Apple unveils contactless payments via Tap to Pay on iPhone
apple.com
apple.com
This is about the merchant using an iPhone to accept credit cards and other Tap to Pay devices.
The customer was able to pay with Tap to Pay with their iPhone for a while now.
I was ready for this in 2005.
https://money.howstuffworks.com/personal-finance/debt-manage...
If course as the article points out, it wasn’t even new technology back then:
“ Not Exactly New Tech Mobile introduced the Speedpass in 1997. Speedpass is a small device on a keychain (called a fob) that users wave in front of the Speedpass logo on gas pumps. The cost of the gas is automatically deducted from the user's Speedpass account”
It's still got the "contactless" part, though.
The only thing they have in common is the physical action of "boop boop" at a terminal or scanner.
I went to England in 2019, at which point cards in the US had been updated to use magnetic stripes, and everyone was using tap-to-pay. It turns out my credit card had tap-to-pay support as well but it wasn't widely used in the US (or at least in my sphere). Now it finally seems common-enough here.
I'm planning another trip to Europe in the next year... Really eager to see what payments look like nowadays.
One thing that is annoying for foreigners with credit cards is that they are barely accepted here. We work mostly with Maestro and almost all Dutch e-commerce sites work with Ideal which directly link to the banking apps of the local banks.
My wallet does not contain any cash anymore and just an ID and OV card.
https://www.linkedin.com/pulse/dutch-payment-landscape-one-m...
I haven't touched cash ever since covid hit, and very rarely before it.
The problem is that they have a local exchange there, and do not have cross agreements with all of the payment vendors (not at the Visa level, but bellow that). It was annoying, and caused us a lot of hassle. I am not sure how we could have avoided it.
Normal Mastercard/visa credit don’t work here since shops have to pay way higher transaction fees while almost nobody uses them.
https://en.m.wikipedia.org/wiki/Maestro_(debit_card) https://en.m.wikipedia.org/wiki/V_PayPlease
It will be phased out though in 2023 to Mastercard debit and visa debit so likely in the future Netherlands payment system will be more aligned with what other countries use.
That sounds like an absolutely terrible idea. Why would we give these two rotten-to-the-core companies such power over our payment systems?
Maestro and V-PAY already _are_ owned by those two companies, and are debit cards. What changes with Mastercard/Visa debit?
:-)
From my personal experience, there were roughly about 80% of shops in NYC, up until the beginning of pandemic, that did not accept contactless or where it did not work. One particular supermarket next door had the proper POS for 3 years and it still wouldn't work even this May when I left.
The restaurants were even worse.
I always forget about contactless. I think all my cards can do it? Not knowing for sure is why I never try, and just stick the card in the slot, which always works.
I think I've paid with my phone one time ever. For some reason I can't bring myself to trust it to work 100% of the time so I can leave my cards at home, at which point I may as well just use a card since I have 'em anyway. I guess I could start carrying phone + cash as a backup and skip the cards, but that's even less convenient. I do activate the payment screen (iPhone) all the time by accident, though I couldn't tell you how.
(I'm not even that old...)
I generally pay with the apple watch if the store supports it (most seem to, nowadays). It is more convenient than reaching for the wallet since the thing is in my wrist anyway.
I always called this "chip". My UK friends called it "chip-and-pin" in 2012. But yeah, no idea what the technical or widely-accepted colloquial terms are.
> Not knowing for sure is why I never try, and just stick the card in the slot
Yeah, for some reason the UX for contactless is terrible. Sometimes something will show four evenly-spaced green lights (and sometimes they're blue--in any case, why does that mean "contactless"?) but often those lights don't appear until you attempt a tap-to-pay and then they might be delayed by several seconds. And even then, occasionally the hardware malfunctions and can't actually handle tap-to-pay. These hardware failures seemed to be way more common in the early days, but now almost everything does support tap-to-pay--you just often can't tell until you try which is just the dumbest thing ever.
