I still don't understand the business case other than trying to open a new revenue stream because it certainly wasn't solving a problem
Afaik you can't do that in Europe. At least I've never heard of it being possible.
Conceptually, I don't grasp how possibly exposing my PIN number at a point of sale is MORE secure. I just can't get past the idea that I'm now using the number I use to withdraw funds at an ATM at MORE places than just at my bank.
I doubt it will take much for you to get past it.
And the machine itself checks the PIN against the chip. No sending anywhere, no checking by the clerk.
You only have to trust the machine itself. If you don't, you're fucked anyway because who says a hacked machine will only charge as much as it says it will?
Card+signature is security by "something you have", Card+PIN is "something you have and something you know". That's much more secure.
A signature isn't "something you know" because it's written on the card anyway. If it's not written on the card, then using the signature doesn't do anything in the first place. And nobody checks those signatures anyway. This is why for large purchases they ask to see your ID.
If a machine charged you too much, either it would say so on the receipt and you could protest immediately, or the receipt wouldn't match the charge so you could protest later. Sure, the first few customers might get fucked, but soon the bad machine would be caught. OTOH if the machine processed the current transaction correctly while sending all your codes to the bad guys, it could do so until the store noticed its bad firmware, which could take years.
There's no way around trusting the machine itself.
Banks already correlate fraud reports to where customers have used their cards to track down offending stores that skim cards. They don't have to find the bad firmware, they just have to see "well 10 customers had their cards skimmed, and the only store they had in common was that one"
If someone hacked the terminal I use for an Apple Pay transaction what exactly would happen? It's a one time token that gets passed to the terminal and I immediately get a push update about the transaction.
Most american banks are issuing EMV & Sign cards, which means no PIN. You can set a PIN, but it's not a default flow and you have to call in to get it set.
And we're Chip+PIN here in general. But all merchants provide the Chip+Signature option.
http://www.lowcards.com/emv-transactions-slow-37884
Compared to Apple/Android Pay it's painfully slow, but it's also noticeably slower than swiping.
The process can be slower if the retailer uses an older system that hasn't got a permanent network connection. With some ancient terminals, you could hear a modem dialing up and talking to the bank. That was slow, but luckily those kind of terminals are now rare.
Edit: Swiping used to take 1-2 seconds to process, EMV seems to take about 10.
Worse yet, not all the chip enabled readers have the chip part enabled. So you can stick your card in, wait, and then realize you have to swipe. Otherwise, you swipe, get the suprisingly aggressive BZZZRT sound, and then use the chip reader and wait at least 5 seconds while it authenticates.
I'll time it at the local Target. It's slow.
In terms of speed from fastest to slowest: Apple/Adroid, swipe, swipe and sign, swipe and PIN, dip and sign.
When using a chip, my process is: insert card, wait for transaction to complete, remove card, put everything away, go.
You'll notice that putting stuff away happens in parallel with the transaction in the first case, but they're in series in the second case.
It may be reasonably quick, but it's still noticeably slower than swiping. It's not a big deal, but it's just one of those little annoyances.
If we had chip+pin it would be a different story, but because we have to sign, the EMV+sign process is slower than swipe+sign.
Is this seriously a security measure? Even if it did matter, it's on the back of the card anyways, for someone to copy!
Why not just get rid of it?
The US is way behind on this, it's ridiculous.
So is chip + signature, but that's a different argument.
Having all the important aspects of your life a little distributed isn't the worst thing in the world.
You're out at a restaurant, and you drove there. Your phone dies somehow, either dropped in toilet, or what have you. How do you do the following?
- Pay for dinner
- Drive your car, since your keys were in your phone
- Pay for a cab since you can no longer drive
- Pay for a phone replacement at an Apple Store
etc, etc.
Plus, I'm now going to trust all of my sensitive data to Apple's cloud storage? No thanks.
Lose your phone and you lose your payment instrument and your keys... no thanks.
