Live data from Hacker News

Apple Pay on pace to account for 10% of global card transactions

qz.com

151–160 of 432 posts

Re: Apple Pay on pace to account for 10% of global card transactions

#151
post #87

Earlier quoted context omitted.

You should revisit your concept of what Europe likes. Even in Berlin, the cash-only capital of Europe, I almost never use cash anymore.

I think the parent is right. The EU has limited the interchange fee for credit cards (like Visa and MasterCard where the scheme and merchant bank are separate entities) to 0.3%. They did not make a statement about whether we like cashless or even contactless payments, just that the associated fees are limited, which makes rewards programs essentially infeasible.

Cost me almost £20 a month and the banks just found other ways to charge the merchants so no voter ever saw a benefit

Re: Apple Pay on pace to account for 10% of global card transactions

#152
post #39

Earlier quoted context omitted.

I thought that you had a fixed number, but Apple generates some kind of unique code, which is sent to the terminal. I.e., the terminal doesn't see your actual number.

There is a lot of deliberately confusing marketing. "Tokenization" simply means that a new PAN is generated once per device. This is a normal PAN registered with the payment scheme and your issuer. It has to be a normal PAN, otherwise it would never pass through all the exiting payment infrastructure. What is generated per transaction is the EMV unpredictable number, but this is part of the EMV protocol and done for…

Why do you say it's deliberately confusing?

Re: Apple Pay on pace to account for 10% of global card transactions

#153
post #39

Earlier quoted context omitted.

I thought that you had a fixed number, but Apple generates some kind of unique code, which is sent to the terminal. I.e., the terminal doesn't see your actual number.

There is a lot of deliberately confusing marketing. "Tokenization" simply means that a new PAN is generated once per device. This is a normal PAN registered with the payment scheme and your issuer. It has to be a normal PAN, otherwise it would never pass through all the exiting payment infrastructure. What is generated per transaction is the EMV unpredictable number, but this is part of the EMV protocol and done for…

> What is generated per transaction is the EMV unpredictable number, but this is part of the EMV protocol and done for any EMV transaction.

What about when magstripe emulation is in use, does Apple Pay support that in the US?

Re: Apple Pay on pace to account for 10% of global card transactions

#154
post #54
post #17

A big part of this is that apparently US credit card companies decided not to include contactless when they switched over to chip cards, in order to save money. Ironically, contactless was becoming fairly common before the move to EMV, but is now pretty rare. I think about half my cards had it a few years ago, but now none do.

Contactless is also a security concern on actual cards. It only stores a single number (like the stripe, unlike the chips or phone-based NFC), and it effectively "broadcasts" it in a radius of a couple of inches. Very easy to skim even while it's still in your pocket.

>Very easy to skim even while it's still in your pocket

Do you have any details on that?

From my understanding skimming is mostly an issue for magstripe, as contactless (at least in the proper EMV implementation) is cryptographically secured. There is not much to skim.

I'm aware of a few papers on relay or downgrade attacks, but I would consider them mostly of theoretical relevance (e.g. https://www.usenix.org/system/files/conference/woot13/woot13... or https://pdfs.semanticscholar.org/c8a6/9d63996f8f1eef414dbd29...)

Re: Apple Pay on pace to account for 10% of global card transactions

#155

Earlier quoted context omitted.

In the US it's usually 'insert card into reader, then wait 30-90 seconds'. I don't know where the delay comes from, but Apple Pay is usually faster for me.

30-90 seconds is a big exaggeration. Using chip without a pin number takes at most 5 seconds, and using a pin only increases the wait for the duration it takes to enter the code.

Depends some readers still use POTS and would have to make a call.

About 20 yeas ago before wide spread use on the internet in the UK they where looking at using the ISDN D channel to do card authentication

Re: Apple Pay on pace to account for 10% of global card transactions

#156
post #113

Earlier quoted context omitted.

At least in the UK, contactless is limited to 20£ and probably has other limits as well I suspect.

£30 currently. Though mobile payments don’t fall foul of this in theory, in practice some terminals are limited to £30 to match the card limit, which can be annoying when you want to pay by mobile (the most secure way).

>in practice some terminals are limited to £30 to match the card limit

Mostly the fault of a cheap implementation from my understanding as they them don't have the data required to verify the CDCVM.

Re: Apple Pay on pace to account for 10% of global card transactions

#157

Now if only I could carry my ID around on my iPhone I wouldn't need to carry a wallet.

Until you drop you phone and break it or it barfs on you in some other way. There was high profile case of an iPhone user who got fined over £600 because the phone died and they could not show the rail ticket to the guard on the train. She was lucky enough to get it picked up by the national press, probably knew someone.

Rail crimes are one of very few criminal offences in the UK where you don't have to intend to break the law to be convicted.

That means if you can't show your ticket to a guard when requested, even if you did have a ticket on your phone, did have a mobile battery pack, did have a spare wifi hotspot for signal, did have a spare phone incase the first failed, and did have a spare finger in case of your finger suddenly falling off, you are still breaking the law, and can still get a criminal record and go to prison for it.

And due to the way rail companies are allowed to prosecute you directly rather than involving the police or CPS, you can be sure they will prosecute in these cases.

Re: Apple Pay on pace to account for 10% of global card transactions

#158

Earlier quoted context omitted.

So, yep? They didn't claim it was a unique feature of Apple Pay.

They make it sound like there is a special "Apple sauce" that they built and strongly suggest they generate a new PAN for every transaction. The suggest that a "token" instead of a PAN is used for the transaction. This is very misleading. If you read it very carefully they are not wrong, but for the uninitiated a wrong impression is crated. They are using an industry standard protocol that is 25 years old.

suggest that a "token" instead of a PAN is used for the transaction

Maybe because people know the word "token" and don't know what a "PAN" is. Apple has built a trillion-dollar company by speaking at the level of its customers, not technobabble.

Re: Apple Pay on pace to account for 10% of global card transactions

#159
post #45

Earlier quoted context omitted.

That's an interesting viewpoint. Where do you live? I would imagine you live somewhere that is not along the coastline in the USA. The only time I have ever run into any kind of social friction (percieved or actual) it was only around the time that it had just rolled out and everyone would groan and say stuff like "yeah, it says we do apple pay but it wont work" But after those initial bumps it is really prevalent an…

Portland, OR, but I never saw anyone use it in Brooklyn, either. Though NYC is incredibly backwards as far as payment technology goes, and most places strongly prefer cash. I still get your reaction sometimes, or that look that says "I'm tolerating this, but you're annoying me."

I'm starting to see QR codes on food trucks downtown that used to be cash only. Not gourmet ones but your average Chinese, Halal, breakfast/lunch etc.

Re: Apple Pay on pace to account for 10% of global card transactions

#160
post #54

Earlier quoted context omitted.

Contactless is also a security concern on actual cards. It only stores a single number (like the stripe, unlike the chips or phone-based NFC), and it effectively "broadcasts" it in a radius of a couple of inches. Very easy to skim even while it's still in your pocket.

>Very easy to skim even while it's still in your pocket Do you have any details on that? From my understanding skimming is mostly an issue for magstripe, as contactless (at least in the proper EMV implementation) is cryptographically secured. There is not much to skim. I'm aware of a few papers on relay or downgrade attacks, but I would consider them mostly of theoretical relevance (e.g. https://www.usenix.org/system…

I've seen it demonstrated on local news programs, and sometimes I see TV commercials for metallic sleeves you can put your NFC cards in so they don't get skimmed.

When I had a Washington State combined driver's license/North America passport, it came with one of those little sleeves. So there must be some kind of threat, or the government wouldn't hand those out.

Post reply on HN