This is page 2 of:
One Payment App Uses Often-Called Friends To Authenticate. (Privacy? What’s That?)
When a customer changes elements of those attributes—perhaps by upgrading the OS or deleting no longer needed applications—the system guesses whether those changes make sense. A customer upgrading the mobile OS, for example, would not be a fraud trigger nearly as much as that customer downgrading the mobile OS, Kleitsch said. “It’s all about weighing the attributes,” de los Reyes said.
If the Buck system suspects that the phone trying to make the purchase is not the phone that signed up for the service, it can prompt for secondary authentication, such as by asking for a CVV or a ZIP Code, de los Reyes said. Each retailer can also set its own security triggers—such as a number of purchases or a dollar amount, within a set timeframe—and Buck has its own fraud triggers on top of those. “It watches for an excessive number of transactions. If all of a sudden we see 10 transactions all within 30 minutes,” the system will either ask for more information, shut down the use of the payment card on file or even shut down the entire application, de los Reyes said.
With all of those mechanisms in place, Kleitsch argues, the single-click payment from the Buck app is reasonably secure. Indeed, it’s optimally secure given the nascent nature of the mobile payment market and the need to make the transactions as effortless as possible for consumers. Slow down the process too much—such as by insisting on a PIN—and risk consumers avoiding the mobile transactions entirely. Once consumers are used to and comfortable with mobile transactions, additional security can be added.
The only problem: Who will pay the cost of fraudulent transactions during the initial phase? The most likely hole is when consumers using this app misplace their phones or have those phones stolen. Given that the phone will be authenticated, some bad transactions will proceed before the various excessive-use fraud triggers (or the user disables the phone and cancels the associated payment cards) kick in and end the thefts.
As those decisions are debated among the brands, issuers and processors, apps such as those from Buck are going to look attractive from a market growth perspective but less so from a risk perspective. And yes, the chances are that retailers will end up footing the bill for the experimentation—and pocketing the profits if it all works.