6 ms·
MasterCard to start verifying transactions through selfies
- EugeneOZ 11y agoI hate selfies. Please leave pin codes for people who don't trust image recognition algorithms enough.
- Fradow 11y agoRelevant link: "Fingerprints are usernames, not password" (applies to all biometrics): http://blog.dustinkirkland.com/2013/10/fingerprints-are-user-names-not.html http://blog.dustinkirkland.com/2013/10/fingerprints-are-user... Long story short, it's a bad idea, and it's really not secure.
- prof_hobart 11y agoIn the two years since that article was written, how many cases have there been of iPhones actually hacked in the wild through TouchID?
- harperlee 11y agoHow would one measure that, even if it is happening?
- mc32 11y agoNot hacked in the normal sense but there have been kids who needed their sleeping parents' phones unlocked, so they just put the phone to their parents' fingers...
- prof_hobart 11y agoBy news stories? Given the amount of media attention there was when the early proof of concept hacks emerged, I'd be amazed if they wouldn't be all over any story that had even the slightest suggestion that someone might have lost data as a result of a stolen phone having been hacked via TouchID.
- higherpurpose 11y agoIt's much worse for pictures than fingerprints because most people have tons of pictures of themselves online now, and many are also public. It's probably just a matter of time before malicious hackers start spoofing their identities.
- tetraodonpuffer 11y agodon't forget all the ongoing advances in the "here's a bunch of pictures, come up with a 3d model of the person" problem, making the spoofing even easier
- LoSboccacc 11y agoWell we had this idea ten years ago, but the biometric scan was checked for freshness against a database of biometric scans. It was thought for protect the conversation between two leers however and not for blind validation. The idea to protect against this kind of replay attack was that if the algorithm was unsure of the scan it could request a new one, validate it and present it to the user in case of low confidence biometric match or high confidence forgery: the point being that humans are good at detecting the kind of tampering that could fool an algorithm and vice versa. This required to send the biometric scan to the peer and to validate it on the other side of the communication channel instead that on the device. Well, we weren't technically using it as password in the end, I guess I'll have a closer look at what they're doing. And check if that old patent is still good. Eheh not that I have any rights to it left of course.
- eurmag 11y agoMy question is: "Selfie as a Password", - Is it really secure?
- JoeAltmaier 11y agoIts a terrible idea. Its a password you can't change, can't even choose, leave lying about all over the place. Its everything a password shouldn't be.
- revmoo 11y agoTo our valued MasterCard customers, We recently learned that one of our service providers, was the victim of an illegal and unauthorized intrusion into its network during the first quarter of 2016. In response, the service provider enhanced the security of its network systems, cooperated with law enforcement including the United States Secret Service (“USSS”), and investigated using leading outside security firms. Out an abundance of caution we are recommending all of our customers to get plastic surgery to their face in order to secure your identity and financial accounts. As a token of our apology, we will be paying 80% of all related surgical costs. Again we apologize for this incident and we will be taking steps to ensure it does not happen again.
- marak830 11y agoEdit: after reading JoeAltmaier and thinking more about it, its a terrible idea. You cant change it, its easy to dupe. No. Just no. Ill leave my original post though. :-) Id argue its more or less the same as a pin. Both could be gotten past with a determined attacker or a generic setup(camera for pin/selfie). Infact id say easier for certain people who post selfies on public sites, ripm. Cut and paste on x background. The more i think about it, the stupider the idea sounds.
- bayarealife 11y ago(I'm probably dead for being a new account, but post for the benefit of the showdead people) It really is facial identification, but is coached in so much language to seem hip and cool that it becomes almost uncomfortable. MC is saying that they will allow facial identification as an authenticator is much less interesting of a story I suppose.
- snarfy 11y agoThis reminds me of the hat from fifth element: http://images2.fanpop.com/images/photos/5000000/The-Fifth-Element-the-fifth-element-5050874-1918-796.jpg http://images2.fanpop.com/images/photos/5000000/The-Fifth-El...
- gearhart 11y agoSeems to me that this is a cheap, relatively smart piece of marketing, rather than a serious proposition - note the heartbeat and voice recognition ideas that they're also "experimenting" with.
- tehmaco 11y agoThere's a better link here [1], which explains with more details. Main thing seems that it's not just facial recognition, you can use a fingerprint scanner (assuming your phone has one) instead, and that it requires you to blink when you're being scanned by the app. So it doesn't seem to be just static image recognition, it's looking at the video stream to ensure that your face is there and that it can blink (getting around the 'just hold a photo in front of the camera' problem). [1] http://money.cnn.com/2015/07/01/technology/mastercard-facial-scan/ http://money.cnn.com/2015/07/01/technology/mastercard-facial...
- peterwwillis 11y agoSince a video is just a string of images, all the attacker would need is a sufficient number of photoshopped images to show a series that (when stitched into a video) shows the user blinking. I'm pretty sure you could make a Photoshop plugin that would do this. I'll do you one better: you could probably make a print-out paper 'mask' of a person's face and just blink yourself, or something similar. This kind of tech isn't always as smart as we think.
- IKnowComputer 11y agoHow is this supposed to work in low-light and dark environments, like a classy restaurant? What about people that don't have camera phones? This will end up being opt-in only, I'm sure. Can you imagine the checkout at the supermarket as vain people hold the line up while they make up their hair? I really don't see this as becoming commonplace.
- yc1010 11y agoPeople are missing the point, like "chip and pin" this is not about protecting the consumer but about protecting Mastercard and their duopoly "What you mean you did not pay for a hooker and rum in Amsterdam, then who is this in a selfie you took" > shows a selfie some hacker stole from the poor eejits Lifeinvader page.
- lucb1e 11y agoIf only. > shows a selfie [taken from somewhere] The software only sends a hash of the "map" of the face to Mastercard for comparison (or so an earlier Dutch article on security.nl put it). They can never show you the original image again.
- bcg1 11y agoI don't even have a cell phone. And there is zero chance I would ever get one just so that SlaveCard will process payments for me. That whole industry is like the grandfather that clearly can't drive anymore but everyone's afraid to confront about taking the keys away... why is nobody willing to 'disrupt' these people already?
- jlgaddis 11y agoI would just be happy if I could actually use my "chip and pin" credit card when performing a transaction. I have yet to find a retailer where I can actually use it.
- 51Cards 11y agoInteresting, where are you located? Here in Canada I use mine practically everywhere on a daily basis.
- frandroid 11y agoThey're in the U.S., the last large bastion of the magnetic strip.
- harperlee 11y agoAnd the paper cheque.
- jessaustin 11y agoI love paper checks.
- jlgaddis 11y agoYep, I still write several checks a month too (almost exclusively for rent, utilities, and the occasional donation).
- kwhitefoot 11y agoI think the last cheque I wrote was at least 15 years ago. They don't exist here, Norway, any more.
- jlgaddis 11y agoIndiana, US
- 11y ago
- kefka 11y agoThere's lots of easy avenues to attack this. 1. Look for user's Youtube, Facebook, and other social media for photos/video 2. Videochat and record them. 3. Find them IRL and record them. 4. Print a mask of that person, and leave eye holes. Now you blink instead. Ridiculous.
- chinathrow 11y agoHahahahahaha. Remember that OS X login mode by your own selfie where you could simulate blinking with a matchstick and login with a photograph?
- deleted 11y ago[deleted]
- istvan__ 11y agoFirst I thought I mixed up my tabs and I am on 4chan instead of being on HN. Other verification approach is to use voice like WeChat does. http://www.biometricupdate.com/201503/instant-messaging-app-wechat-on-ios-adds-voice-biometrics http://www.biometricupdate.com/201503/instant-messaging-app-...
- marcosdumay 11y agoWell, it just shows that banks and credit card issuers will go to any length to avoid implementing a proper PKI and secure transactions. My only question is why?
- jnsaff2 11y agoDidn't they get the memo from Japan? http://pinktentacle.com/2008/06/magazine-photos-fool-age-verification-cameras/ http://pinktentacle.com/2008/06/magazine-photos-fool-age-ver...
- __z 11y agoThey require the user to blink to protect against this sort of attack but there are workarounds.
- logn 11y agoI'm starting to feel like a grey neckbeard. In my day, when I wanted to hang out with my friends, I called them, from a landline, known simply as "the phone". These days, I'm at or near a desktop/laptop computer almost 24/7 so don't see much need for a smartphone. I dread the day when a smartphone is required to be a part of society. It's shifting in that direction rapidly. If being on Facebook/LinkedIn also becomes a necessity, hopefully I'm already retired and have a beautiful lawn.
- stox 11y agoThe next step will be to embed smart phones in children at birth. I guess "The President's Analyst" was more prescient than we gave it credit for.
- ma2rten 11y agoActually the main reason I have a smartphone is for GPS. Imagine a device where you enter the name of a place and it tells you how to go there.
- collyw 11y agoSure its easier now, but it wasn't that much of a problem before. Just get an A-Z map of the town you are going. When I was travelling I always had a Lonely Planet guide. It had most of the information you would be likely to find with online searches, and organised in a helpful way.
- deleted 11y ago[deleted]
- herge 11y agoI always wonder if there were these old fogeys who complained when the first postal services were brought in in the 19th century. Like "Back in my day, I visited my friends and family because I cared, but now any idiot with a stamp can send me an annoying letter."
- tomjen3 11y ago
- gonzo41 11y agoThe don't want to make money safe. making money safe makes money slow. Pay wave / pay pass and mastercard/visa chargebacks are all about getting money moving around more.
- bobm_kite9 11y agoOk, so everyone has pointed out how insecure this would obviously be, and all the simple ways in which you could fool it. But, I'm left wondering, did the guys at mastercard never even think this through at all? This is people's money after all. It needs to be safe. Did they not even consider that, as soon as this is rolled out, people were going to see money disappear? I can't believe they didn't think of that. Which makes me wonder, why am I even reading about this at all?
- derefr 11y agoCredit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card. As such, everything the card companies do in the name of "security" is not to prevent people from losing money—they don't need to solve that problem. They just need to solve the perception people have that credit cards are insecure. In other words, all credit card security (yes, even chip-and-pin) is security theatre. Whether it works or not, it's not there to work; it's there to feel good.
- ufmace 11y ago> Credit card companies already have the perfect "security" measure: retroactive limited liability for stolen cards. Nobody loses money because someone steals their credit card. 100% on that. Money is lost all the time, but thanks to that retroactive liability, the bank and/or merchant loses it instead of the consumer. Security for the consumer is already as good as it could possibly get, so they're really saving themselves and their merchants. This is a good thing, because they have a much more direct incentive to save themselves money than to save you money.
- dragonwriter 11y agoThe cost of limited consumer liability for stolen cards is spread across all consumers in other card fees (perhaps hidden ultimately in network/merchant fees, and thus spread further in consumer prices.) In a competitive credit card market (which we may not really have, but that's a different problem) an issuer reducing the incidence of lost would be able to compete better by either lowering charges or providing greater benefits while making the same profit, forcing other issuers to match those features or be driven out of the market.
- TrevorJ 11y agoOK, so who thinks it would be a good idea to post their credit card number and CVV2 code on their Facebook wall? Because that's essentially what Mastercard has caused everyone to do here.