Live data from Hacker News

MasterCard to start verifying transactions through selfies

americans.org

41–50 of 56 posts

Re: MasterCard to start verifying transactions through selfies

#41
post #12

People are missing the point, like "chip and pin" this is not about protecting the consumer but about protecting Mastercard and their duopoly "What you mean you did not pay for a hooker and rum in Amsterdam, then who is this in a selfie you took" > shows a selfie some hacker stole from the poor eejits Lifeinvader page.

If only.

> shows a selfie [taken from somewhere]

The software only sends a hash of the "map" of the face to Mastercard for comparison (or so an earlier Dutch article on security.nl put it). They can never show you the original image again.

Re: MasterCard to start verifying transactions through selfies

#42
Ok, so everyone has pointed out how insecure this would obviously be, and all the simple ways in which you could fool it.

But, I'm left wondering, did the guys at mastercard never even think this through at all? This is people's money after all. It needs to be safe. Did they not even consider that, as soon as this is rolled out, people were going to see money disappear?

I can't believe they didn't think of that. Which makes me wonder, why am I even reading about this at all?

Re: MasterCard to start verifying transactions through selfies

#43
post #39
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

I always wonder if there were these old fogeys who complained when the first postal services were brought in in the 19th century. Like "Back in my day, I visited my friends and family because I cared, but now any idiot with a stamp can send me an annoying letter."

They did about the telephone, though:

>"The Americans have need of the telephone, but we do not. We have plenty of messenger boys." -- Sir William Preece, chief engineer of the British Post Office, 1876.

Radio, planes and xrays:

>"Radio has no future. Heavier-than-air flying machines are impossible. X-rays will prove to be a hoax." -- William Thomson, Lord Kelvin, British scientist, 1899.

The grand canyon: >"Ours has been the first, and doubtless to be the last, to visit this profitless locality." -- Lt. Joseph Ives, after visiting the Grand Canyon in 1861.

Oil drilling: >"Drill for oil? You mean drill into the ground to try and find oil? You're crazy." -- Workers whom Edwin L. Drake tried to enlist to his project to drill for oil in 1859.

Nuclear energy: >"There is not the slightest indication that nuclear energy will ever be obtainable. It would mean that the atom would have to be shattered at will." -- Albert Einstein, 1932.

The Germ theory: >"Louis Pasteur's theory of germs is ridiculous fiction." -- Pierre Pachet, Professor of Physiology at Toulouse, 1872.

Brain surgery: >The abdomen, the chest, and the brain will forever be shut from the intrusion of the wise and humane surgeon." -- Sir John Eric Ericksen, British surgeon, appointed Surgeon-Extraordinary to Queen Victoria 1873.

All taken from: http://www.rinkworks.com/said/predictions.shtml

Re: MasterCard to start verifying transactions through selfies

#44

Ok, so everyone has pointed out how insecure this would obviously be, and all the simple ways in which you could fool it. But, I'm left wondering, did the guys at mastercard never even think this through at all? This is people's money after all. It needs to be safe. Did they not even consider that, as soon as this is rolled out, people were going to see money disappear? I can't believe they didn't think of that. Whic…

Credit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card.

As such, everything the card companies do in the name of "security" is not to prevent people from losing money—they don't need to solve that problem. They just need to solve the perception people have that credit cards are insecure. In other words, all credit card security (yes, even chip-and-pin) is security theatre. Whether it works or not, it's not there to work; it's there to feel good.

Re: MasterCard to start verifying transactions through selfies

#45
post #39
post #29

I'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes…

I always wonder if there were these old fogeys who complained when the first postal services were brought in in the 19th century. Like "Back in my day, I visited my friends and family because I cared, but now any idiot with a stamp can send me an annoying letter."

> I always wonder if there were these old fogeys who complained when the first postal services were brought in in the 19th century.

The first postal services were formed long before that; there were definitely some in the late 17th Century, may have been earlier.

Re: MasterCard to start verifying transactions through selfies

#46

Earlier quoted context omitted.

In the two years since that article was written, how many cases have there been of iPhones actually hacked in the wild through TouchID?

How would one measure that, even if it is happening?

By news stories?

Given the amount of media attention there was when the early proof of concept hacks emerged, I'd be amazed if they wouldn't be all over any story that had even the slightest suggestion that someone might have lost data as a result of a stolen phone having been hacked via TouchID.

Re: MasterCard to start verifying transactions through selfies

#47
post #23

I would just be happy if I could actually use my "chip and pin" credit card when performing a transaction. I have yet to find a retailer where I can actually use it.

Just in the past few months I've been seeing many more of them around the Boston area in the U.S. at big stores. It's coming.

Chip-and-Signature is becoming one of the standards in the U.S, not Chip-and-Pin.

Mastercard is one of the companies trying really hard to prevent pin numbers from happening.

It's almost as if an executive heard that "biometric" is happening, and decided to take a bet on it.

Re: MasterCard to start verifying transactions through selfies

#48
post #44

Ok, so everyone has pointed out how insecure this would obviously be, and all the simple ways in which you could fool it. But, I'm left wondering, did the guys at mastercard never even think this through at all? This is people's money after all. It needs to be safe. Did they not even consider that, as soon as this is rolled out, people were going to see money disappear? I can't believe they didn't think of that. Whic…

Credit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card. As such, everything the card companies do in the name of "security" is not to prevent people from losing money—they don't need to solve that problem. They just need to solve the perception people have that credit cards are insecure. In other wo…

> Credit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card.

100% on that. Money is lost all the time, but thanks to that retroactive liability, the bank and/or merchant loses it instead of the consumer. Security for the consumer is already as good as it could possibly get, so they're really saving themselves and their merchants. This is a good thing, because they have a much more direct incentive to save themselves money than to save you money.

Re: MasterCard to start verifying transactions through selfies

#49

I would just be happy if I could actually use my "chip and pin" credit card when performing a transaction. I have yet to find a retailer where I can actually use it.

I'm in the US, and I had never seen anybody actually use it up to a week or so ago, even though lots of retailers are putting in the chip-capable readers. But I've been traveling for the last week or so, and I just ran into a couple of retailers in other states where I had to scan the chip of my cards instead of the mag strip for the charge to go through - and one of them was Target.

So it looks like it is coming to the US, slowly but surely.

Re: MasterCard to start verifying transactions through selfies

#50
post #44

Ok, so everyone has pointed out how insecure this would obviously be, and all the simple ways in which you could fool it. But, I'm left wondering, did the guys at mastercard never even think this through at all? This is people's money after all. It needs to be safe. Did they not even consider that, as soon as this is rolled out, people were going to see money disappear? I can't believe they didn't think of that. Whic…

Credit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card. As such, everything the card companies do in the name of "security" is not to prevent people from losing money—they don't need to solve that problem. They just need to solve the perception people have that credit cards are insecure. In other wo…

The cost of limited consumer liability for stolen cards is spread across all consumers in other card fees (perhaps hidden ultimately in network/merchant fees, and thus spread further in consumer prices.)

In a competitive credit card market (which we may not really have, but that's a different problem) an issuer reducing the incidence of lost would be able to compete better by either lowering charges or providing greater benefits while making the same profit, forcing other issuers to match those features or be driven out of the market.

Post reply on HN