Live data from Hacker News

Apple unveils contactless payments via Tap to Pay on iPhone

apple.com

501–510 of 736 posts

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#501
post #466

Earlier quoted context omitted.

Contactless bank cards were widespread in the UK before Apple or Google had their own payment systems. I think the "real story", as it were, is that the banking industry held contactless payments way more than Apple ever did.

Right, and with the advent of NFC in phones, US consumers didn't need the banks' permission to pay contactlessly. Despite this, contactless payment adoption was still slow in the U.S. even though most phones had NFC, it wasn't critical mass until Apple finally decided to support NFC technology.

I would argue it was a myriad of factors. Here in NY the adoption of OMNY and the pandemic contributed far more than Apple rolling out Tap to pay. The biggest issue being merchants lacking having the motivation to move away from outdated readers.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#503
post #411

Earlier quoted context omitted.

I had no idea if the magnetic stripe on my (australian) credit card worked until a recent trip to the USA. I’ve had that card for years and I don’t think I’ve ever swiped it before. Australian POS terminals won’t let you use the magnetic strip on a card when chip & pin is available. Even inserting your card seems old fashioned now - PayPass (contactless payment) is by far the most common way to pay in australia. Each…

I'm far more likely to have my wallet on me than my phone. Credit cards have infinite battery life, 100% waterproofing, no real-time tracking/spying and low to no cost to lose. Cash trades out the low cost to lose for anonymity.

> no real-time tracking/spying

You'll want a Faraday cage for any contactless cards.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#504

Earlier quoted context omitted.

And what really make this a 5th modality is the required CVV (card verification value) printed on the backside of the card.

From what I know is CVV isn't required if the card is presented in person. The card processor will revoke your agreement if you verify the card is present and it's actually not however.

Which is why I have a habit of removing the cvv from the card(scratching the numbers off) and just remember those 3 digits like an extra pin. This practice is becoming obsolete with MFA solutions like 3Dsecure

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#505

Earlier quoted context omitted.

I wasn't arguing in favor of Venmo, but are VISA and MasterCard really better options in this regard?

They are required for the CC transaction, this adds an additional player that should not be necessary. In civilized countries they have direct bank to bank transfers.

> In civilized countries they have direct bank to bank transfers

I'm sure whatever country you're from (or otherwise alluding to) is a fine place, no need for the transparent insecurity. :) Narrowly, I agree that secure (and fee-less) bank-to-bank transfers would be preferable to CC.

> They are required for the CC transaction, this adds an additional player that should not be necessary.

We're positing a situation where CC's aren't available, so it's not an additional player but rather a different player.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#506
How secure is this? For example in the Netherlands creditcards are showing a secret number on the backside of the card. Let's say the app on the phone is altered and making pictures of the card once it swiped over. The phone can then collect all information to make a purchase. I would not trust somebodies phone to swipe my card over.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#507

Great, now I need an RFID-blocking wallet because any yeehaw can place their iPhone to my pocket to charge my credit card.

That's been possible ever since mobile POS services have started supporting contactless payments, without any catastrophic fallout.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#508

Earlier quoted context omitted.

Same in the US. I virtually never use cash. The only real problem I run into is the occasional "open bar"--drinks are free but there's still an etiquette that you should leave a tip which generally means cash.

The EU terminals have support for tips separated from the primary amount.

If I understand you correctly, we have those here in the States as well, but the problem is you're not using your CC in the first place (in the "open bar" scenario) so you never actually use the terminals.

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#509

Earlier quoted context omitted.

> I've only just gotten used to the slide-it-in-the-slot kind. I always called this "chip". My UK friends called it "chip-and-pin" in 2012. But yeah, no idea what the technical or widely-accepted colloquial terms are. > Not knowing for sure is why I never try, and just stick the card in the slot Yeah, for some reason the UX for contactless is terrible. Sometimes something will show four evenly-spaced green lights (an…

> Mostly on iOS I'm often trying to pay quickly and I try to activate the contactless payment but I'll end up turning my phone off or I'll try to bring up my card before my phone is close enough. Having an Apple watch helps out a lot here. I can't do it on my phone either, but on my watch it is trivial.

Good to know. I've had my eye on one for a while, but I opted for Air Pods last Christmas. :) Maybe this year...

Re: Apple unveils contactless payments via Tap to Pay on iPhone

#510
post #94

Earlier quoted context omitted.

8 Global/7 JP and later has FeliCa secure element; checkm8 exploit works up to X. It’s a fine thinking to not accept secure transaction originating a potentially jailbroken device; perhaps that’s why?

I was wondering about that too. I wonder how much SecureROM extraction pays nowadays? It used to be $200k circa 2015: https://ramtin-amin.fr/#nvmedma (Interim while the above URL currently doesn't work: https://web.archive.org/web/20200217151824/http://ramtin-ami... )

There are publicly available SecureROM dumps online, see http://securerom.fun

The author(s) maintain the site out of personal interest.

Post reply on HN