‹ BackHN Continuity

Thread

Banks and Credit Unions to Team Up Against Apple Pay Fees

127 points · 133 comments · Brajeshwar

  1. havaloc · · focus · HN ↗
    I get why the banks are not happy, but I can tell them that I am not going to use Chase Wallet, Bank of America Wallet, Citi Wallet...just pay the fee and be thankful for the reduced payment friction, which they invariably make money from. PS: Nobody is going to use Paze (yet another half baked wallet), other than to collect the free $10 to sign up for it.

    Somewhat related, even Walmart relented and now supports Apple Pay/Contactless. Every big merchant has now relented (Kroger, Home Depot, Walmart).

    1. syvolt · · focus · HN ↗
      Or Apple Pay can just be like Google Wallet is on Android? The alternative is not multiple apps.
      1. add-sub-mul-div · · focus · HN ↗
        Another alternative (in the US, at least) is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all. What an unforced error, to shovel more of your data at them needlessly.
        1. jasode · · focus · HN ↗
          > is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all.

          Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.

          The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)

          1. cosmic_cheese · · focus · HN ↗
            Importantly, this provides a degree of protection from compromised PoS terminals. Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges, whereas back when I was still tapping, inserting, or swiping my card I’d need to call and get a card or two replaced almost every year.
            1. MBCook · · focus · HN ↗
              Inserting and tapping is just as safe.

              Swiping is where the risk is.

              1. mrpippy · · focus · HN ↗
                Or (common in the US) handing your card to a restaurant waiter who walks off with it to do the charge
              2. ericmay · · focus · HN ↗
                I’m not super familiar with the implementation details but wouldn’t inserting not be as safe since there’s a physical connection?

                With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?

                1. notpushkin · · focus · HN ↗
                  Inserting and tapping is mostly the same process, apart from the physical layer of the protocol (NFC vs interfacing the chip directly).

                  Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.

                  1. ssl-3 · · focus · HN ↗
                    > Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.

                    At least around where I am (Ohio, USA), at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.

                    In doing so, entire card is pushed all the way into the same slot that is also used for reading the magstripe, and to the same depth that is used for magstripe transactions.

                    This quality leaves the door open for magstripe skimming.

                    (It may be a stupid way of building things, but things exist in the real world that are built this way anyhow. Whether the information on the mag stripe still has any utility for a would-be thief in 2026 is a different matter.)

                    1. MBCook · · focus · HN ↗
                      The credit cards, I believe, have pledged to eliminate magnetic stripes. Although given how long it takes us to do anything for all I know that will be by 2060. They are also planning to extend credit cards past 16 digits, which may also require the magstripe to go away.
                    2. notpushkin · · focus · HN ↗
                      > at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.

                      Fairly standard for ATMs, yeah. I’ve always wondered why they do it like that.

                      And I think I’ve seen ticket machines like this in Finland – not a typical ATM-like receptacle, but you do insert the card all the way in and it locks it down. (I guess Ohio gas pumps also have something like that?)

                      So yeah, those things exist, but the “typical” terminal style where you only insert the card halfway is fairly safe at least. :-)

                2. tialaramex · · focus · HN ↗
                  Physical connection doesn't matter. This isn't a Hollywood movie, there isn't some mega-virus which magically seizes controls of trivial objects by passing through a connector.

                  All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.

                  The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.

                  Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...

                  EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.

                  In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.

                  1. MBCook · · focus · HN ↗
                    There are two forms of wireless. The first was “magstripe emulation” and it’s exactly what you think it is. The card would hand over the exact data on the magstripe.

                    It’s also exactly as secure as you think: it’s not.

                    That hasn’t been used for a long time, and I don’t even think people accept it anymore. May not have for years. At least for credit cards. It’s quite possible that’s still how door access cards or maybe gym membership cards work. I don’t really know.

                    Everything now and for many, many many years, has been EMV over NFC. And you’re right on that one it is essentially identical to sticking your card in the EMV reader.

                    1. tialaramex · · focus · HN ↗
                      The exact technologies used for "access cards" have varied over the years, but last time I checked most of them still aren't doing anything even vaguely secure. The card says "I'm card 1234-5678" and the access system checks that is on the list, welcome in. Like magnetic stripes it isn't obvious to the human operator, but just like magnetic stripes you can just clone it by listening and reciting the same, "I'm card 1234-5678".

                      Now to be fair, you'd often find these systems are so clumsily installed that you don't need to clone a card anyway, the out-of-hours access has an "emergency" generic key you can buy from a hardware store, the controller was placed on the wrong side of the door - that sort of thing. But even a well-installed system is typically vulnerable to a competent intruder.

            2. ValentineC · · focus · HN ↗
              > Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges

              BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.

              [1] <a href="https:&#x2F;&#x2F;stripe.com&#x2F;en-sg&#x2F;resources&#x2F;more&#x2F;what-are-bin-attacks-heres-what-businesses-should-know" rel="nofollow">https:&#x2F;&#x2F;stripe.com&#x2F;en-sg&#x2F;resources&#x2F;more&#x2F;what-are-bin-attacks...

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.