Also, signing with anything other than a pen and paper is still a disastrous user experience (see every courier's PDA system ever built)
Also, signing with anything other than a pen and paper is still a disastrous user experience (see every courier's PDA system ever built)
For them to include a PIN entry system, they would need to do so on the chip reader device itself (non-iPhone).
The keypads for PIN entry systems always hash the PIN before it leaves the keypad... no other software gets the PIN.
If you cannot offer secure PIN entry, then you cannot offer PIN entry.
You can still take a signature, but now the burden of responsibility changes. Fraud is covered by the merchants if you use signatures.
They can still screw around with that one single transaction, but they cant duplicate the card.
Its like an ssl tunnel straight from your card to your bank. The other party is just passing the encrypted one time permission slip to charge money.
It completely ended skimming here. As for unsecured devices like an iPad, the goverment mandates two way authentification. This is done by sending an authorisation code per text message, or an auxiliery device, not connected to anything, that uses the signing chip on the card, to provide the user with a one time authentification code.
Where are the finger print scanners or iris scanners when we need them?