← Back to context

Comment by svpk

10 hours ago

> with increased attack vectors.

I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen.

If you just mean it's less private than I don't really know that it's terribly different than using a card. Especially if the ecosystem were open and you could choose your payment provider and not just have to use Google/apple.

You might want to look into NGate.

  • if I’m reading the source I found correctly, that has got nothing to do with Tap and Pay, where a virtual card is stored/emulated on device via the secure element, instead emulating an Contactless reader and relaying a real card pressed up against the device.

    If anything, this attack is a benefit of mobile payments, where you need a second device to perform the attack with, and the user to use verify themselves for the payment to go through.