> Isn't allowing the user to opt to just bypass the PIN a bit of a security hole?
That's a valid point of view, but I actually believe that the business is taking (the bulk of) the risk. In case of a chargeback, the business has to prove that I made the purchase, and a PIN is better evidence that I actually made it compared to just a signature.
This means that businesses might accept signature only for relatively low amounts. Indeed, it's not uncommon that neither is needed for amounts under a couple of lunches or so, to make lunch queues quicker. I assume the throughput is sometimes worth the risk.
That's a valid point of view, but I actually believe that the business is taking (the bulk of) the risk. In case of a chargeback, the business has to prove that I made the purchase, and a PIN is better evidence that I actually made it compared to just a signature.
This means that businesses might accept signature only for relatively low amounts. Indeed, it's not uncommon that neither is needed for amounts under a couple of lunches or so, to make lunch queues quicker. I assume the throughput is sometimes worth the risk.