Don't worry, I'm sure they'll give you a free three month subscription to a new pair of eyes every time they leak your iris scans.
Mastercard Launches Its Biometric Retail Payment System in Europe
41–50 of 50 posts
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#42If I won’t give Amazon my palm print to pay at Whole Foods, why the f would I give Mastercard a pair of retinal scans? Seems like MC executives grew up on “Minority Report” and thought, damn this is a good idea!
Are retinal scans a big deal? It requires a decent camera with very good optics or short distance from your eyes to get a meaningful identification, so your casual CCTV mass surveillance isn't a problem. If I want anonymity, irises are going to be very low on my list of potential worries. Also, I consider those to be public data (just like my face, fingerprints, overall appearance, voice or DNA), because anyone willi…
The security issue.
I.e., Mastercard treats their technology as infallible and the people who find an exploit select you as the victim. Mastercard fails to take responsibility and continues to allow you to be exploited with absolutely no mechanism to defend yourself.
Credit card numbers can be changed a lot easier than eyeballs can be.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#43Don't worry, I'm sure they'll give you a free three month subscription to a new pair of eyes every time they leak your iris scans.
Are they keeping the scans, or just a hash of the scan?
I guess if every PoS that supports bio also required a camera and human verification, then you couldn’t just pass the hash to some API
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#44I don't really see how this is a drastically better experience than tap to pay, NFC, Apple Pay, etc. It would feel odd to provide eye scans to everyday retailers, and then at some point, you have to worry about your eye scan being stolen, and you can't (easily) get a new eye afterwards, but you can replace all the payment methods that aren't your eyes.
> I don't really see how this is a drastically better experience than tap to pay, NFC, Apple Pay, etc. I do, but I don't see how those methods are better than a chip and pin. Waiting in line at a checkout or getting on a bus behind somebody hopelessly futzing with their phone to mess with the app is the new waiting for someone to write a check. The eye thing is dystopian, but it'll be fast.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#45Earlier quoted context omitted.
Are retinal scans a big deal? It requires a decent camera with very good optics or short distance from your eyes to get a meaningful identification, so your casual CCTV mass surveillance isn't a problem. If I want anonymity, irises are going to be very low on my list of potential worries. Also, I consider those to be public data (just like my face, fingerprints, overall appearance, voice or DNA), because anyone willi…
> Or am I missing something? The security issue. I.e., Mastercard treats their technology as infallible and the people who find an exploit select you as the victim. Mastercard fails to take responsibility and continues to allow you to be exploited with absolutely no mechanism to defend yourself. Credit card numbers can be changed a lot easier than eyeballs can be.
They're not unlikely to claim that it was me because machine reports seeing my eyes (because it doesn't hurt them to try to deny the claim), but generally industry is well aware that fraud exists.
> Mastercard fails to take responsibility and continues to allow you to be exploited
True for debit, but for credit the idea is that it's card issuer's problem if they still authorize those biometrics-authenticated transactions afterwards. The most probable scenario is that they'll immediately block the card and ability to use biometric payments after receiving the fraud report. Then start figuring out what happened.
So, I guess, as long as I don't have all eggs in one basket (MasterCard), I will be inconvenienced but not really exploited.
And given that it's not exactly trivial to quietly steal then impersonate someone's eyes and face, until that actually happens (low-probability event) it seems convenient to pay (high-frequency event) without reaching for a wallet or device.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#46Earlier quoted context omitted.
Are retinal scans a big deal? It requires a decent camera with very good optics or short distance from your eyes to get a meaningful identification, so your casual CCTV mass surveillance isn't a problem. If I want anonymity, irises are going to be very low on my list of potential worries. Also, I consider those to be public data (just like my face, fingerprints, overall appearance, voice or DNA), because anyone willi…
You nailed it, we should not use public data for important things like this that could result in fraud.
And if some credit organization or airport security says they're fine with using it - I see this as their risks, not mine. And giving them my biometrics isn't hurting me because I won't use it for anything I care about. Unless, of course, I'll be forced to, somehow - but I doubt that's likely.
I see MasterCard doing this as they estimated a risk-to-profit factor to be satisfactorily low. My overall impression of banking/finance industry is that they're very different when it comes to security - they tend to have what we'd call poor security practices, but they compensate this by taking responsibility for when things fail, swallowing the losses (cheaper than upgrading everyone and everything) and just making sure they earn more than they lose. It's more prominent in US (where half of the industry relies on knowing last four of secret SSN number that you have to share-not-share with a lot of companies, and some very "secret" questions like my birthday - and the economy still works somehow!) than in EU, though.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#47Earlier quoted context omitted.
> Or am I missing something? The security issue. I.e., Mastercard treats their technology as infallible and the people who find an exploit select you as the victim. Mastercard fails to take responsibility and continues to allow you to be exploited with absolutely no mechanism to defend yourself. Credit card numbers can be changed a lot easier than eyeballs can be.
> Mastercard treats their technology as infallible They're not unlikely to claim that it was me because machine reports seeing my eyes (because it doesn't hurt them to try to deny the claim), but generally industry is well aware that fraud exists. > Mastercard fails to take responsibility and continues to allow you to be exploited True for debit, but for credit the idea is that it's card issuer's problem if they stil…
Isn't it the reverse, with the issuer declining fraud allegations as they can "prove" you originated the transaction ?
That's the building block of 3DSecure and other additional authentication, where the merchant is protected from chargebacks in exchange for pushing stronger check on the customer.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#48Earlier quoted context omitted.
Are they keeping the scans, or just a hash of the scan?
Does that even matter when the same set of eyeballs theoretically produce the same hash? It leaking has the same effect, what more benefit would having the “real” eye scan have to an attacker that just wants to use your bank account? I guess if every PoS that supports bio also required a camera and human verification, then you couldn’t just pass the hash to some API
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#49Earlier quoted context omitted.
> Mastercard treats their technology as infallible They're not unlikely to claim that it was me because machine reports seeing my eyes (because it doesn't hurt them to try to deny the claim), but generally industry is well aware that fraud exists. > Mastercard fails to take responsibility and continues to allow you to be exploited True for debit, but for credit the idea is that it's card issuer's problem if they stil…
> it's card issuer's problem if they still authorize those biometrics-authenticated transactions afterwards. Isn't it the reverse, with the issuer declining fraud allegations as they can "prove" you originated the transaction ? That's the building block of 3DSecure and other additional authentication, where the merchant is protected from chargebacks in exchange for pushing stronger check on the customer.
Also, in my experience, when a fraudulent transaction happens, banks tend to not challenge it much. When someone impersonated my card (I'm not sure but I suspect it was a BIN stuffing attack, since it was a sock drawer card) they just handled it without any issues.
3-D Secure shifts the risk/convenience balance and adds additional security checks, but it doesn't make customers liable for fraud.
Re: Mastercard Launches Its Biometric Retail Payment System in Europe
#50You don't need to like crypto, but all those privacy issues, inflation, regulations, etc. with fiat money naturally leading to find better alternatives.