Live data from Hacker News

Offline card payments should be possible no later than 1 July 2026

riksbank.se

491–500 of 581 posts

Re: Offline card payments should be possible no later than 1 July 2026

#491
post #158

Earlier quoted context omitted.

Are there people that like cheques? For no good reason, I keep a list of why I use checks (in the U.S.): - Charitable donations because charities maximize every penny, and electronic contributions eat into that - Paying the accountant - Good accountants make every penny count, and aren't interested in paying credit card overhead. - Tipping the paperboy at Christmas - Tipping the doorman at Christmas - Business licens…

In Finland, and I imagine in most of Europe in general, people just make bank transfers for most of those things. Unlike in USA you cannot just pull cash from someone's account if you know their bank account number, you need to setup SEPA Direct Debit to do that and it requires explicit authorization from the account owner. It isn't even really used much in Finland, most companies just send electronic invoices that y…

Unlike in USA you cannot just pull cash from someone's account if you know their bank account number

People say things like this as if the money taken in a fraudulent transaction just disappears and is untraceable, and unrecoverable. That is false.

It's one of those scare tactics that the middlemen use to sell a vision of financial-techno-secure-utopianism in order to collect a percentage of the money. Don't fall for the marketing.

The money has to go somewhere: Into another bank account, usually, which is easily traceable since banks by law have to know who they're dealing with.

Even if a check gets cashed at a check cashing store, the store requires ID, the person getting the money is on video, sometimes they have their fingerprints taken by the store, and if something still goes wrong, the store is on the hook for the money when the transaction is reported as fraudulent and reversed.

These are all problems that were largely solved last century.

Re: Offline card payments should be possible no later than 1 July 2026

#493
post #404

Earlier quoted context omitted.

We know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. It's a completely solved problem, but it's a more complex (and as such more expensive) solution than just assuming ubiquitous connectivity and a backend that never goes down, which is how we got to where we are. > Is this motivated by a need to prepare for war? Preparing…

> We know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. But how do they prevent people double spending the same amount? Say someone has 100$ and boards on a plane. During the trip, this person buys a bag of potato chips sold for 90$. At the same time, his bank account is automatically charged 90$ for a bill. With credit card…

... information theoretically... you can't

it's okay

there's already some fraud, waste, loss, inefficiencies, accidents (packages lost, chargebacks by mistake, package arrives weeks later)

....

that said the chips have some physical protection, it's not trivial to clone them

and the chip has a variable where it stores how much more you can use without online confirmation

of course, these are cheap protective measures, but to crack it you would need more effort probably than the total credit that's assigned for offline spending

Re: Offline card payments should be possible no later than 1 July 2026

#494
post #326
post #47

Earlier quoted context omitted.

The EMV standard has long supported an offline transaction flow. AFAIK it was the default almost everywhere in Finland circa 2011, contactless there was almost always instantaneous. Digging into why that was compared to the invariable wait when using contactless in the UK revealed this flow. The card has a variety of risk counters on it that allow it to securely decide whether an offline transaction can proceed, at l…

I think metro trains in countries like The Netherlands and Singapore use this approach where in you tap your cards and entry and exit and you are billed usually somewhere at the end of the day.

in the Netherlands you can now pay with your normal credit or debit card instead of a special train card. Was a thing in Kyiv metro for a decade too.

Re: Offline card payments should be possible no later than 1 July 2026

#495
A lot of people asking here in comments how the implementation would look like, given this is HN and the crowd here is technical inclined. No idea how they will do it but I can tell you how I did it in 2008.

See, in 2008 one of my projects had a client that had a lot of venues around continental US and Mexico and those venues were having sparse internet connection (think sky resort venue, remote and internet delivered by antennas that weather could affect it). Meaning when internet was not available any card transaction was a no go. This was a problem to be solved so my client asked if there is a way to make offline credit payments. So here is my implementation: -read credit card details and deliver the goods -> store card details in a local database, encrypted -> check online connectivity -> when internet was a go try to charge the card. If it was good then all was done, details were erased from local storage, everybody happy. If it failed then retry, 5 times per day, for 5 different days. After 25 tries, blacklist the credit card. Forward the information to legal department and mark that credit card as not acceptable from now on. So if you screwed the client with a bad credit card, you screw it only for 5 days maximum. And you also had a legal department on your ass. Meaning you got a fake card, good for you, keep it up cause now you are also on Secret Service radar (most people don't know but Secret Service, not FBI, gets involved in this). In the years I got involved in this project, 8 years, the number of times this was an issue raised to legal department was like under 5. So most folks actually pay and the few that got retried had probably a temporary problem with their funds and eventually they got it back on track. For those under 5 I think all of them eventually cut a deal with legal without raising the issue further up. Sorry guys, no juicy story involving Secret Service here.