This is exactly what I thought, but I started using Apple Pay, anyway, because Discover is offering 10% cash back on all in-store Apple Pay purchases through the end of the year. That's too good to pass up. Now that I've been using it for a while, I wish it were available everywhere. It's a small thing, but taking my phone out of my pocket is the most natural thing in the world. Subjectively, the process feels smooth.
Unfortunately, Apple Pay is suffering from the wrong end of network effects. Support is far from ubiquitous, so you don't know whether any given transaction will support it. You can look for the NFC logo, but some places with the logo still don't support it. At that point, it's easier to whip out the card by default. If I've been to a place before and know they take it, I'll usually use it, but there aren't many such places for me.
Because I don't see how the phone can be much quicker when plastic cards support the same contactless transactions, and have no buttons to fiddle with.
The phone can be quicker than a plastic card because the phone is more convenient to reach. It's just in my pocket. Reach in, thumb on home button, put near terminal, approved, put phone away. With a card, I have to get it out of my wallet too. Not a big deal, but not as smooth. (Plus, with today's addictive smartphones and short attention spans, half the time my phone is already in my hand at this time.)
Strictly speaking you can leave the card in your wallet and just hold the whole wallet to the terminal. But this only works if you have exactly one contactless card (or if you don't care which card pays). Unfortunately the US is moving away from such cards. I used to have two or three, but I just checked my wallet and out of the eight payment cards I have in there, none of them support NFC. Sad.
"Hey! How annoying is it that you have to carry AS MANY AS FOUR CREDIT CARDS?"
"Um, it's... not really..."
"Well how about CARRYING FIVE?"
"What?"
"Well, ours merges those together but... it doesn't really work anywhere so."
"TAKE MY $50!"
On the same note, I will never, ever use something like CurrentC that gives those same vendors a direct line into my bank accounts.
Like you, I'm skipping it, though.
Fair point.
I live in a rural area where I'm sure a majority of people shop exclusively at Walmart. For someone like that, it would probably be a great app to have. I shop at Walmart too, but not as often as my local grocery store and specialty shops. I would much rather pay in one, standard way at all of them instead of some patchwork of differing methods: EMV card here, mag swipe there, NFC here, take a picture of a QR code there. It just adds hassle on top of the direct advertising platform(s) I would be voluntarily installing to my device. The benefits just aren't worth it.
Aside from the digital receipt thing (which, in my opinion, is really only useful if you are planning on returning an item or collecting receipts for tax deduction) where is the additional value with the mobile Walmart app?
It's an awful system, just like the rest of their stuff. I'm sure it's going to be very successful.
Imagine your coordinates being determined to be the entrance of an OB/GYN office, and suddenly getting megs of push spam for your new baby. Or you appear to stand around the parking lot at the sportball field for hours every summer weekend, expect lots of push spam about charcoal, disposable grills, brats, picnic stuff.
What I don't understand is from a market dominance standpoint, why would walmart of all people want that data? Maybe they think they can market the data to other companies. Everyone has to shop at walmart sooner or later, maybe that means everyone will have their app sooner or later, so they'll have lots of privacy to sell to other companies.
I use Android pay and I still think it is harder to pay by phone. I have it in case I forget my wallet at home. http://www.forbes.com/sites/quickerbettertech/2015/06/01/why...
The hysterical thing is Apple Watch I saw this guy pay with it and then had to enter the pin and he was doing it through the watch interface. It took him FOREVER and I said "That was simple." He in return said "Simple as Brain Surgery." Don't they already have his finger print???
Don't misunderstand, chip & pin is something the US has long since needed. But the chips are unreliable and entering a pin on some terminals is annoying. A phone with NFC might be easier than that, just fingerprint to unlock, and then press a single button on the phone.
OTOH, NFC credit cards are now also becoming more common in europe too, i.e. https://www.visa.co.uk/products/visa-contactless/ http://www.mastercard.com/contactless/
[0] EDIT: it might have happened and I can't remember it, which is effectively the same thing in context.
But I do use my card(s) a great deal. So much so that the contacts on the chip are changing from gold to brown.
I've never had a problem with a card reader not properly reading swipes or the magnetic strip wearing down. Only times I've had a swipe fail has been when I mis-swiped the card, and that's entirely on my own klutziness, not any kind of mechanical failure.
