Same thing with “pay with your face” they tried in China. They all are susceptible to replay attacks. It is garbage!
The only secure way to authorize actions is to have a device in your possession which you unlock with your password and/or biometrics — and use THAT device to sign interactive challenges or ZK-SNARKS.
The device could stores keys in a secure enclave, but regardless, the keys should never leave the device. The ability to export private keys (as with ethereum and bitcoin wallets) is insecure, too.
Look how 1password does it: local key plus master password. Far better than LastPass (master password only).
Also you should have notifications whenever a new device authenticates, or when you are trying to establish new recurring payments at a great rate than you would allow otherwise. Then you need to confirm from other devices.
That is the scheme that works universally and the further you depart from that, the more ridiculous hacks you get.
That's such a naive take on security. Reminds me of "salt shaker vulnerability": https://www.linkedin.com/pulse/hacker-restaurant-alexander-s...
Today, almost any time you use your credit card online in the US, you are susceptible to replay attack. Even PCI-compliant merchant can simply save your payment method for future uses (neither SCA, nor VISA's VAU is being enforced).
What exactly is the attack vector for face payments, if they are not used for P2P payments, only happen in public places with plenty of cameras, and are capped?
Just because it's "possible", doesn't mean it introduces risks that are not acceptable. Sure, you can risk prison time and get a bag of groceries for free. But stealing groceries old-fashioned way is less risky.
ANY biometrics you use to pay can be easily replayed. Whatever function you derive from these biometrics can be executed when you’re not there.
Not to mention that the biometrics themselves can be emulated by a device (eg voice recording) as you see in sci-movies like Minority Report (fake eyes) or that star trek clip.
Sure, for smaller amounts and using copious amounts of “seller beware” chargeback protections, the system can work. And those chargebacks can be good for many things, so that is how our financial system works now.
But if you want to secure thing that are valuable, like elections and many others, then what I described is the optimal solution.
Does this kind of devices really comes in biometric versions ? As someone else mention, unlocking an ATM (or anything else) with a device and your fingerprint is very vulnerable to “steal device and cut finger”.
but, "..which you unlock with your password and/or biometrics"?
unlocking with biometrics is actually the problem, regardless of where the unlocking takes place.
relying on a third-party device that you can't even verify is in the custody of its user as "the only secure way to authorize actions" is highly problematic for similar reasons.
and confirming "from other devices" rapidly turns into a user nightmare.
the irony in all this is that lengthy, strong, non-reused passwords are actually pretty secure, and they don't require any specialized technology or rely on possessing a device that you just forgot on the airplane seat pocket and is now winging its way toward another country.
Perhaps to unlock even more valuable transactions, you’d want to bring an external key, like a Yubikey or Ledger Nano wallet etc.
Lengthy passwords that you enter are not very secure. Anyone can capture your keystrokes, look over your shoulder with a camera, or even look at heat signatures on your phone after you left to the bathroom and locked it: https://www.zdnet.com/google-amp/article/this-thermal-attack...
It may be a shock but that movie will actually turn 41 this summer.
It seems the author has shown that a replicant can trick a bank.