In the payment processing sphere, we are stuck with a duopoly that charges insane fees for something that was very complex and labor intensive 50 years ago. But today - if we could start from scratch - the entire payment volume of EU can be processed on a well provisioned computing rack with a software written in less than a year by a small team. It could be offered by ECB as a free service, with strong privacy guarantees written in EU law.
Entire modes of fraud, such as credit card cloning, would cease to exist. Online payments - seamless, safe, and instantaneous, just scan a QR code.
But we cannot start from scratch because the incumbent is good enough and the rent they extract from each member of society is small enough to not motivate them to initiate a switch, even if the aggregate rent is a staggering amount that would be recouped in days of the new system going online.
Someone can just stick a QR code on top of the office one. [1]
[1]: https://www.straitstimes.com/tech/can-i-trust-this-qr-code-c...
* find physical card or virtual in an app
* copy paste or insert "secret" numbers, and trust the website won't save them, because they are static
* insert a bunch of personal data which the merchant has no real reason to know, but that is used for "fraud detection" because they don't trust you are the real owner of the "secret" static password
* go back to your phone and get the SMS/3dsecure validation prompt, because it turns out your bank also doesn't trust the secrecy of the "secret" numbers they issued you
* finally, pray to the cave gods the transaction has gone trough the complex duct tape and bubble gum contraption, is not flagged for review or reversed by the various intermediaries etc.
It's all a baroque mess, multiple layers of cruft accumulated over the decades. To compare, even a crypto transaction is much smoother and simpler, navigate to checkout, scan the QR code with your wallet app, press pay and you are done. And that's not to praise crypto, any solution designed from scratch for the age of the internet will be much better.Also, the payment system should not be confused with the banking system. Complete control over the payment system would give the attacker the ability to deny payments or make fraudulent ones, but would not, for example, allow the attacker access to accounts not linked to a payment instrument, or allow them to circumvent the limits set on such instruments.
It's advancing a lot quicker than you'd expect given that many of the countries aren't really that good at coordinating with each other.
Further, NFC is usually the first to be left out when manufacturers cut costs to hit lucrative price points.
Apple never implemented host card emulation (HCE) as an API, but that doesn't matter as these payment systems usually aren't backed by a payment card network, thus they'd have to build needlessly complex reconcilliation systems when transactions already debit directly from accounts, and offline usage isn't considered a major use-case.