Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Chip & Pin has the fatal flaw of asking me to trust unverified hardware. I know that my phone is trustworthy. I don't know that your POS terminal is. It definitely eliminates a lot of the issues present in the current magstripe setup, but what I want is something that requires access to a black box I trust.

As long as I'm handing credentials to an untrusted computer that I have to trust to behave honestly, the problem isn't solved.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: