AnotherWorthlessBlog I Support NoCleanFeed

10Dec/093

Twitter creator develops ridiculous insecure stupid device…

Apparently the creator of Twitter has developed a mobile credit card solution that will be given away for free...

Ok... First let's go through the problems with this...

I'll start with security, because that's what I like. We've seen the multitude of Twitter failings in this area over the past 3 years of it's operation. Would I trust the same guy that developed Twitter with developing something that was going to read my credit card??? Fuck no...

Another problem, which leads back to security, the whole "given away for free" thing. Anything that is given away for free is usually of low quality. Take for example company pens, they're most often of very low quality, they're going to be given away for free and have very little direct impact on the business so why give a damn. I feel that this device will not have the budget it deserves and will end up being horrendously insecure.

Now my problems with the actual idea. Something that reads my credit card, ON SOMEONE ELSES PHONE... This person could have ANYTHING on the phone. It could have been hacked, they could be being malicious and attempting to steal card data. At least with the current POS terminals I have some re-assurance that the firmware isn't emailing all my card data to some Russian who's going to go out and enjoy some nice Vodka on me tonight. Of course ultimately it'll be on the bank but that's another story.

Recent history is shown that smartphones are all the rage for hackers these days and that they're fast becoming the target of all types of nasties. This just gives more incentive to an already developing field. Props to you for the idea of having a device that reads a card and sends the data over the microphone port of a smartphone to ultimately be decoded by software but WHAT THE HELL... A smartphone is probably one of the most UNTRUSTED end-points ever... I'd prefer to trust my computers back in Wangaratta that my siblings have filled with malware than trust some random coffee shop owners smart phone with my card data.

And it's blatantly obvious that this doesn't support smart card tech. Which annoys the hell out of me. Why are we still developing end solutions for mag stripes??? Mag stripes in access control went out the window ages ago, why the hell are we still using it for processing payment data.

This device is useless.

Merchants already have access to terminals that work over 3G/GPRS data networks and something like credit cards should never be processed through someones personal smartphone that they just installed the lovely furry kitty screensaver on that is just waiting for something nice and juicy like a credit card to pass through the system.

I'm sorry but Jack Dorsey, do us all a favor, and stick to micro blogging... And stay the hell away from my credit cards...

SOURCE : http://edition.cnn.com/2009/TECH/ptech/12/09/twitter.dorsey.credit.card/