India recently launched a payment system where merchants install an app on an Android phone, and connects a fingerprint reader it.
Clients provide their Aadhaar number (like a national identity number), and scan their finger to authorize transactions which debit money from their account.
Is this a relatively secure system, compared to say chip and PIN cards?
I believe it would be possible to capture the users fingerprint using something to intercept the communication between the fingerprint reader and phone, and then replay the recorded fingerprint along with the Aadhaar number (which may be captured with a keylogger or even memorized by the merchant).
Is this fear justified?