How facial and palm recognition terminals work and what they mean for your privacy

Australians will soon be able to pay for coffee, shop, and earn loyalty points using nothing more than their face or hands, but a cybersecurity expert warns the risk to consumers’ privacy is “uniquely dangerous” if biometric data is hacked or stolen.
Eftpos operator Verifone has introduced new payment terminals embedded with biometric technology that can facilitate transactions at the checkout through facial and palm vein recognition.
The new suite of payment terminals, called Victa, contain two cameras: one to capture a photo of customers that is converted into a biometric ‘token’ and matched with the customer’s identity, and another infrared camera for palm vein detection.
“We see this as a new way to pay, complementary to what people already know today,” said Verifone head of product Ben Hughes. “This is a way that you would be able to identify someone at the point of sale.”
Customers are required to opt in for the biometric payment method, which sits alongside existing payment options like tap-and-go. Merchants that choose to adopt the new terminals, such as retailers or fast food companies, would provide their customers with an enrolment process (typically through an existing smartphone app) where customers take a photo of their face to create a biometric profile that is linked to their payment details or loyalty program.
At the point of sale, enrolled customers select the biometric option and present their face or palm to the camera at the terminal, which is matched to their profile for the transaction to be approved.
Verifone Asia Pacific president Paris Tsounias touted the new technology as simplifying the checkout process and reducing friction for consumers signing up to or verifying membership to loyalty programs by bypassing details like mobile numbers and email addresses.
“In the future, I won’t have to remember any of those details. [The retailer] would have me registered, and my biometric profile will be there. As soon as I walk up to the checkout, it will know it’s [me],” said Tsounias.
“It might have nothing to do with payment at all, but it might be a way to identify a consumer coming into your store.”
Australia is the second market to roll out the new payment terminals after Victa was launched in New Zealand last week.
Verifone has not yet signed any banking or vendor partners in either country, but Hughes said the company was in discussions with a number of fast food chains, supermarkets, retailers with large loyalty programs, and operators in the health industry. It is currently running a small pilot in the US with a fast food kiosk, but Hughes declined to provide further details.
The global payments technology giant does not retain images of consumers, but scans the face in real time and matches it up with the biometric profile uploaded by the user, shifting the data risk from Verifone to the merchant partner.
Biometric data on iPhones and Androids, used to unlock phones, apps and authorise payments, stay on the user’s physical device and is not shared with Apple, Google, or in the cloud, meaning Verifone’s terminal-based hardware transfers this data from consumers’ devices to a third party.
Cyberspace and data policy expert and former Australian Privacy Foundation chair David Vaile described biometric facial recognition as “intrinsically imperfect” and said consumers were being asked to place an enormous amount of trust in Verifone at a time when no company could guarantee immunity from data breaches and AI can rapidly manipulate or exploit personal data.
“Biometric is a uniquely dangerous identifier, unlike say a driver’s license or a social security or credit card,” Vaile said.
“If something goes wrong – the algorithm that does the training is hacked, or the data store is hacked – you can’t revoke it … You are stuck with that biometric basically for your lifetime.”
The user’s biometric profile is held by the merchant, bank or digital wallet, not Verifone, which Vaile said was “very convenient” for the global payments technology giant.
“They’ve already insulated themselves from the most direct business relationship with the person most likely to suffer the harm,” he said.
“Being realistic, it’s hard to assess the full level of [risk],” Vaile said. “This has alarm bells ringing at every level.”
Hughes hailed the opt-in biometric payment option as fully compliant with the Australian Privacy Act and an “even more secure way of identifying a person”.
Tsounias said that dual authentication processes would continue to evolve, but conceded that they hadn’t yet “worked out all the nuts and bolts of it” as it was new technology being introduced to the market.
“We see this as the next evolution of what that would look like moving forward in terms of payments in the future.”
The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.
