Today, I have learnt why banks won't use cellphones the way ringtones are sold. While negotiating with several cellular operators, I have received the detailed protocol description. It's a security inferno. Unfortunately, the stuff is in Hungarian, but otherwise it would definitely merit a few comments on this blog.
The protocol leaves every involved party (except the cellular operator) exposed to fraud. Right now, I am thinking hard how to build something even remotely secure on its basis, but I was deeply disappointed today. No wonder banks are reluctant to deal with this heap of dirty hacks and kludge.