> I think I've paid with my phone one time ever. For some reason I can't bring myself to trust it to work 100% of the time so I can leave my cards at home
I definitely do it as a last resort, but I've done it a few times (e.g., if I forget my wallet). Mostly on iOS I'm often trying to pay quickly and I try to activate the contactless payment but I'll end up turning my phone off or I'll try to bring up my card before my phone is close enough. The uncertainty always makes me feel way more anxious than it should and it's just less stress to use a card (cards also don't run out of batteries).
Having an Apple watch helps out a lot here. I can't do it on my phone either, but on my watch it is trivial.
Whenever "your transaction" begins at the register could be when you're eligible to present your payment to the terminal.
Fred Meyers here in WA still doesn't support contactless payments (QFC, owned by the same company, does, however), annoying since I still have to shop there often.
Some Freddy's do, at least intermittently. A few weeks ago, the one in Lake City had it enabled on their pads at the self checkout and I successfully used tap. But when I went back a week after that, tap was turned back off.
Kroger uses their smaller brands as testbeds for stuff and since QFC is somewhere in the bottom five for size-of-Kroger-operated-brands, I guess it makes sense.
It’s annoying I have to carry a credit card, driver license (WA doesn’t support digital licenses yet), and an Orca card (also, annoyingly not phone compatible yet) in the wallet MagSafe attachment for my phone.
Yeah, that was my experience as well.
> Fred Meyers here in WA still doesn't support contactless payments (QFC, owned by the same company, does, however), annoying since I still have to shop there often.
I've largely had good experiences all over the midwest, but there are a few Stripe card readers that advertise "contactless" but don't actually work (probably misconfigured?). I've been traveling around AZ recently, and I've found a few POS terminals that don't support contactless at all, strangely. But overall they seem pretty widely available.
The tech was mostly there a while ago, but hardly universally supported. This is one tech area where the US has definitely been notably behind the curve.
Besides that, literally everywhere allows contactless payments. Even Visa/Master is changing their card designs to move vital information to the back of the card to prevent information theft via hidden cameras or a very keen eye.
In my experience on such rare few occasions I was able to tip with Venmo.
I'm sure whatever country you're from (or otherwise alluding to) is a fine place, no need for the transparent insecurity. :) Narrowly, I agree that secure (and fee-less) bank-to-bank transfers would be preferable to CC.
> They are required for the CC transaction, this adds an additional player that should not be necessary.
We're positing a situation where CC's aren't available, so it's not an additional player but rather a different player.
A misstatement by me, still they are extra to what should be a bank to bank matter.
Good thing is you can actually use Apple Pay, I use my Watch to pay for stuff all the time.
You have to have a foreign bank account that supports it, I use Wise since it allows Turkish customers.
Of course huge amounts of stores offer contactless paying, but generally Cash is still dominant around here. Change is slow, and currently, Cash is still king, especially with small or street merchants.
For many small businesses non-tax registered money is the lub which makes them run well.
Jokes aside the price of getting a card terminal where for many businesses completely unattractive for a long time and often still are if put in context to the number of people which will use it.
I know one local takeaway which stopped accepting card payment after their terminal broke recently, as it wasn't worth it to buy a new one. Instead they now allow sending money by PayPal, but non-advertised and mainly for a single specific big recurring customer and sometimes if someone doesn't has cash with them.
Smaller stores or restaurants, forget it. Bring cash.
Beware, since covid, use of cash has dramatically fallen, last month a restaurant struggled to give me 2€ change, they didn't have 2€ in cash ! Paying in cash with the right amount should never be a problem though.
Spend is kinda hilarious - in supermarket checkout "can I pay $150 in cash and remaining using card?" just so you don't have to deal with coins.
It's weird getting pitches from US FinTechs that are solving problems that literally only exist because of how painfully backward that US financial infrastructure is.
I can't wait to live in a 100% cashless society but I do think that the process should be refined (especially for phone payments).
Atm I tap and often have no idea if I'm really paying exactly what I should be. Credit card/debit numbers should only ever be temporary and for a given amount to a given merchant (like how my bank requires generating an OTP when adding a new payee). Confirmation that we are paying x merchant £y is definitely required.
Current system is really weak in that if someone has my credit/debit number they can arbitrarily charge me, in the UK if someone has my sort code + bank they can use that at a business to create a debit request and I get arbitrarily charged.
However, most merchants now have terminals that accept contactless mobile payments without a limit -- Tesco were one of the last to upgrade. So if you pay with your phone then you're back at risk of forgetting your pin.
I'd quite like it if there were some mechanism for setting device spend limits, as my smartwatch will do payments but with only a pattern for security it doesn't matter that I'd be happy only using it for sub-£5 payments: it'll quite happily authorise much more.
I used this payment processor in utah in the early 2010s at Jamba Juices and a few other random places. It was pretty sweet but its name was Isis and that was right around the time Isis started becoming big and I believe they ended up dying off.
Avoiding the Isis name was even enough to change the story line for the animated show Archer.
Pretty impressive backwards compatibility, although I think the original copy-to-paper mechanism is finally being phased out, since some new credit cards no longer have raised digits. (My new Visa from Chase has the digits on the back, and they're only slightly embossed and not in the same place. Probably wouldn't work with the old swipers.)
I wonder how long until magstripe is phased out?
5 payment modalities with a thin piece of plastic.
In the Authorisation step, the merchant on behalf of the network can decide whether you, the supposed card holder, are authorised to make this payment. For example if you have Chip-and-PIN this is the step where a PIN failure means they won't give you the bottle of whiskey you just pointed at through the glass.
To be effective Authorisation must happen up front. With Chip cards, (and also contactless payment) this can happen even offline, because the Chip can carry policy decisions like "Offline payment of up to $10 each time, $100 total before I talk to the network is OK, after that No more until I see a network" inside it.
Impression machines were the very most rudimentary type of "Authorisation", the impression recorded is some evidence they actually saw your card. Or a card embossed with the same numbers, at some point. Modern networks don't want the useless paper trail which results, but some impression machines are still out there and hey, it felt like a "real" card payment. The fact they're essentially useless doesn't matter because...
The Settlement step is separate, and often happens hours, or even days later. In this step the Merchant says, hey Payment Network, I'm Some Big Merchant and I want $123 from your customer #9876.
You might think, aha, and now they provide details from that authorisation right? Right? Nope. It's totally unauthenticated, subject to all manner of glitches and mistakes, and it is based entirely on trust. The big merchants are rich, so, if they sometimes lie and steal that's OK. Whereas if you, Mr Wage Earner, don't pay for that can of Pepsi, you're a criminal and you're going to jail.
If some merchant in say, Spain decides you just spend €546 on a TV with your card, even though you've never visited Europe, that just works. Left to itself, €546 plus conversion costs goes on your card account. To reverse that you'd have to notice the €546 charge, call your bank and complain about this clearly fraudulent card transaction. They're not always going to magically detect it, they should have some anti-fraud pattern matching e.g. if that store suddenly claims everybody living in your town in Ohio bought a TV from them, that's suspicious, it probably doesn't go through, and hey if you never visited Europe maybe that's enough to block it, but not necessarily. The responsibility sadly always stays with you to report any bogus transactions that get through even though the Card Networks made barely any effort to prevent fraud. So, read your card statements.
Master card said they will start phasing out mag strip in 2024.
Soon enough tap/dip will be the only way.
Cards still have magstrips on them but I can't remember the last time one got used. Maybe a gas station.
Australia has just 6 banks. And they have a history of collaborating on things like this - since a fluid economy raises all boats, and fraud hurts them all. All Australian cards and point of sale systems support chips and taps. And have for nearly a decade.
