Skip to main content

Opinion

One device for everything can quietly erode payment security

For this month's blog, I decided to explore how Two Factor Authentication (2FA) has been steadily undermined by the fact that so many of us are authenticating ourselves and purchasing goods and services, all on the same handset, in the same session. Tap to Authenticate, with a possible further Step Up to tapping in your payment card's PIN code, looks like a great way to restore 2FA for mobile-only commerce. Let's explore.

More of us are buying on our phones, and the numbers have stopped being marginal. Adobe research found that smartphones handle 56.4% of all online transactions across the 2025 US holiday season, up from 54.5% in the same period the year before. In the UK, Adobe had mobile-only commerce at 61.5% of online holiday revenue, worth around £16.5bn. Among the under-30s, the tilt is sharper still: Retail Economics' "Shades of Z" points to a clear majority who would rather shop on their phone than on any other screen.

So, for a growing share of people, the younger ones especially, discovery, comparison, authentication and payment now all happen on the same device, in the same session, often within the same minute, the convenience is real. However, it quietly undermines an assumption payment security has leaned on for years.

Two factors on one device aren't really two factors

Strong authentication works by combining factors that are meant to fail independently: something you have, something you know, something you are. Independence is the whole point. The rules behind Strong Customer Authentication are explicit that compromising one element must not compromise the others.

The familiar mobile flow breaks that principle. You buy in one app, then approve in your banking app, all on the same handset. The moment that single device is lost, stolen or compromised, both 'factors' go with it. You no longer have two independent factors. You have one device wearing two hats. Call it one-and-a-half-factor authentication.

This isn't theoretical. The Office for National Statistics recorded 272,000 mobile phone thefts in England and Wales in the year to March 2025, up roughly 16% on the year before. A growing share follow a now-familiar pattern: a thief watches the owner type in their passcode, then steals the phone, and with it, every app and every approval living inside it.

Biometrics and passkeys prove the device, not the person

The instinctive reply is "but my phone uses my face or fingerprint." It's a weaker answer than it sounds. Biometrics and passkeys are very good at proving which device is being used. They are far weaker at proving which person is using it.

Consider how people actually live with their phones. Apple's Touch ID stores up to five fingerprints, and nothing stops those five belonging to five different people; Face ID lets you register an alternate appearance as well. These features exist precisely because we share our devices: a partner who can unlock it, a child who needs it for a game. So, an on-device biometric just confirms the handset is genuine and unlocked.

However, it does not confirm that the account holder is the person tapping "buy". Passkeys, FIDO and on-device biometrics, for all their strength against phishing, share this blind spot. The phone proves "what". It struggles to prove "who".

The older fixes are weaker still. SMS one-time passwords were never robust: SIM-swap attacks and network interception have drained real accounts for years. In addition, because the hijacked number is usually a stepping stone to the actual theft rather than the theft itself, the headline fraud figures understate the problem. In-app approval is an improvement, but on the same handset, it remains one device doing both jobs.

Friction isn't the enemy – misplaced friction is

None of this argues for slowing everyone down. The overwhelming majority of payments are low-value and low-risk, and they should stay frictionless; that is exactly what good risk-based authentication is for. The case is narrower, and harder to argue with: when something looks anomalous — an unusual amount, a new payee, a change to account details, it is reasonable to ask for more. The question is what more should be. If the extra step lives on the same phone, you haven't added a factor. You've added a tap.

Bringing the second factor back

One practical answer is already in most people's pockets: the physical bank card. Ask the customer to tap their card to the back of the phone for a higher-risk action, and the issuer can verify a genuine EMV cryptogram from the real card — a one-time value that can't be copied, dynamically linked to that specific transaction, rather than static data lifted from a screen.

That reintroduces a true something-you-have: a separate physical object the compromised device cannot conjure on its own. Add the card's PIN — something-you-know — and you are back to genuine multi-factor authentication for the transactions that warrant it.

This is no longer a thought experiment. Visa's Chip Authenticate service, now live with launch partners and expanding through 2026, does exactly this. The cardholder taps their card to the phone via the issuer's app to confirm higher-risk events: password changes, high-value transfers, limit changes, in place of an SMS code. Other networks are moving the same way.

It is not a cure-all, and it would be a mistake to pretend otherwise. If a device is riddled with malware, or the user is socially engineered into tapping, possession of the card helps less, and device-integrity controls still matter. However, for the large class of risk events driven by stolen credentials rather than a stolen handset, proving the genuine card is present is a real step up from 'approve on the same phone'.

Why the card may not disappear

There's a longer arc here too. We tend to think of a card as a way to pay, and assume that as wallets and tokens take over, the plastic simply fades away. Tokenisation is certainly accelerating: Visa has now issued well over 13 billion network tokens and reckons around half of its global e-commerce is tokenised, with Mastercard on a similar path.

But notice what tokenisation actually does: it abstracts the card's payment role into software. What it doesn't replace is the card's other, quieter function: a cryptographically secure identity token you can hold in your hand. As the payment credential dissolves into tokens, that second role becomes relatively more valuable, not less. It's a reason the physical card may earn its place for longer than the 'cards are dying' story assumes — not as a way to pay, but as a way to prove it's really you paying.

This is the challenge we spend our time on at Mypinpad: how everyday devices can carry secure PIN entry and authentication without extra hardware, so a step-up like this can happen on the phone someone already has.

The move to mobile-first buying is real, and welcomed. The job now is to make sure the convenience doesn't quietly cost us a factor. For most payments, keep it frictionless. For the risky ones, let's prove it's really you — not just your phone.

Where do you land? Is a deliberate, occasional step-up worth it, or is the market too committed to the single-tap journey to tolerate that additional authentication request?

Talk to Us

Ready to explore what Mypinpad can do for you?

Certified. Independent. Deployed across 28 countries. Let's talk about your use case.

Get in Touch