Mastercard Launches Its Biometric Retail Payment System in Europe
nakedcapitalism.com
nakedcapitalism.com
I guess if every PoS that supports bio also required a camera and human verification, then you couldn’t just pass the hash to some API
Seems like MC executives grew up on “Minority Report” and thought, damn this is a good idea!
It requires a decent camera with very good optics or short distance from your eyes to get a meaningful identification, so your casual CCTV mass surveillance isn't a problem. If I want anonymity, irises are going to be very low on my list of potential worries.
Also, I consider those to be public data (just like my face, fingerprints, overall appearance, voice or DNA), because anyone willing within a reasonable proximity can get this data anyway and there's no stopping it. So, if some company wants to use that as an authenticator... well, that's a stupid idea that I would protest for anything sensitive (unauthorized access to which could actually cause me some griefs), but as long as it's not my liability (and for a credit card it is not - fraud disputes aren't fun but it's not my money either) they can do... whatever, I guess.
Or am I missing something?
The security issue.
I.e., Mastercard treats their technology as infallible and the people who find an exploit select you as the victim. Mastercard fails to take responsibility and continues to allow you to be exploited with absolutely no mechanism to defend yourself.
Credit card numbers can be changed a lot easier than eyeballs can be.
They're not unlikely to claim that it was me because machine reports seeing my eyes (because it doesn't hurt them to try to deny the claim), but generally industry is well aware that fraud exists.
> Mastercard fails to take responsibility and continues to allow you to be exploited
True for debit, but for credit the idea is that it's card issuer's problem if they still authorize those biometrics-authenticated transactions afterwards. The most probable scenario is that they'll immediately block the card and ability to use biometric payments after receiving the fraud report. Then start figuring out what happened.
So, I guess, as long as I don't have all eggs in one basket (MasterCard), I will be inconvenienced but not really exploited.
And given that it's not exactly trivial to quietly steal then impersonate someone's eyes and face, until that actually happens (low-probability event) it seems convenient to pay (high-frequency event) without reaching for a wallet or device.
Isn't it the reverse, with the issuer declining fraud allegations as they can "prove" you originated the transaction ?
That's the building block of 3DSecure and other additional authentication, where the merchant is protected from chargebacks in exchange for pushing stronger check on the customer.
Also, in my experience, when a fraudulent transaction happens, banks tend to not challenge it much. When someone impersonated my card (I'm not sure but I suspect it was a BIN stuffing attack, since it was a sock drawer card) they just handled it without any issues.
3-D Secure shifts the risk/convenience balance and adds additional security checks, but it doesn't make customers liable for fraud.
And if some credit organization or airport security says they're fine with using it - I see this as their risks, not mine. And giving them my biometrics isn't hurting me because I won't use it for anything I care about. Unless, of course, I'll be forced to, somehow - but I doubt that's likely.
I see MasterCard doing this as they estimated a risk-to-profit factor to be satisfactorily low. My overall impression of banking/finance industry is that they're very different when it comes to security - they tend to have what we'd call poor security practices, but they compensate this by taking responsibility for when things fail, swallowing the losses (cheaper than upgrading everyone and everything) and just making sure they earn more than they lose. It's more prominent in US (where half of the industry relies on knowing last four of secret SSN number that you have to share-not-share with a lot of companies, and some very "secret" questions like my birthday - and the economy still works somehow!) than in EU, though.
I trust federal agencies more than private corporations, having seen the inside of both.
I do, but I don't see how those methods are better than a chip and pin. Waiting in line at a checkout or getting on a bus behind somebody hopelessly futzing with their phone to mess with the app is the new waiting for someone to write a check. The eye thing is dystopian, but it'll be fast.
Fumbling with your phone sounds like a silly statement but so did fumbling with your wallet.
I don't think people want to look away from their phones to do anything, least of all pass a retina scan. You don't even need to swipe away from TikTok to use Apple Pay.
Your wallet and phone are lost/stolen. I wish the ATM would take my bank username and password but this is a close second in that situation. Wouldn't use it otherwise.
Perhaps selling this collected data to third parties? I'd imagine optometrists would want it to push mail in fliers.
I don't see how this is any more convenient than using a mobile wallet. In fact, it looks less convenient than using the actual card - even if you forget the card you can usually just key in the number at the terminal.
So how do you make people use a retinal camera? You cut a hole in a picture of a monkey or the store mascot’s head and put up a big sign that says “look at Mr. Groceries to pay your bill with MasterCard EyeScan” or whatever it is called.
Because explaining how to use it to every single person in line is definitely going to make it fast.
Apple pay is about as biometric-y as I'm willing to go for payments.
Europeans hate having sovereign and self sufficient industries, or is it done through psyops?
Imagine giving away your biometric and, soon if not already, your DNA data to foreign countries that will make sure their interests come first (Nordstream sabotage, broken France-Australia submarine deal, US Inflation Reduction Act)
You don't need to like crypto, but all those privacy issues, inflation, regulations, etc. with fiat money naturally leading to find better alternatives.
Hint: it's already deployed and working and nobody wants your retinal scans, because it requires a more costly setup at the PoS.
I trust my phone enough. My phone can authenticate me and you can authenticate it. We have that today, works great.
I don’t need “stare at the picture of the monkey over the camera and press the button to pay” or whatever other nonsense retails will do to this.
I’m not anti-biometrics. I’m ok with it on my devices I’ve made that decision on.
But retailers everywhere? No. I know the devices will need to be certified just like EMV terminals, so it’s not like the Amazon things. But that’s still to far.
how hard is it to steal your eye scan?