole point of a public key system is that nobody needs your private key. So we don't need to provide individuals and businesses with a way to give their private key to somebody else. The only reason you'd give your private key to somebody else is because you want them to seamlessly impersonate you forever, so there's no need to make it any easier than, for example, giving your kidney to somebody else.
Concrete example: A WebAuthn/ U2F "Security Key" offers no way to get the Private Keys out. If you want to "steal" the credentials used to get into my GitHub your best bet is to somehow trick me into physically packaging up the USB authenticator itself and sending that to you by FedEx or something. Or maybe you could try putting a knife to my throat or something?
https://en.wikipedia.org/wiki/National_identity_cards_in_the...
I have that!
> and all you will have achieved is replicating the user experience of bitcoin.
I've never used bitcoin or any other cryptocurrency. What's the user experience like?
I would describe the first-time-user onboarding procedure as "complex enough that it's unlikely to become mainstream"
Onboarding is elaborate to avoid fraud, but not really complicated, and basically a necessity if you don't want to have to go to a bank office to manage your account and make transactions.
It is a pretty secure system I think, but government procedures make it a pain to work with.
This also makes your next sentence nonsense, anyone advocating for PKI is advocating for a technology that has trusted authorities, that's how it works, it's as though you claimed computer evangelists don't like mathematics because it uses symbol manipulation.
And then it makes your next sentence nonsense, something like Signal isn't a PKI, it has no CA role, who "Janet" is on Signal is only a matter for you and Janet. Signal also isn't purely TOFU, you can insist on manually verifying every identity just as you can on SSH.
But even though I believe the Web PKI is the only successful public PKI there are plenty of other PKIs in use that are successful in a narrower sphere, and we're already in a discussion thread about such a sphere, the global banking system.
† The Web PKI isn't strictly just a PKI for the World Wide Web, it's actually a PKI for TLS services on the Public Internet. But it exists only because Netscape built SSL, and in practice its oversight is from the major browser vendors (most notably Mozilla but of course also Microsoft, Apple and Google). There was once a good chance the only TLS client implementation you had with any useful PKI enforcement was your web browser, today it's likely other tools on your system also do this... but always relying on the Web PKI.
And also just as simple to use.
So some aspects of our products dont “need a blockchain for this” but the proliferation of standardized signing tools and size of the niche has made it extremely viable to cater to that market.
PGP had 30 years to get anywhere, and all we have are some pretty bad, cumbersome businesses releasing poorly integrated signing software on modern OS’ that even privacy advocates can barely tolerate for their email and other messages. People want to try to say the same thing about cryptocurrency over half of a decade or a whole decade but they’ll just have to wait for the Ivy league business school case studies to start coming out about the rest of us that have already figured this out for business.
Turns out changing consumer behavior isn’t hard when there are economic incentives to do so that benefit the consumer.
The thing is something that works, and works well is hard to displace. Especially when it makes money. And when you are running a business and you have to choose:
- keep making money
- update system that is making money and hope it will work and it will stop making money
What really is the sane option here?
Also one other point the credit card companies are way better option for customer over say paypal.
If you're doing it over the phone though things like public key won't really work - to be long enough would make the numbers impossible to read out reliably, let alone the calculation I would need to do with my private key to prove I own it.
It's how to authenticate and authorise an offline cardless transaction that's hard
Visa does support this scheme and I hate it when it happens. I try to use my bank password the less possible. I also believe it's a huge phishing risk as people don't look at the URL.
I personally prefer that the bank assume the current risk. It's not like it's making them bankrupt to do it right now...
For what it’s worth, in the US, chip is pretty much everywhere. Main difference is that it’s chip and signature vs chip and pin. I wish we’d switch to pins as well, but it’s not like it’s the dark ages or anything.
At least that's my understanding of it, might not be that clearcut.
Issuers will start to decline card transactions for any merchants that submit payments that haven't gone through 3DS.
https://breakdev.org/evilginx-2-next-generation-of-phishing-...