Was? Most of the ones I use are still magstripe-based ("remove your card quickly"). Only occasionally it says "leave card inserted" which is where (I assume) it's talking to the chip.
But the chips are relatively flaky and often don't work. At least here (California) after three failed chip communication attempts, the terminal allows a magstripe swipe instead as a backup. Happens quite often.
Each year there seems to be fewer reasons to carry a wallet around. Cash? Killed by covid. Card? Apple Pay. Drivers licence? There’s an app for that. It won’t be long before wallets are entirely useless.
You'll want a Faraday cage for any contactless cards.
And when the pressure-stamp machine broke, the merchant would use a pen, and write the card number by hand. No problem.
I've seen this still happen occasionally in taxis - or rather I saw it happen within the past decade. When I last lived in the states I'd bump into it especially with rural taxis - I assume it's dying quickly though because it's incredibly inconvenient when compared to paying via an app or tapping.
The lack of raised digits is actually a serious issue for legibility, I've had the digits fully rub off on some flat-printed cards - this may have been a low quality printing issue but either way I wouldn't applaud it being adopted since the raised numbers make it easier to read by eye.
On the back though it has a lot of details about the account, who I am, validity and so on, so all the same data is on the card, just not on the front and not embossed.
Current era bank cards aren't bright enough to change their numbers though, many of them are scarcely "smarter" than they were when they were completely passive, just barely enough going on to make it trickier to counterfeit them, not really any attempt to actually make that truly impossible for the majority of banks and customers. From the bank's point of view if they spend $5 per card to avoid $3 per card of fraud, they wasted $2 per card, and if half that fraud lands on the customer (because Mrs Smith didn't notice or the bank successfully prevented her claiming her money back and blamed her for the loss instead) they wasted $3.50.
The Apple card doesn't display the number anywhere on the card at all.
(Edit, just to clarify - I get out of the Taxi on the other end guilt free because the driver lied to me about payment options. I don't like skipping out on service payments - I think people should be paid fairly for the work they're doing (even if I could get away with not paying)... but if you're lying to me you're doing me a disservice)
It was super depressing at the time to hear the Libertarian crowd come out in staunch defense of this program.
1. https://www.independent.co.uk/news/world/uber-uses-secret-pr...
Look up the definition of "regulatory capture," and you'll see a photo of a taxicab, or at least you should. When the law does not respect the people, the people will not respect the law... nor should they.
We didn't have cash, so we just left. The woman was furious. We hadn't received our food yet, but it was already being cooked. She screamed at us to go to an ATM a few blocks away, get cash, and come back. We just found another restaurant. If the card hadn't worked I would've felt bad and probably done that, but she wouldn't even try it. Don't advertise that you take credit cards and get mad when customers try to use them.
Just because the terminal has a magstripe reader on doesn't mean her merchant account provider accepts it. Plenty don't, or some transfer the liability to the store in that case.
> If the card hadn't worked I would've felt bad and probably done that, but she wouldn't even try it. Don't advertise that you take credit cards and get mad when customers try to use them.
In 2014 a card that doesn't have a chip might as well be broken. I don't think you can put this one on her.
Chips were basically non-existent on US cards in 2014.
I'm not Norwegian but it'd be pretty similar up here in Canada at this point - if your POS terminal gets damaged and your mag stripe reader breaks there isn't really a big reason to immediately shutter your store and replace it.
2014. I don't remember with 100% confidence, but I'm pretty sure none of my (many) credit cards had a chip back in 2014.
Stores here didn't even start installing chip reader card stations until ~2018 or so.
I disagree with this. The new-style card numbers are printed in a much more legible typeface, with more contrast than the old raised numbers. Much easier to read IMO, although the blind may disagree! I've had no issues with the ink wearing off on any of my cards.
Wait what?
I think in many parts of the world that isn't possible anymore for a long long time. Like all of EU.
