Feeds

PayPal's fizzog-based payments app rubbished over reliability worries

'What if the shop assistant's an idiot?' asks security bod

Build a business case: developing custom apps

Shop assistants may be too thick to guarantee the security of Paypal's new real-world payment system, a leading security bod has cautioned.

PayPal is currently trialling a new system that allows shoppers in the London suburb of Richmond to pay for stuff using their ugly mugs.

Customers can pay for goods using their pocket fondleslab, as long as a shop assistant verifies their identity from a photograph.

But Andy Kemshall, co-founder and technical director of two-step authentication specialists SecurEnvoy, warned that the system could be fallible.

He said: "Using face recognition to authenticate quick and convenient payments in shops and cafes seems ideal in our ever-busy lives. However I have serious doubts about the security of this method.

"The completion of the transaction relies on the shop assistant verifying the customer’s face – certainly a risky method of authentication that could easily be subject to human error, be it accidental or deliberate. Using mobile phones to authenticate processes such as payments is the way forward. However, face recognition technology, as it stands, is nowhere near sophisticated enough to act as a reliable method."

Kemshall said that security systems needed to be "99.9 per cent perfect, at the very least" and claimed that biometrics did not yet offer this level of reliability.

He added: "Using manual face recognition, in the way exhibited by Paypal to authenticate payment in store, is a clear case of running before you can walk.”

Some 12 shops in the Richmond area are trialling the system, but PayPal hopes to roll the new system out to 2,000 shops by the end of 2013.

Rob Harper, head of retail services at PayPal, said: "This is another step on the journey towards a wallet-less high street, where customers will be able to leave their wallet or purse at home and pay using their phone or tablet. We predict that by 2016 this will become a reality." ®

Boost IT visibility and business value

More from The Register

next story
KDE releases ice-cream coloured Plasma 5 just in time for summer
Melty but refreshing - popular rival to Mint's Cinnamon's still a work in progress
Leaked Windows Phone 8.1 Update specs tease details of Nokia's next mobes
New screen sizes, dual SIMs, voice over LTE, and more
Mozilla keeps its Beard, hopes anti-gay marriage troubles are now over
Plenty on new CEO's todo list – starting with Firefox's slipping grasp
Apple: We'll unleash OS X Yosemite beta on the MASSES on 24 July
Starting today, regular fanbois will be guinea pigs, it tells Reg
Another day, another Firefox: Version 31 is upon us ALREADY
Web devs, Mozilla really wants you to like this one
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Cloudy CoreOS Linux distro declares itself production-ready
Lightweight, container-happy Linux gets first Stable release
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Maximize storage efficiency across the enterprise
The HP StoreOnce backup solution offers highly flexible, centrally managed, and highly efficient data protection for any enterprise.