Technology is supposed to make life easier, not harder.
That may be true, but the current track record of technology is that when it makes things easier for the user it also makes things easier for the hacker.
Don't want a smartphone? All the capabilities stated above could in theory be placed into a relatively small dedicated device that is only used for Authentication purposes. Hell, instead of even having an onboard battery, the device could have a cord that plugs into the POS device and transfers data while receiving power that way.
I personally want something more secure than the Swipe & PIN that my Debit Card uses with the protection that comes with Swipe and Sign that's the current method used by American Credit Card companies. Like I said, Chip and PIN is only mildly more secure than Swipe & PIN and I feel that my proposed method would bring security to a more comfortable level, at least for me.
I still don't like Chip & PIN. It's better than swipe and sign of current credit cards, but it's not much more secure than using a Debit Card at the terminals now, which is Mag-stripe Swipe and PIN here. I'd rather have cards with 2FA. Sure, my idea requires a smartphone with data access, but a business needs some kind of data-line to process credit card transactions now anyway. For my Idea to work replace the card machines with a type that has a keypad and provides NFC or Bluetooth access, or uses a screen to display a QR code; similar to the parent's idea so far... Now the device doesn't even have to be a smartphone... just smartphone like. Smartphones now are capable of using fingerprint readers so a payment device only would need a Camera, NFC radio, Cell Radio (possibly optional, but would make SMS messaging viable), WiFi radio, Fingerprint reader, and a TFT (maybe GPS too...).
My idea goes something like this: POS has rung up all the customer's items and requests payment. POS Pay-Pad Pops up the total and a QR code on the screen and activates the NFC Radio. Customer can either use the NFC or Camera on their device to get the relevant information (Store Name/Number/Location, Total amount due, any other pertinent info), Device then uses whatever data connection it has available (POS NFC, POS Bluetooth, Wi-Fi hotspot, Cell Data, SMS...etc) to send the information to the requisite Authentication company (MC/V/AmEx/Dsc/Store Card Auth; possibly chosen from a menu on device), Authenticator application then requests fingerprint from user to authenticate with. Upon successful authentication a confirmation page would come up where the user can verify all the information received from the QR code / NFC transfer and make sure it's right (the information would not be what was stored from the initial read but received again from the AuthCo to ensure that the data wasn't corrupted in transfer). Re-authenticating by fingerprint confirms the info, hitting a physical button will cancel it. Upon successful second authentication, a one time use pin number would appear on the screen for the user to punch into the POS terminal keypad. When the POS receives the PIN and verifies it against information it just received from the Authentication Company, it accepts payment and marks the transaction complete. The only time this whole scenario would fail is during data outages, which could be mitigated by having a physical card as a backup for performing imprints and manual processing on, which the user can possibly log in their authenticator application.
This is just a thought, but I'm just a dreamer. I hope I'm not the only one.
Aol users:
Keeping the
"h...t...t...p...colon...slash...slash...slash...dot...dot...com..."
joke alive.
Neutrinos have bad breadth.