Hacker News new | ask | show | jobs
by kbenson 3718 days ago
This thread[1] is the one you want. The EU allowed "offline" transactions, where the chip was used only to verify the pin. The "quick chip" method you describe may be secure, but I have very little faith that these companies can architect a lasting secure solution, the incentives just aren't aligned in our favor.

Simply put, requiring the authorization token (card, phone, etc) be present and accessible for the entire transaction is not a bug, it's a feature. I surely do not want transactions happening after I've left the store, and while you can sign a verified transaction request with everything needed to process the transaction on okay from the bank, that's an extra level of complexity on top of a system I already don't trust them to get right.

1: https://news.ycombinator.com/item?id=10414994