Live data from Hacker News

How Apple Pay works and why it matters for developers

clover-developers.blogspot.com

61–70 of 116 posts

Re: How Apple Pay works and why it matters for developers

#61

Earlier quoted context omitted.

I'm a Canadian who is temporarily in the US, and it seems so backwards to me. A signature? You mean writing on a piece of paper that probably never gets looks at allows someone to take money out of my bank account? Chip+Pin at least has a semblance of technical security. And cash? Don't get me started. Cash can be physically lost. Cash can be stolen. When you pay with cash, you get given coins as well as the thing yo…

This, I'm living exactly the same situation right now. Last time I came to the US, I realized my cards' magnetic bands weren't working. Would have never noticed otherwise, chips don't wear off. Had to prepare for new cards before my next trip. Chips came so long ago in Canada that I can't recall when. My surprise every time I remember they're still not here. Then cash only places and having to receive coins; the wors…

And then what do you do with the coins, hope that one day you'll get the chance to use them?

You dump the coins in a change jar on top of your dresser. Then once a year or so, when you have accumulated $100 in coins, you bring the jar to a coinstar machine at your local supermarket and get the coins converted to an Amazon gift certificate.

Re: How Apple Pay works and why it matters for developers

#62
post #21
post #16

Earlier quoted context omitted.

Apple Pay is focused on easing consumer pain and friction, leading to more competition among service providers and retailers since trying new services will become easier for users.

Ok now I'm not sure which aspect you're talking about. Because in the physical world the friction is not "oh I need a card" it's physically getting the customer in the door. Otherwise, what's involved is needing merchants to have NFC readers. This might be an exciting new thing in the US, but certainly in my neck of the woods NFC has near universal penetration. In the virtual world...this problem has been solved over…

> Everyone has Paypal - very few people (relatively) will have ApplePay.

Today Paypal has something like 150 million users worldwide while there are 72 million iPhone users in the United States alone. Presumably all of these people will eventually upgrade to an iPhone supporting ApplePay.

Re: How Apple Pay works and why it matters for developers

#63

I'm very curious about the business side of ApplePay. Is Apple going to get some (miniscule) cut of every transaction performed? I.e. is this a new revenue stream for Apple?

they said in their faq that they won't be taking a cut. Either this is purely for improving the ecosystem, or they're getting a cut from banks for cutting down fraud.

Re: How Apple Pay works and why it matters for developers

#64
post #35

Earlier quoted context omitted.

I've never used Google wallet- but how could Apple's UI be worse? All you do is tap your device. How did Google Wallet work?

that's the payment experience, sure, but there's all those moments before and after your payment. say, adding a card, managing which cards you want to use at which locations, etc. there was plenty of footage in the live stream this morning, or stills here: http://www.apple.com/apple-pay/ but the bigger point: you're quibbling over the first of three points i made in an aside (the other two being that google wallet ha…

Well, there's the second half of that sentence which qualifies it with "broad, inclusive". I'm not saying I agree, although it could be that Apple believes Google Wallet was not broad, inclusive, or both.

Re: How Apple Pay works and why it matters for developers

#65
post #34

Maybe it's just me but I'm not drinking the kool aid about Apple Pay in today's announcement. Aside, I really hated the fact that to watch the event you had to use a Safari browser, same with watching Swift tutorial videos on their website, using latest Chrome on a Mac... Maybe I'm old school but I'm actually finding that payment options are getting worse, not better. This is another example of further fragmentation.…

The problem of capitalism is that all agents want (amongst other things) full vendor lock-in. Sadly that's been our general direction for the past 50 years in most aspects of life, and there seems to be little hope for reversing the machine in thr short term.

As against planned economies in which lock-in by a single vendor is mandatory and essentially irreversible. The answer, as Adam Smith observed, is a well regulated market.

If you're going to make negative comments like that, it would be helpful if you were to offer some kind of alternative and why it's better.

Re: How Apple Pay works and why it matters for developers

#66
post #41
post #15

Earlier quoted context omitted.

It really doesn't do this. Apple Pay is not the solution to moving money between parties who aren't registered merchants, with the relevant banking setup. Anyone can be become a merchant with a PayPass reader today. Apple Pay is not changing that, nor can it since that sector is entirely dependent on local commerce/finance laws and payment processor anti-fraud costs.

Having first-class OS support for the payment method (and the fact that a huge amount of people have been forced to register a credit card through iTunes at one point or another) means that the consumer barrier to entry is super low.

> forced to register a credit card through iTunes

I'll never forget the day they held a gun to my head and made me buy my first iPod.

Just so I get the terminology right though, when you register a card within itunes Apple is forcing you to do so, but when you register it with Google Play, Google is reluctantly allowing you to do it. Did I get that right?

Re: How Apple Pay works and why it matters for developers

#67

Maybe it's just me but I'm not drinking the kool aid about Apple Pay in today's announcement. Aside, I really hated the fact that to watch the event you had to use a Safari browser, same with watching Swift tutorial videos on their website, using latest Chrome on a Mac... Maybe I'm old school but I'm actually finding that payment options are getting worse, not better. This is another example of further fragmentation.…

Well, sometimes digital payment comes with a nice discount. That's where CASH can't compete.

Re: How Apple Pay works and why it matters for developers

#68
A few counterpoints to having your phone used as a payment device :

- it breaks more easily and wears out quicker than a card

- you can't lend it to a friend to have him buy stuff for you ( i don't have a pass id iphone so maybe i'm wrong on this one)

- it gets stolen more often because it has intrisic value ( and a big one for the iphone)

- if it gets stolen, how are you going to call your bank to disable it ?

Plus, retrieving fingerprints from a stolen iphone was demonstrated last year and seems pretty easy. Now that iphones will be used to pay, you can expect criminals to get very familiar with the technic very fast.

Re: How Apple Pay works and why it matters for developers

#69

Earlier quoted context omitted.

I'm a Canadian who is temporarily in the US, and it seems so backwards to me. A signature? You mean writing on a piece of paper that probably never gets looks at allows someone to take money out of my bank account? Chip+Pin at least has a semblance of technical security. And cash? Don't get me started. Cash can be physically lost. Cash can be stolen. When you pay with cash, you get given coins as well as the thing yo…

I stopped signing a long time ago. Now I scribble, draw pictures, whatever.

You mean like this guy? :)

http://www.getrichslowly.org/blog/2006/07/29/the-credit-card...

Re: How Apple Pay works and why it matters for developers

#70
post #23

The part I'm not quite following is when the tokenization takes place. If it takes place per transaction then the PAN must be saved in the phone somewhere and the phone would have to be online to do the tokenization in real-time. If it is a one-time tokenization that happens when the card is added isn't that token just as valulable as the PAN since the token can be used across merchants? Maybe the 3-D secure piece of…

My understanding is that this operates on basically the same principle as RSA SecureID. You have an unlimited-use token stored in a dedicated chip, that for all practical purposes is impossible to access, short of, let's say, a scanning electron microscope.

That chip, with its unlimited-use token then generates one-time tokens which are sent over the payment network.

In theory the chip could issue an arbitrary number of tokens if criminals got ahold of it. But in practice, it stores a little bit of the data it needs to make a token in the neighboring TouchID chip, which operates on essentially the same principle (stores fingerprint data and missing payment data in secure hardware location, only lets it out if fingerprint sensor looks good).

To summarize you have to steal both the phone (or both chips anyway) plus the fingerprint information so the chips are useful. But wait, you say--I did steal the fingerprint data! The user left fingerprints on the back of the phone!

Well, you've got me there. But hopefully by the time your very sophisticated gang of gloved thieves has bagged and dusted your phone for prints, you've made your way to iCloud.com and revoked the phone's forever-time token, so all future one-time tokens will be considered invalid.

Keep in mind, the standard being replaced here is one where you carry all your payment information around in your pocket in plaintext. This scheme is a massive improvement on that. There's an old saying that seems relevant here: I don't have to outrun the bear, I have to outrun you. There's tremendous amount of value in being marginally safer than the next guy.

Post reply on HN