July 7, 2015 By Douglas Bonderud 2 min read

No one likes passwords. Users complain they’re too cumbersome, easily forgettable and make logging into multiple endpoints a pain. IT security teams, meanwhile, struggle against user predilection to choose easily guessed, familiar password strings and then daisy-chain them across multiple accounts.

According to Naked Security, however, credit card giant MasterCard is rolling out a solution for online purchases over the next few months: pay-by-face, which would require a facial scan as confirmation for purchases. There’s huge interest here and big-time potential, but do selfies really fit the picture of perfect security?

Blink and You’ll Buy It

According to MasterCard’s Chief Product Security Officer Ajay Bhalla, “Passwords are a pain.” He argued that the potential security offered by passwords is consistently undermined by users: While they want personal data protected online, they’re not happy about memorizing multiple sets of login credentials or following complicated password rules. That’s the impetus for the company’s new facial scanning program for online purchases.

Here’s the idea: Using the MasterCard phone app, consumers will be able to pay for their purchases online. Before the transaction is complete, however, the app will ask for user approval in the form of either a fingerprint or facial scan. For fingerprints, users need only touch their screen. For facial recognition, they need to stare at the screen for a moment and then blink once. Bhalla believes that the “new generation” of buyers will embrace this selfie technology, and he might be right. On paper, this sounds like the ultimate form of multifactor authentication; users can’t exactly leave their face at home or forget how to blink.

A Password About-Face?

Not surprisingly, MasterCard’s new master plan has raised a number of security concerns. The first stems from worry over data collection: Does the app allow MasterCard to amass a huge library of consumer selfies and leverage them for unknown future purposes? As noted by The Hacker News, however, the PCI giant says that all facial scans will be digitally converted and then sent to their secure servers, leaving them with no way to reconstruct user profiles.

The second concern revolves around malicious use. Technology companies have been trying for years to make facial recognition an essential part of mobile device security, but so far, even the most advanced systems have proven easy to break. Static face scans, for example, were easily fooled by photographs, and Google’s 2012 initiative “Liveness Check” was tricked by using two photoshopped images that cycled between a user’s face with eyes closed and eyes open, DroidDog reported.

The FBI, meanwhile, has quietly been leveraging the Next Generation Identification (NGI) system developed by Lockheed Martin, which contains over 25 million mugshots. While MasterCard said there’s no way to reconstruct facial data and everything is securely stored on its servers, it has been quiet about any encryption technology. If malicious actors were able to steal this data and reverse the digital conversion procedure or trick the system with altered images, the results could be disastrous. Unlike passwords, there’s no way for users to reset their face.

Is pay-by-face perfectly posed take the purchasing world by storm? There’s a good chance users will appreciate the ease of taking a selfie instead of remembering complicated passwords. Long-term value, however, depends on the ability of MasterCard’s detection software to perform near-flawlessly and avoid the stigma of being two-faced when it comes to the storage of consumers’ personal data.

More from

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today