The future shouldn't be worse than the present, but it looks like that's the road we're going down...
Although it seems less common over the last several years (perhaps because now physical cards are often replaced several times before they nominally expire?), this used to be a serious problem. The most common fix for a read failure was to put the card inside a plastic grocery bag, pull the bag tight, and then reswipe it. I have no idea how this fixed anything, but I witnessed it working many times.
My mum is a cachier. It is a constant headache where she works. Some tills the staff avoid using until last because the reader sucks so bad.
But, to you, C&P is an infallible technology that doesn't comfort to our normal rules of physics, so I'm sure nothing will convince you.
Contactless cards were introduced relatively recently, where you just tap and go - no verification required (as such there's a limit on the amount you can pay using contactless). These are very speedy, I think more so than Apple pay, and are becoming increasingly popular.
In London (and possibly other places in the UK, I'm unsure) they have actually integrated contactless card readers into public transport, meaning you can hop on a bus/tube and pay for the journey with your card. Essentially, you can carry around a single card to commute, buy your lunch, go shopping and everything else.
I already carry around my driver's license. I already carry around the access card to my school. I already carry around my student ID. I already carry around 3 different library cards. I already carry around my public transport card. I already carry around my debit card. I already carry around cash.
Even if you remove a few of those I still need to carry my wallet with me, so what difference does it make? I mean, other than the loss of separation of identities that comes with the territory. It's fine that my public transport card has low security, because you can't cash it out easily, and it only carries a very limited value anyway. Neither of those apply to my debit card.
Actually there's likely more incentive to pickpocket a wallet for its cash contents, rather than the contactless card(s), given in a lot of wallets this will be both greater and, by definition of course, easier to cash out on! So it seems like carrying contactless cards doesn't add any particular incentive for theft above what has existed forever with carrying cash. Also, any other security vulnerabilities with the debit card, unrelated to contactless, still exist exactly as they do today.
So, it seems to me that merging cards, i.e. adding contactless and the ability to use it for transport, and other things, seems to just add marginal convenience with essentially no added risk of theft or fraud[1]. So yes, it's not a life-changing technology and it won't mean you no longer have to carry a wallet, but it represents a small win and certainly a step improvement for everyday convenience, so that's good right? I for one simply think the fewer cards I have to carry, the better, to be honest.
[1] though I have, to be fair, heard about the issue of thieves 'skimming' contactless cards in people's pockets, I don't know if that was always just a scare story or if it's actually a real exploitable vulnerability - but this seems likely to be a pretty far-flung edge case anyway.
Chip & PIN is not coming to the US. Chip & sign, yes, but no PINs.
But back when we used mag stripes, I used to see failures all the time.
The anecdata in my life says chip&pin is FAR more reliable.
I have however worn out a card that has been in use for a couple of years.
I would beg to differ that the chips are unreliable. Other solutions might be easier, don't know about that though.
I used my apple watch to pay in about 90% of transactions, including parking meters!
Almost all merchants support "Visa PayWave" (aka NFC) so moving my wrist up to the terminal to pay was a fun talking point.
Not one checkout clerk had seen the apple watch used before, because the Aussie banks haven't reached an agreement with Apple yet.
Meanwhile in the states, some idiot retailers actually shut off their NFC readers because they didn't want to support Apple Pay.
I like the idea of Apple Pay. It's not accepted at enough places yet to make it really worthwhile, but I could see contactless payments being a big thing in the future.
We have a VERY large network of point-of-sale registers, all built around the old swipe-to-pay (often requiring signature) credit card model. Replacing practically every POS register in the country is not a simple task; we're rolling out "chipped cards" and new registers to support them (that's a lot of effort & money), but doing so will take most of a year.
That's why Apple Pay is such a big deal, and why the fuss about large businesses trying to roll out their own specialized (and usually inferior) version: yes we're starting to move to chipped cards, but even those are proving slow to use in many/most areas; most of the new registers also support NFC, making Apple Pay's "double tap a button and wave your watch/phone nearby" desirable - IF the store turns on the NFC & infrastructure.
