Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Kaspersky Comment: Palm scanner launched for ’secure payments’

September 2020 by David Emm, Principal security Researcher at Kaspersky

Following the news that ’Amazon has announced a new payment system for real-world shops’, the comment below from David Emm, Principal Security Researcher at Kaspersky.

“The new Amazon One payment sounds very convenient: you just hold your palm above the reader and it charges your card automatically – no swiping, no PIN, nothing. But to do this, they’re taking biometric data - in this case, a palm - and storing it in the cloud correlated with payment data. Amazon says the data will be encrypted. If we want to bring on the future securely, we must ensure it’s well encrypted, because Amazon One combines identification, authentication and authorisation into a single point. If someone were to steal and decrypt the data from the cloud they could potentially spoof someone’s identity and spend their money.”

The key lies in how the data is being encrypted and stored. Where identification and authentication are separate, for example where a biometric is used to identify you and a PIN is used to verify that identity, anyone stealing the biometric data wouldn’t have a complete set of information or enough to steal people’s money. But in the case of Amazon One, they would have everything they need.
Much safer to keep the two thing separate - biometric data to identify you and something else (such as a PIN) for authentication.”


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts