Live data from Hacker News

Apple unveils contactless payments via Tap to Pay on iPhone

apple.com

351–360 of 736 posts

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#351
post #218

Earlier quoted context omitted.

And the numbers themselves that can be entered manually. 5 payment modalities with a thin piece of plastic.

And what really make this a 5th modality is the required CVV (card verification value) printed on the backside of the card.

From what I know is CVV isn't required if the card is presented in person. The card processor will revoke your agreement if you verify the card is present and it's actually not however.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#352

Earlier quoted context omitted.

It’d be trivial for a rogue payment app to display one $ amount on the screen yet deduct another.

Display the $ amount on which device though? If you want to be secure, you display it on the customer's iPhone and have them confirm. Either way though, this is different from skimming. Skimming allows the skimmer to make future transactions which is much much worse.

Absolutely agree, it ought to be displayed and then consented to based on that knowledge.

Right now with most contactless in shops in the UK you're left thinking "did they key that amount in right?" and if you're paranoid you ask for a receipt (from the machine, although merchants often drag their feet or try to give you one from the till not the reader!) and/or you check on the phone afterwards (which would be a pain if it showed an issue because by then it's a bit late!)

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#353

Earlier quoted context omitted.

I can’t speak for America but in the U.K. there have been terminals that do this that small independent businesses have used for years. They connect to your phone too and work with both Android and iOS. You see taxis, street food sellers and all sorts using them. They also cheap and yet still look a hell of a lot more professional than this thing does. https://merchantmachine.co.uk/contactless/ Note that some of thes…

Sorry, by ”this thing”, do you mean an iPhone? That it looks less professional to use a phone than a dedicated card reader? I can see it, I was just genuinely a little thrown by the wording.

Sorry yeah. I don’t know why I shouldn’t trust tapping on someone’s iPhone but it doesn’t scream “professional shop” in the same way that those card readers do. Even though those card readers are very cheap and ostensibly work the same, they just feel more “professional”.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#354

Hacker News is such a bizarre place. On the one hand, we have threads about how browsers are fingerprintable and some app is using telemetry and endless discussions on theoretical zero-knowledge protocols and the importance of cryptography and Snowden saying this and that that get voted up to the top. On the other hand, something like this comes up which is basically another step along the "no-one accepts cash" funne…

How long before some stores don't accept cash? How long before banks do a background check (taking weeks) before giving you cash?

Most Airlines quit accepting cash for on board purchases. "For our convenience"

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#355
post #177

Question for anyone in the know at Stripe ... does this make a iPhone work like the existing BBPOS WisePOS terminals and able to interact with a web app _without_ any code running on the phone itself (other than Stripe's) Or is it more akin to the BBPOS Chipper readers and still needs a custom mobile app to interact with? ie: can a platform built on Stripe use this for their customers without needing to supply a mobi…

Correct me if I'm way off, but when Apple launched it, iPhones had a separate secure element with applets that use keys stored in slots, very similar to chip/pin cards. The protocols for payments (EMV standards) all used symmetric keys, and so any issuer who wants to be a part of Apple Pay needs Apple to get a key into their SE.

It's possible to do this through a process called "personalization," where in general, a secure element has "initialization" keys that are installed at manufacture, but then the keys get updated (personalized) once the user gets it.

I'd speculate that Stripe could get integrated using a personalization protocol, with new keys over the existing protocols, and not require its own intitialization keys in the SE. A further speculation would be that Apple's pay partnership with GS may have facilitated a different protocol that uses more manageable asymmetric keys for doing reconciliations, and all the complexity is in integrating with generic payment terminals, whereas for anything that doesn't depend on that, you can use more sensible protocols that aren't freighted with backward compatability to chip/pin cards.

Square would probably be the easier integration, but Stripe may have some secret sauce for this. Anyway, wildly speculative, and would be interested what's way off in that.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#356
Outside of USA, where most people don't have an iPhone, I don't really see the point.. It would be more usefull with ipads or any less personal device : If the shop's owner haves an iPhone accepting paiement but it's an employee doing the paiements, the shop opwner has to give his personal phone to the employee to accept paiement ? Or he needs to buy an other iPhone with no personal data and accepting paiement (is it even possible ? ) to give the employee ? .. and now it's already more expensive than a simple contactless paiement machine.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#357
post #330

Earlier quoted context omitted.

Harder for whom? The attack vector here isn't "hackers compromised everyone and can correlate your data", it's "Visa knows everything about you". I agree with the GP, this is a huge privacy blind spot.

> The attack vector here isn't There are multiple attack vectors. One of them is "why did I just get another charge from that place we visited last June". Another being "oops, we plugged our pin into a skimmer", etc. Agree that letting Visa/MC/whomever know everything about your transactions is a choice... Otoh if they pay you 3ish % for it, you might decide you're more than happy to.

I have half a mind to make a debit card that lets you whitelist merchants. You use the same card everywhere, but unless the merchant is in the whitelist, the charge fails. Also, you can set limits and rules.

Basically like privacy.com, but why use a new card per merchant?

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#358
post #320

Earlier quoted context omitted.

Only one of my cards actually has raised numbers and its about to expire, so will probably get a completely flat one that replaces it as well. 2 of my cards are tap only, the mag stripe is gone - they are also store-specific cards, so that might have something to do with it. Master card said they will start phasing out mag strip in 2024. Soon enough tap/dip will be the only way.

Yeah, here in Canada the magstrip has all but gone the way of the dodo - it's chip-and-pin or tap everywhere here. IIRC vendors here stopped taking magstrips before the Americans even. Cards still have magstrips on them but I can't remember the last time one got used. Maybe a gas station.

Same in Aus. I think banking innovation like this is way easier in smaller countries like australia because there’s way fewer banks. The USA has hundreds of banks - so getting them to all agree on a standard is near impossible. It’s no wonder America still uses ACH and cheques.

Australia has just 6 banks. And they have a history of collaborating on things like this - since a fluid economy raises all boats, and fraud hurts them all. All Australian cards and point of sale systems support chips and taps. And have for nearly a decade.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#359

Earlier quoted context omitted.

Paying with your phone is actually more secure than the old mag-swipe method. Your phone will tokenize your credit card information, which makes it significantly harder to track credit card usage across various merchants. Of course it isn't as private as cash, but it is a step forward from mag-swipe. Square has a good explainer if you want to read more: https://squareup.com/us/en/townsquare/what-does-tokenization...

Apple Pay only tokenizes card information once when the card is added to the Apple Wallet on a device, not for every transaction. This means that usage for an on-device tokenized card can still be tracked until the card is removed and re-added.

I believe while the token is generated once, each transaction is signed with a unique signature (I believe that's the term) that only the payment processor can decipher. The merchant doesn't get any stable/identifiable information that can be used to track you across purchases/sessions/stores.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#360
post #326

Earlier quoted context omitted.

> Swiping pressure-sensitive paper over the raised numbers (the original method) is still possible I've seen this still happen occasionally in taxis - or rather I saw it happen within the past decade. When I last lived in the states I'd bump into it especially with rural taxis - I assume it's dying quickly though because it's incredibly inconvenient when compared to paying via an app or tapping. The lack of raised di…

Cards are slowly moving towards not having printed numbers at all, and having the numbers only available via the issuer's app or website. This allows for rotating numbers.

Rotating numbers are still extremely viable with fixed card numbers - it's possible to issue a set of semi-permenant printed numbers and also offer a tool that can issue additional digits for untrustworthy retailers or strange one-off payments. The removal of digits from the card itself is a cost being levied on the customer and it provides no real benefit.
Post reply on HN