Earlier quoted context omitted.
> Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor. Isn't that how chip-and-pin works?
Except that the merchant still gets to see my credit card numbers (both sides). But it's how paypal works. The merchant only get an authorization code from paypal, and this code is useless to a hacker.
With chip and pin? I don't think they do.