Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Isn't allowing the user to opt to just bypass the PIN a bit of a security hole?

That's a valid point of view, but I actually believe that the business is taking (the bulk of) the risk. In case of a chargeback, the business has to prove that I made the purchase, and a PIN is better evidence that I actually made it compared to just a signature.

This means that businesses might accept signature only for relatively low amounts. Indeed, it's not uncommon that neither is needed for amounts under a couple of lunches or so, to make lunch queues quicker. I assume the throughput is sometimes worth the risk.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: