4 ms·
It'd be cool if payment cards had a built-in LCD screen for the PIN as a TOTP. That shouldn't be much harder for consumers than the existing card verification/s
by rob-olmos 6y ago
It'd be cool if payment cards had a built-in LCD screen for the PIN as a TOTP. That shouldn't be much harder for consumers than the existing card verification/security code.
- Symbiote 6y agoIt's not built-in, but an external device can generate an OTP (maybe a TOTP?). Some European banks have used this system for over 10 years, but others just use SMS or nothing. https://en.wikipedia.org/wiki/Chip_Authentication_Program https://en.wikipedia.org/wiki/Chip_Authentication_Program
- dzhiurgis 6y agoWhy not use card itself as u2f? Most phones now has nfc reader now. Could be used for both - online purchases and bank logins.
- Symbiote 6y agoPerhaps the banks did't want to trust the security of the phone? Bear in mind these card readers were introduced in the UK and Sweden in 2007, around the same time as the first iPhone.
- dzhiurgis 6y agoYet literally every bank trusts the security of the phone + telco when sending you 2FA token via unencrypted SMS...
- ValentineC 6y ago> Why not use card itself as u2f? Most phones now has nfc reader now. Most budget Android phones don't, and the iPhone one is locked down. Some banks now have an in-app token. Many bank apps also have some form of jailbreak/root detection. If the detection is tripped, the app will either kill itself, or disable the in-app token.
- dzhiurgis 6y agoLets not try to solve the problem for everyone. It’s obviously an opt in. If they really wanted it to work they could design card that also plugs into usb-c or micro-usb port to work as hardware token. Also iPhones can now read NFC card. My partner already used her passport to get onto SmartId system in Lithuania. In-app tokens rely on your phone - loose it and you are really screwed. Wanna let your accountant to use account while you on vacation - you can’t. Plus setup (or suspicious logins) normally depends on a SMS 2FA.