Instead banks should use WebAuthn. WebAuthn's credentials are directly bound to the DNS name. So anything that involves fooling the human like a phishing site can't work. The only site your authenticator can give the real-bank.example credentials to is... real-bank.example.
Not to mention that in order to have a decent WebAuthn experience, you need a Yubikey with NFC, which go for 30-60$ if I remember correctly. Cost of authenticators is why everyone switched away from RSA SecurID.
I don't see what a Yubikey with NFC is getting you here. For a laptop/desktop user any of the Security Key products in an appropriate USB form factor (USB C for some newer laptops otherwise USB A) would be suitable.
The high end phones are or in the case of the iPhone very shortly will be WebAuthn platform authenticators, there's nothing extra to buy. Apple released a video of the pleasant UX journey they want to promote, obviously being Apple it doesn't actually say this would work on non-Apple devices but I use it already so I know it does.
Use using credit card numbers is IMHO a very conventient way of paying with the liability for fraud being setup exactly in the right customer-friendly way.
1. I have a dongle that creates a number code when prompted. 2. My phone is set up for 2fa, again through the bank. The screen shows the same keyword as the website and I enter a pin into my phone to authorize the transaction. I can't remember if I need to use the fingerprint option on the phone or if that's just for the bank's app.
And anecdotally, I cannot speak for the entire world, but European banks have no problem disputing fraudulent charges that happen overseas.
I admit the ability to reverse a credit card payment is nice, but that mostly means that it's also a risky form of payment to accept for the merchant. They might send the goods and still have the customer challenge the transaction. And of course you still pay for this; credit card transactions are relatively expensive.
I absolutely agree that banks should not be the ones discharged with consumer protection but unreversible payments are not nearly as beneficial for consumers even if insured in some ways by the government.
I'd rather have a market protecting me with verified reviews and as close to zero costs for sellers. Not unlimited refunds that put small sellers out of business, leaving only Amazons and eBays.
Banks have developed and signed off on the ideal system; THEY are saying the system is safe, therefore THEY are responsible if something goes wrong with your payment.
Smaller specialty game webshops sadly don't.
IIRC, SOFORT used to just ask you for your banking credentials, and then it would just log in to your online banking and put a regular transfer through.
Amazon.de does a nice job by offering direct debit: you put in your IBAN and they automatically debit your account, which works across SEPA. But this seems very fraud-sensitive (you could put in anyone's IBAN), which is probably why it's not more common.
Not using a CC is just leaving insurance money on the table for no reason. I've done chargebacks after getting fraudulent goods transferred over with relatively little hassle, and would probably never managed to reverse a bank transaction.
State orgs wouldn't surprise me in the least tho.
Obviously I can block it for all transactions abroad but that doesn't seem like the best idea either.
The only working solution is to generate temporary card numbers for international transactions, but that leads to the shortage issue.
Right now all of the burden is on the credit card companies. Any fraud is their liability.
If we switch things up, and implement something like passwords or pins, WE get the liability. That’s worse than our current situation. And given how badly people get hacked or phished, all it means is that consumers lose.
Right now, those “magic little numbers” work great, and in the case of fraud, we are protected. I don’t want the situation to reverse itself and have us the first to suffer from fraud.
This the way card networks have encouraged migration to systems that support tokens and cryptograms to limit fraud.
See https://www.creditcards.com/credit-card-news/understanding-e...
For card-not-present transactions (i.e., all online credit card transactions) the liability is the merchant's. There is no recourse for a merchant who is a victim of a stolen card, the money is simply removed from their account.
Tell that to retailers who lose a gazillion dollars to fraud reversals every year.
so a system that prevents them losing a gazillion dollars is available, and they opt to instead lose the gazillion dollars. it's their fault, and they should lose that money. we don't need to tell them anything -we just need to point and laugh.
PIN in stores and 2FA online is already the norm in the developed world. It didn't exactly cause a disaster for retail.
There are a few countries where it still isn't completely rolled out (US being the most notable one) but those are now outliers.
> customers are generally happier without it
Again I think this perspectivve is US centric and not global (?).
I'm not in the US or talking about the US per se.
I as a customer want 3D Secure because I don't want to deal with fraud at all but AFAIK it's not that liked among users. And I did run into issues where the 2FA setup my bank offered took a physical letter to initialize/reset and I couldn't actually buy flight tickets I quickly needed (ended up changing cards). So I can sort of see how people can get a bit annoyed as long as 3D Secure is a bit frictionful.
Online businesses would like it if it helps them avoid fraud as well. The problem is that conversion rates drop and so only few businesses implement/enforce it unless it's the law (see EU). Given how simple it is for a customer to ask for a chargeback I don't think there's a clear winner here for using 3D Secure except for acquirers and brands. Issuers don't really gain anything either given their already strong position when handling chargebacks.
Unless you can eliminate fraud, those are basically your two choices.
Which is exactly the purpose of good security measures.
Bad or nonexistent measures and an insurance against fraud slapped on all prices is a local maximum. Good security measures which really push back the fraud and allow prices to drop the insurance premium is obviously a better local maximum.
You also don't have to eliminate 100% of fraud, just make it so rare that you can basically ignore the risk because it happening to you is as unlikely as being struck by lightning (or any other risk of life that people are comfortable to ignore due to it being vanishingly small). The classic credit card fraud with magstripes was the exact opposite of that: there was almost no credit card owner who didn't get hit by it, and while people generally didn't lose money due to reimbursement by the cc companies, they still lost time and nerves over some stupid interruption in their lives that was entirely unnecessary in the first place.
I myself had one of my cards suddenly deactivated by the bank because of alleged fraud (it wasn't even real fraud, just some heuristic going crazy over an actually intended payment). I was on a cruise ship in the Caribbean sea when it happened and all of a sudden couldn't pay my beers with my ship card anymore. Fortunately I had a second card with me that was working so I continued using that, but in order to switch my onboard expenses account over to it I had to spend some time at the customer service desk on the ship, where there was a row of passengers standing at phones, occasionally speaking with someone in various languages, but most of the time they seemed to be waiting in silence for some kind of response. It took me a few minutes of overheard conversation until I realized that these guys were in the same spot that I was, but less well prepared; they didn't have another credit card with them and thus had to call their banks back home in order to get them to unlock their accounts again.
If you don't keep your card safe, it's your liability, just like with passwords. Read the manual.
You can't do crypto with dumb block storage.
But if you have a chip you should absolutely do _something_ smarter than storing and reciting the number verbatim.
I don't believe the majority of fraud is stolen physical credit cards
Why not allow plugging the card into the computer just like a yubikey for online payments? It would be quite difficult to pull off, but credit card companies can save a lot on fraudulent transactions if it is implemented.
And as for transactions on mobile phones, most of them have NFC as well; contactless payments could work there too.
In most countries, the card number is only used for online and phone transactions. There's probably no way to do better than this without abandoning cards entirely in favor of some kind of device (or app) that has enough of a user interface to do a human-readable challenge response.
we don't use a pin, because that doesn't help with fraud. most fraud is either online, or someone at the store, who can easily skim or see your pin. online you can use 3dsecure, which has a pin.
processing a transaction doesn't mean your money's gone. you can dispute any fraud charge for 2 months. so the pin doesn't do anything. and for bank accounts, where it's debit, and your cash is immediately taken out, we've had a pin since before europe had an atm card.
I think it's just not widely known about/common usage in the US even though the infrastructure seems to be widely there.
The rest of the world reached that point around 15 years ago, including countries with high credit card use (UK, France) and high debit card use (Northern Europe).
Is this really a thing in the USA?
I feel for you guys.
Benefits?