It will be many years before US merchants truly phase out accepting magnetic strips.
I've noticed all the UK-issued cards I've received in the last year or two no longer have the raised numbers. Just the same details printed in ink on the card. Quite an improvement as the card details are easier to read now!
Still seem to have the traditional (but almost never used) magnetic stripe, however.
I'd say maybe it raises fraud alerts faster, but I had a friend who did this for every credit payment for like two months before she finally had them replace her broken card. (No idea why, since it was free.)
Yeah, this used to be the case (years ago) in the UK too. But now days, most card readers no longer have magstripe readers on them. The chip is the backup now in case contactless fails!
I actually had to do this in 2013! Working as a waiter at Chili's, whenever the power went out (happened once or twice the year I worked there) we'd dig out a quite heavy apparatus and make carbon copies of the credit cards. Every time I used it, my customers commented they'd never seen such a thing before (I suppose the clientele was either too young or had bad memories).
Earlier last year, I was at Shake Shack when their online payment system went down. They decided to just stop charging people (even if they had cash!) and gave out free meals. I much prefer that system.
It’s been like this for several years now - and tap to pay has basically been the default (for purchases under $100) for even longer.
I'm pretty sure it was a tap to pay with the app. I can't remember if the other device was also iOS. It was definitely not the kludgy QR codes like it is now.
I thought it was so cool, but it never caught on. I read a while later that PayPal was licensing that tech and let the license expire.
I'm currently on a trip back to Australia and I forgot my wallet (!!), but it's fine because I just use Apple Pay everywhere. It's never once been a problem.
Unfortunately this is one of those cases where being among early adopters wasn't an advantage, in many areas of Italy cash is still the only viable payment method.
cough tax avoidance cough
Also friction plays a part, Italy is the second oldest country in the World on average.
My mom uses electronic payments, but I haven't been able to teach her how to pay online or "tap to pay" no matter how hard I tried.
I won't even start to talk about my dad, who doesn't even own a smartphone or a mobile phone before the smart ones existed.
They prefer to go to the ATM and pay cash, their lifestyle is very far from globalized even though they are strongly against tax evasion and always ask for their receipt.
Ironically I've know about Telepass because my parents have been using it for as long as I can remember.
My guess is that they trust Telepass because it's backed by a (former) public institution, Autostrade, but they don't trust mobile phone manufacturers or payment processor companies as much.
I'm not sure they are completely wrong.
A key factor why all these project failed wasn't the technology. As you rightly point out, the technology was already available back then. It was mainly the vast differences in business models in the two industries: telcos and banking. The telcos were spoiled back then and expected any service to deliver a margin of at least 30%. Banks operated on a very different operating margin for the transactions. They never got that reconciled.
I remember back when Apple introduced Apple Pay many people were stunned by how little they charged. But in the end, that was their key insight to make this work. Quite impressive from a company with very high margins on their core products.
Sorry for the passion but i was involved in the mobile payment scene at the time. It was not the banks halting the development of mobile payment. It was: 1- Apple 2- MNOs (Mobile Network Operators) 3- Samsung
Apple closed off the iphone NFC api which dried up VC funding in the mobile payment scene. This is one of the reason we have QR Codes everywhere today, and not NFC tags.
To securely process mobile payment, you needed to have a secure enclave (SE) on the phone which would keep encryption keys safely. At the time, the MNOs wanted that secure enclave to be the SIM card, so they could control that space. Google retaliated by cutting some circuitry between the SIM Card and the phone: the SWI lines. Banks were charging north of a million $ to embed applications in the SIM Cards, and were charging you the same for any update. Apple at the time started charging 4 million $ as a deposit to acquire a special nfc permission (walmart and starbucks had one) to emulate a credit card.
Samsung was the worst. They were already embedding a Secure element in their phones without giving access to it. They started 2 or 3 years ago giving access to 3rd partys.
