Banks in EU are solving a different problem, they want to ensure only account holder can get through the auth process, and if attacker makes it through, liability is on the account holder, not the bank. Frictionless means more transactions to offset loss from fraud borne by bank.
1
Still doesn't reflect the fact that these FaceID and future facial recognition is something you have (a very specific enrolled phone) and something you are (FaceID). They need to update their advice to match reality.
1
2
That’s it! Same reason there isn’t chip-and-pin in US, shifts liability from merchant to bank. With chip-and-sign, liability is with the merchant.
Oct 17, 2018 · 8:42 PM UTC
2

