SET (Safe Electronic Transaction) Was: 3D Secure++ for Push Payments

From: Anders Rundgren <anders.rundgren.net@gmail.com>
Date: Fri, 27 Jun 2014 16:14:13 +0200
Message-ID: <53AD7C35.2090800@gmail.com>
To: Adrian Hope-Bailie <adrian@hopebailie.com>
CC: Web Payments CG <public-webpayments@w3.org>
On 2014-06-27 15:08, Adrian Hope-Bailie wrote:
> p.s. It just occurred to me that your protocol is quit similar to what VISA and MasterCard tried to do with SET (as I understand SET).

That's right!  Being an old fart I actually tried SET 1998 since Swedish banks were one of the first to launch it.

The SET "business process" description is quite good:

> I think it was probably ahead of its time and might have been more successful today.

It was a very ambitious effort requiring a (for that time) advanced pretty fat browser plugin/wallet.
Regarding successful today, EMV cards remain unusable on the Internet.

Gemalto is trying though: http://opoto.github.io/secure-element
I find this approach pretty much at odds with how the web works.

Some people claim the the "final solution" will be unveiled at:

We'll see about that.  Personally, I believe mobile devices will perform this task (device = holds a bunch of embedded credentials).
Then you get away from cards, readers, third-party middleware and APIs designed like 20 years ago.

Unfortunately most things in this space is NDA-protected including the Google Wallet and ARM's TrustZone.

> I couldn't find anything online other than a wikipedia article about SET but it looks like almost everything is still available via the internet archive:
> http://web.archive.org/web/20020802134102/http://www.setco.org/

Thank you very much.  I must have had that old spec. somewhere in my head when I did this writeup!

Mixing the two failed predecessors (3D Secure and SET) will surely create DOUBLE EPIC FAILURE :-) :-)


