Starting from 2030, Mastercard will no longer require Europeans to enter their card numbers manually when checking out online – no matter what platform or device they’re using. Mastercard will announce Tuesday in a fireside chat with CNBC that, by 2030, all cards it issues on its network in Europe will be tokenized. In other words, instead of the 16-digit card number we’re all accustomed to using for transactions, this will be replaced with a randomly generated “token.”

The firm says it’s been working with banks, fintechs, merchants and other partners to phase out manual card entry for e-commerce by 2030 in Europe, in favor of a one-click button across all online platforms. This will ensure that consumers’ cards are secure against fraud attempts, Mastercard says. Users won’t have to keep entering passwords every time they try to make a payment, as Mastercard is introducing passkeys that replace passwords.

56 points

Consumers will be able to make one-click payments at the checkout page using biometric authentication with a thumbprint

That’s a nope from me, dog.

permalink
report
reply
8 points

My PC doesn’t even have a microphone.

permalink
report
parent
reply
4 points

This is likely something like a FIDO token/passwordless setup of some sort (i.e. Windows Hello).

The thumbprint would just unlock the hardware device, so the thumbprint itself wouldn’t need to be transmitted to your credit issuer. This gives you full two factor authentication of your identity because you need the hardware device (something you have) and your biometric (something you are). They also often allow pins (something you know) instead of biometrics as the second factor.

permalink
report
parent
reply
43 points

Yeah, I’m not giving them biometrics. There had better be an alternative option.

permalink
report
reply
17 points

The first thing I thought was “what’s the alternative?” If I don’t do biometrics on my phone then why would I do it for my credit card? I’m American so I don’t have to worry about this yet but it’s probably an indicator of what’s coming here.

permalink
report
parent
reply
2 points

It’d be cool if they had a yubikey integration or some other hardware based solution where you must physically present it.

permalink
report
parent
reply
1 point

I might be wrong, but I think they will probably let the OS handle the biometrics offline, which means that they won’t have access to your biometrics, they just work with cryptographic keys. Otherwise it doesn’t make sense, as apps usually don’t have direct access to the fingerprint reader. It will probably be similar to how a passkey works.

permalink
report
parent
reply
8 points
*

Sure. Because “working with banks, fintechs, merchants” was a swift friendly collaboration when moving to chip and PIN…

(/sarcasm … Because it was not.)

I’m pressing X to ‘doubt’ on this one.

Edit: I’m American. It’s a good point that Europe has historically done a much better job with payment security.

permalink
report
reply
11 points

In Europe it was relatively smooth though, in my experience. I worked in a shop when it was rolled out. I’m guessing you’re American?

permalink
report
parent
reply
3 points

Good guess.

permalink
report
parent
reply
10 points

Your banking systems are two decades behind everyone else. Please rejoin this thread in 2044 thanks 😂

permalink
report
parent
reply
5 points
*

no more custom roms if you want to actually pay for stuff. awesome.

permalink
report
reply
5 points
*

Interesting but I just memorized my card numbers. It’s incredibly convenient and I recommend everyone to do it.

This might improve security though, because instead of using the same numbers everywhere you use different tokens everywhere.

It would be cool if computers could use their smart card readers (Chip and NFC) to pay stuff online.

permalink
report
reply

Cybersecurity

!cybersecurity@sh.itjust.works

Create post

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Community stats

  • 1.8K

    Monthly active users

  • 1.5K

    Posts

  • 3.3K

    Comments