POS payments have a trust problem
Have you ever realized that every payment at a POS asks you to trust a machine you have never seen before? You hold out your card or phone, the terminal beeps, and money leaves your account. How much? For what? To whom? Most of the time you take the shop’s word for it. That is not how a payment should work. Here are three ways the terminal on the counter asks for trust it has not earned.
1. Terminals without a screen
Tap-to-pay readers are getting smaller, and the first thing to go was the display. A little puck with a light on it, or a phone the cashier keeps in their hand. You tap, it flashes green, done. You have no idea what amount was just charged. You will find out when you check your bank app later, if you check at all.
2. Your PIN on a stranger’s device
Above a certain amount you are asked to enter your PIN. On what? A terminal owned by a shop, leased from a company you have never heard of, running software nobody at the counter can explain. You have no way of knowing whether it has been tampered with, whether it is even a real terminal, or who else sees the keys you press.
3. Screens you cannot read
Many terminals in use today are years old. The display is scratched, the backlight is dim, the amount is shown in small grey digits and you have to tap your card on top of it. Ask an older customer, or anyone standing in bright sunlight at a market stall, whether they can actually read what they are about to pay. Often they cannot, and they tap anyway, because the queue is waiting.
This will blow up
Put those three problems together and add one more fact: a payment terminal is a computer. It runs software, it is connected to the internet, and it is updated remotely by whoever leased it to the shop. There are millions of them, and most of them are identical: the same model, the same software, the same weaknesses.
That is exactly what viruses love. They do not need to break into a hundred thousand shops one by one. They need one hole in one terminal model, and the terminals’ own update mechanism does the rest.
This is not science-fiction. In 2013, malware installed on the checkout terminals of Target quietly collected the card details of some 40 million customers over a few weeks. Home Depot followed a year later with 56 million customers. The terminals kept working perfectly. Nobody in the shop noticed a thing. The only sign was, months later, on the customers’ bank statements. The damages: hundreds of millions of dollars.
Every time this happens, banks have to block thousands of accounts, and the terminals along with them. Overnight, all those card readers become bricks and people are shut out of their accounts. And the next time you are asked to tap on a screenless reader or type your PIN into an old terminal, you will hesitate. You will want to check all the numbers. Everyone does. That hesitation can eventually become the end of POS as we know it. Not because the machines stop working (they will get patched), but because trust is gone.
AI will accelerate this
And this is only the beginning. Where finding a hole in a piece of software used to take a skilled team months of work, AI now does it in hours, for anyone who asks, and it gets better at it every year. Combine millions of identical, internet-connected terminals with a tool that hunts for weaknesses tirelessly and almost for free, and we are no longer wondering if disaster strikes. We are waiting for the next one, and dreading how big it will be and how many people it will hit.
The solution
The fix is not a better terminal, nor expensive fraud insurance. The fix is in the trust model. Stop asking the customer to trust hardware that isn’t theirs.
With a QR payment, the customer scans a code and the payment opens in their own banking app, on their own phone, on a screen they know how to read. The amount and the recipient are shown in large, clear text before anything happens. The PIN or fingerprint goes into the device they already trust with their entire bank account, and nowhere else. Nothing is typed into, or shown on, equipment belonging to someone else.
- You see the exact amount before you confirm
- You see who is receiving the money
- You authorise it in your own bank’s app, not on a stranger’s device
That is what a payment should feel like: no leap of faith, no squinting, no secrets shared. Ask your bank for EPC QR payments, and if you run a shop, you can make the switch today.