Hacker News new | ask | show | jobs
by angoragoats 25 days ago
Okay, so you were mostly referring to payment industry standards, not laws or regulations.

> PCI-DSS (enforced by banks/payment processors) means the EMV token store on your Android phone must be in an isolated uncompromised location (usually the TEE).

Do you have a citation for this? My understanding is that the whole point of EMV tokenization is that it masks the sensitive cardholder data that would otherwise have to be protected in a PCI compliant way. In other words, I don’t think the data that is stored on your phone is covered by PCI-DSS.

And as another poster already mentioned, I don’t think the EU law you’re citing works the way you claim it does.