Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why not just use the card all the time then?


Because the phone is more secure using one time tokens instead of a semi permanent 16 digit number


I was assuming a chip and pin style card. These, as best as I can tell, seem to have most of the security of a phone-based solution, but with a much smaller attack surface (no internet connection, no cellular radio or baseband processor) and no need for recharging or carrying backup payment methods.


The chip on my cards is secure enough compared to a phone-generated token.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: