Comment by add-sub-mul-div
5 hours ago
Another alternative (in the US, at least) is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all. What an unforced error, to shovel more of your data at them needlessly.
> is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all.
Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.
The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)
Importantly, this provides a degree of protection from compromised PoS terminals. Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges, whereas back when I was still tapping, inserting, or swiping my card I’d need to call and get a card or two replaced almost every year.
> Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges
BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.
[1] https://stripe.com/en-sg/resources/more/what-are-bin-attacks...
Inserting and tapping is just as safe.
Swiping is where the risk is.
7 replies →
All EMV transactions (including Apple Pay in a tap to pay scenario) don’t give the retailer the full card number.
don’t be silly, apple displays me exact amount on the screen, in plain fucking text, after each transaction - that’s crazy you wrote this
This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.
The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).
Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)
1 reply →
Man, its amazing how confident you are about this, considering I know individual people who independently work at Visa, Mastercard, AND Apple, who have worked on mobile payments who independently confirm that none of them know any personal info and that its all pass-through.
So, are you sure you know what you are talking about?
4 replies →
That is much better, but you're still paying visa/mastercard some percentage fee for a service which should be provided by e.g. the central bank.
Banks in the Netherlands used to have their own system for 30 years. It was free. It worked.
But it was too much work and didn't make the banks money so now we are also left to the American Visa parasite.
Yeah. But this is the US. This is all we’ve got. Having the central bank do it would be communism, and that’s bad. I learned about it from Saturday morning cartoons.
Ironically it's the central bank (and associated regulations) that cause these intermediaries to exist to begin with.
A protocol to support decentralized payments is a hobby project for an individual. You give each institution an identifier (e.g. their domain name) and each institution gives each customer an account number. If you're account 123 at Chase then you sign in as #123@chase.com, tell Chase you want to send $5 to #456@bankofamerica.com, they send the money and Bank of America tells their customer they have a new deposit. If you want to collect money from someone, you tell your bank to send their bank a payment request and they can either approve it manually (e.g. so you can deliver the goods for a one-time purchase) or configure some rules for which accounts get approved automatically up to some threshold amount (e.g. for recurring payments). Also no reason for banks in different countries not to all support the same protocol.
That doesn't require a central bank or any centralized third party payments intermediary. All it requires is for banks to know how to send money to other banks, which they obviously already do and the specific implementation of that isn't even relevant to the customer-facing payments protocol. So how does this not exist? It can't be that no one wants it, so it's got to be that someone (e.g. Visa/MasterCard) doesn't want it.
3 replies →
yea, feels like tech giants do not have access to this already? they know where you are and what you do every second of every day, keeping away from ( while they know I was a target ) what was the amount on my receipt is really giving it to them :)