Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

EMV only seems to secure offline transactions at merchants and ATMs. How does it protect information for online and phone payments?


As part of EMV, the liability is typically shifted to the merchant for non-EMV authenticated transactions. This provides strong motivation for merchants to do a better job of filtering out fishy transactions.

The only solutions I've seen to using EMV itself for online/phone transactions involve having a more advanced card (i.e. with LCD token readout) or a standalone card reader to interact with the chip.

E.g.: ftp://ftp10.us.freebsd.org/users/azhang/disc/springer/0558/papers/2455/24550388.pdf


Merchants already have to pay back the transaction, plus a charge, plus we're out the merchandise. We already have plenty of incentive to spot fraudulent transactions.

What is needed is a better system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: