Banks and Credit Unions to Team Up Against Apple Pay Fees
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Banks and Credit Unions to Team Up Against Apple Pay Fees
Unofficial Hacker News client; not affiliated with Y Combinator.
havaloc · · focus · HN ↗
Somewhat related, even Walmart relented and now supports Apple Pay/Contactless. Every big merchant has now relented (Kroger, Home Depot, Walmart).
syvolt · · focus · HN ↗
add-sub-mul-div · · focus · HN ↗
jasode · · focus · HN ↗
Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.
The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)
cosmic_cheese · · focus · HN ↗
MBCook · · focus · HN ↗
Swiping is where the risk is.
ericmay · · focus · HN ↗
With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?
notpushkin · · focus · HN ↗
Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.
ssl-3 · · focus · HN ↗
At least around where I am (Ohio, USA), at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.
In doing so, entire card is pushed all the way into the same slot that is also used for reading the magstripe, and to the same depth that is used for magstripe transactions.
This quality leaves the door open for magstripe skimming.
(It may be a stupid way of building things, but things exist in the real world that are built this way anyhow. Whether the information on the mag stripe still has any utility for a would-be thief in 2026 is a different matter.)
MBCook · · focus · HN ↗
notpushkin · · focus · HN ↗
Fairly standard for ATMs, yeah. I’ve always wondered why they do it like that.
And I think I’ve seen ticket machines like this in Finland – not a typical ATM-like receptacle, but you do insert the card all the way in and it locks it down. (I guess Ohio gas pumps also have something like that?)
So yeah, those things exist, but the “typical” terminal style where you only insert the card halfway is fairly safe at least. :-)