Alas, Walmart is trying to avoid Apple's fees by putting support into their own app, which will be annoyingly slow.
Yeah, well, I'm in Canada and we had about the same thing, yet in the last 5 or so years we've seen 2 major changes (chip and pin followed by tap to pay) and most business have kept up, I haven't used the swipe in 3 or 4 years and the tap I'm now able to use tap at most places.
Is there a problem with adoption in the US for some reason that doesn't exist in other places? Perhaps Interac has some special power here or something.
Credit card: 1. Enter phone number (for loyalty card lookup) 2. Select "credit card" 3. Swipe card 4. Answer question about making a donation 5. Confirm credit amount 6. Sign 7. Confirm (This is from memory, but it is roughly correct - I actually fear I may have forgotten a step or two)
Apple Pay: 1. Enter phone number (for loyalty card lookup) 2. Wake iPhone and bring near POS terminal 3. Place finger on home button until it buzzes (~1 second)
The flow for Apple Pay could be a little longer if you need to select a different card, but it is still both far faster and far simpler than the regular credit card flow.
I've never had to do this to use Apple Pay from my watch. Is this the flow for chip and pin cards (I've only got chip and signature)? If so - that's fucking terrible.
I love using apple pay from my watch, I don't even have to roll up my sleeve, just double tap the button and hold it near the reader.
I have a sleeve attached to my phone, which holds my bank/credit cards. The only things I carry are my phone and my keys.
That's not how it works. You don't have to enter a PIN to pay with the watch. You just double tap the side button and hold your watch against the reader and the payment is made.
If you lock your watch with a PIN, then you have to enter the PIN the first time you use the watch after putting it on your wrist. As long as you continue to wear it, you don't have to enter that PIN again. If you take your watch off, then you have to put the PIN in again the next time you put it on and want to use it. It's so if somebody steals your watch they can't use it. Entering a PIN is something you tend to only do once when you put it on in the morning.
What probably happened was that he put his watch on in the morning, but didn't use it until he had to pay for something. Then he had to unlock his watch. In the vast majority of cases, the watch would already be unlocked and there wouldn't be any PIN to enter - the PIN isn't used during payment.
Contactless is as quick as a payment will ever be: Hold your card near the reader for less than a second, and you're done. No need to wait for your phone to wake up and accept a fingerprint, fumbling around trying to hold the phone right, and then put it near the reader.
Once contactless cards become more prevalent, Apple Pay / Google Pay becomes pointless.
1) Contactless uses (needs) the same terminal technology as Apply Pay & Android Pay. So all three are in the same boat, and benefit from the expansion of the others.
2) Just speculating, but Contactless will probably move towards a PIN or something of that nature. The whole payment industry is moving towards 2-factor. Contactless by itself is not 2-factor.
I used to be skeptical of contactless cards because of the lack of 2-factor. I thought it would be a liability (if my wallet gets stolen, now the thief can use my cards). However, the UK banks are quite vocal about promising to repay you if this happens. I've never had to put this to the test, luckily.
Also, there is still an element of 2-factor auth. Occasionally, contactless will ask for a PIN confirmation (perhaps random, or perhaps if the bank thinks the payment seems odd). A new card of mine refused to work until I had made at least one PIN payment with it, for instance.
Finally, there are low contactless payment limits - £30 right now. But these have been steadily rising as banks become more confident with their fraud systems. So, it seems that the payment industry is happy with the system.
Why is the extra thing you have to bring with you and probably use a PIN for "just as useful"? Mobile based systems are also interesting because you can just as easily use them for app based sales. Anything to reduce the friction of someone giving you money is going to be a welcome thing for retailers.
As for app based sales, they exist today just fine with credit cards.
I actually think that banks in the future will stop issuing physical cards altogether and will rely on virtual cards linked with Apple Pay, Android Pay or some other contactless based system.
I think the apple watch is considered 2-factor, where you've already cleared the first factor by unlocking the watch with your passcode (or linked phone unlock)?