The credit card payment system appears completely silly to me.
To make a payment with a credit card online, one must give the store all the details required for it to make an unlimited number of charges to your credit card.
When all they need to know is how to tell the credit card company that they are suuposed to give them a certain amount of money and charge it to the buyer's account.
This could be done extremely easily with public/private key cryptography and would be much more difficult to defraud.
Basically it goes:
1. I recieve an invoice from the supplier
2. I sign the invoice with my private key supplied by the credit card company
3. I send the signed invoice back to the supplier who verifies that I signed it by using my public key.
4. The supplier sends the signed invoice to the credit card company
5. The credit card company verifies that the invoice was signed by me, pays the supplier and charges my account.
6. supplier sends me product.
This still has issues i.e if someone stole my private key they could make charges to my account.
But it's both better than the current written signature or no signature that credit cards currently have as the actually information that identifies you uniquely isn't being sent to lots of other people.
Just a thought.
- Jessta
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment