Replying to @dcuthbert @vanderaj
Banks in EU are solving a different problem, they want to ensure only account holder can get through the auth process, and if attacker makes it through, liability is on the account holder, not the bank. Frictionless means more transactions to offset loss from fraud borne by bank.
1
Still doesn't reflect the fact that these FaceID and future facial recognition is something you have (a very specific enrolled phone) and something you are (FaceID). They need to update their advice to match reality.
1
2
Replying to @vanderaj @dcuthbert
Doesn’t matter how secure it is. Contractually, the EU banks can hold their 2FA vendors accountable, and pass on the costs to their customers. EU banks can’t do the same with Apple.

Oct 17, 2018 · 7:32 PM UTC