Probably this worked because the goods were kinda under $50 as price. So maximum you'd screw the company I worked for like $500. And most likely this would not work with a big retailer like Amazon where you can purchase for thousand of $ in a single transaction. But it had the advantage that it worked with all credit cards, debit or otherwise, Visa/MasterCard or whatever. If I would be on the implementation side nowadays from the Sweden bank in this article, I would probably do it like somebody else already proposed here in comments. Get the card to also contain an electronic signature which means a lot more scrutiny to get it released, which means yeah!, your privacy is fucked to Alpha Centauri and back if you try anything shady.

Re: Offline card payments should be possible no later than 1 July 2026

#496
post #9

It's not about paying by cash but paying by card offline. How is this going to be implemented I wonder. On planes they often accept credit cards even when there's no internet. I assume this is a trust in-credit-based system because they don't accept debit cards, i.e. if you are worth being trusted with a card you can have your sandwich now and we will take care of the bank processing once we are on the ground. So may…

Credit cards were originally an offline payment method. The merchant would create a receipt that included a contact paper imprint of the card (which is why the card has raised lettering) and would present it to the bank for reimbursement.

Re: Offline card payments should be possible no later than 1 July 2026

#497

Earlier quoted context omitted.

It's more complex than that: The card actually has some nonvolatile storage with your current balance, which gets decremented each time you use it.

Not in the Netherlands, no. The card can be a bank card, and you can be billed at the end of the month automatically through direct debit. It also wouldn't work as you describe, as the terminal at the point of entry doesn't know how much to charge you since it doesn't know where your journey ends.

It will bill your 4 EUR (on a tram/bus) or the whole 20 (or something on a train) instead of the actual journey price if you forget to checkout. Pretty sure it can decline cards for insufficient balance too. Not sure the entry gate blocks the amount.

Actual chipcards don't bill you at the end of the month either -- they reload a fixed amount through direct debit (which takes a few days) the moment your balance crosses zero. If the direct debit isn't setup for a card (because it's not a personalized card) or the debit was rejected, the card is blocked.

For business chipcards cards it works somewhat the way you described.

Re: Offline card payments should be possible no later than 1 July 2026

#498
post #469

Earlier quoted context omitted.

That’s because credit card benefits suck in Europe and there’s no point to using them. If you need credit, there are credit options with much lower rates than what credit cards offer. And the reason credit card benefits suck is due to european interchange fee caps and regulation.

> That’s because credit card benefits suck in Europe and there’s no point to using them. Theres still a very good reason to use them - buyer protection. I use a Virgin Atlantic reward card and have it set to pay off automatically, never running up debt. It both protects me as a buyer, and has the benefit of taking ~£500 off annual family holidays, and gives me a free companion seat in the process, effectively halving…

I am not sure what you mean by "buyer protection" but if it's chargeback then it's doable on debit cards too.

Re: Offline card payments should be possible no later than 1 July 2026

#499
post #404

Earlier quoted context omitted.

We know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. It's a completely solved problem, but it's a more complex (and as such more expensive) solution than just assuming ubiquitous connectivity and a backend that never goes down, which is how we got to where we are. > Is this motivated by a need to prepare for war? Preparing…

> We know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. But how do they prevent people double spending the same amount? Say someone has 100$ and boards on a plane. During the trip, this person buys a bag of potato chips sold for 90$. At the same time, his bank account is automatically charged 90$ for a bill. With credit card…

> But how do they prevent people double spending the same amount?

Both payment cards and merchant terminals (essentially also using embedded or removable smartcards) are tamper-resistant and hold symmetric keys only known to the payment scheme or issuer.

The terminal essentially creates a cryptographic secure channel between two smartcards, and they transactionally agree to decrement the balance on one, and increment the one on the other correspondingly.

The really neat thing is that this theoretically even works without the need for central accounts, and is as such very privacy friendly. (Practically, even just one key leaking would have catastrophic consequences though, and to detect whether that has happened, systems usually aggregate all transactions asynchronously and check money movements for plausibility.)

Re: Offline card payments should be possible no later than 1 July 2026

#500
post #493

Earlier quoted context omitted.

> We know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. But how do they prevent people double spending the same amount? Say someone has 100$ and boards on a plane. During the trip, this person buys a bag of potato chips sold for 90$. At the same time, his bank account is automatically charged 90$ for a bill. With credit card…

... information theoretically... you can't it's okay there's already some fraud, waste, loss, inefficiencies, accidents (packages lost, chargebacks by mistake, package arrives weeks later) .... that said the chips have some physical protection, it's not trivial to clone them and the chip has a variable where it stores how much more you can use without online confirmation of course, these are cheap protective measures…

What's the information theory connection in your view?

> these are cheap protective measures,

They're holding up extremely well. I'm not aware of any cryptographic or physical key extraction compromise in EMV, for example. All known bugs are protocol design oopsies, as far as I'm aware.

Post reply on HN