|
|
|
|
|
by dgaudet
2616 days ago
|
|
is there technology around this? i mean i can imagine an API where the CC# itself is only necessary in the first transaction with a new vendor, during which the vendor makes a (signed) request for a vendor-specific token to use for future payments, and can forget the CC# immediately; future payment requests use the same signature chain and the vendor-specific token... making it easy to invalidate any/all of these tokens if the data is compromised, or if the end-user wants to invalidate a specific recurring payment, etc. i'm in fantasy land, right? |
|
Now that's currently only online, but they're releasing a point of sale product soon too. But even with that, you connect to their card reader and receive a token that you can use.