I was under the impression it was because "the people" moaned when they were tricked into making transfers to wrong people, or mis-typing account details.
How would sending a security code prevent that?
I was under the impression it was because "the people" moaned when they were tricked into making transfers to wrong people, or mis-typing account details.
That one would have been solved far more simply by adding some check digits to the account number.
The problem with QR codes on phones is the high failure rate in scanning. I have worked in the entertainment business scanning e-tickets on phones and depending on the scanner used and reflections caused by lighting it is pretty hit and miss. (Event tickets aren't normally mobile specific so are all "e" tickets before somebody gets pedantic about it)This is really a subject for a different forum, let alone a different thread! However, there are two issues that can occur here.
Fraud when the customers security credentials are compromised, or when the customer is conned into making a totally bogus payment is the most serious. That's why most banks will add extra security, particularly for a new payment.
There is a second danger and that is because banks don't yet automatically check the name on the receiving account agrees with the account number and sort code details quoted. Bletchleyite is correct that check numbers should be used. Most banks originally had two such digits in their account numbers. Combined with multiple sort codes that prevented most clerical errors and most incorrectly made payments were rejected at the receiving end as they'd gone to an invalid account number. More recently some newer banks may have used only one check digit and far fewer sort codes, thereby making a simple clerical transposition more likely to direct a payment to a valid and active account number.
In the railway context my biggest concerns are how easily, quickly and diligently electronic tickets can be scanned when requested. On my last two journeys the phone was looked at, but the QR code was not scanned. I doubt the journey details could have been read in the time and at that distance either. If that becomes regular practice any ticket might do - but it has to be validated for that day to produce a visible QR code.