Some links: - https://developer.android.com/guide/topics/connectivity/nfc/... - https://xamoom.com/new-nfc-capabilities-for-all-iphones/
Yep, this was my experience as well, working in the NFC space at the time. Apple also basically forced the whole IoT space to start focusing on QR codes instead of NFC tags, because they were lagging technologically with the iPhone.
Apple is a company with a clear focus. They didn’t even support MMS in the first iPhone. Rightly so.
I know of multiple pilot projects and startups which where basically killed (or majorly revamped) because just supporting Android wasn't viable and Apples not showing any intention to support NFC.
The fact that the NFC we have now is missing a major feature of original NFC isn't helping either (the ability to act as a NFC card if the device it's embedded in is powered of/out of battery).
As a non-Apple-user I've never personally used the feature, but I still thought that stuff like Tap to Pay was a somewhat large selling point for the Apple Watch. So for a second I wondered if I had just been drastically misunderstanding how that worked for a long time and had somehow never actually checked/verified that iPhones/Watch could do that.
I'm down to just a 4 card MagSafe wallet (credit/debit/ID/car key), but I'd love to get to just a phone. Sadly I'm sure Wisconsin will be another 5-10 years before supporting digital ID.
Many states require that you identify yourself (presumably full name and DOB at a minimum) to an officer upon request, but I don't think that means you have to carry the physical card, just provide your identity (which can be done verbally).
Yep, Kroger and Home Depot are the biggest stores I've been to recently that don't take tap-to-pay, but there are some other national chains.
Also recently: my neighborhood florist, doughnut shop, parking garage, and hamburger stand don't take tap-to-pay. I've never been to a gas pump that does, though they all have the logo for it on the front. Every time I've inquired, the people inside say it's not enabled.
Record stores are about 50%. The one I went to most recently, I had to show them how to do it.
But interestingly, my shoeshine guy does take tap-to-pay.
I always keep at least one backup card and some cash in my wallet. I recently had to make an emergency trip to the Walgreens at 5am, and its credit card/tap system was down. It was cash-only for about a week. Glad I had cash backup so my family member's health wasn't held hostage by a technology glitch.
Increasingly public transport supports contactless instead of tickets or proprietary NFC systems - notably the whole of London supports contactless and I've not used an Oyster card in years now.
I've also not seen a card reader that doesn't support contactless since at least 2015, possibly longer. I'm not sure, but based on how quickly contactless rolled out from 2007, I suspect they'd been adding support to the hardware a well before it was enabled.
I know everyone says it but USA really needs to do better. It doesn't make sense that this is so uniquely difficult to rollout there.
E.g the most expensive device here [1] is only 120 €, and it can also print the bill. The cheapest that does the job is a mere 20 €.
The POS terminals for BlueMercury (a national cosmetics chain) are iPad Airs with a tap-to-pay reader bolted on them. This would remove that bulk, expense, and potential point of failure.
> At checkout, the merchant will simply prompt the customer to hold their iPhone or Apple Watch to pay with Apple Pay, their contactless credit or debit card, or other digital wallet near the merchant’s iPhone, and the payment will be securely completed using NFC technology
The language is a bit verbose, but does look like it supports standard NFC based contactless also.
https://merchantmachine.co.uk/contactless/
Note that some of these even have chip and pin readers for those without contactless.
Compare that to competitors in the space like Square, which costs ~$300 USD and charges ~2.6% plus a flat 10 cents per transaction.
If you're not doing over $50k in volume per month and already have an iPhone...you might as well just use the Square app and take NFC payments on your phone instead of investing in the reader (assuming you're operating in a space where consumers will readily have NFC payments ready).
https://squareup.com/shop/hardware/us/en/products/chip-credi...
Plus if your customer drops this, they're not breaking your expensive iPhone screen.
If it's iphones have reached saturation with small business owners, let's build a business on top of that already dug and locked in moat, then perhaps.
If it's offering this feature is a driver for more small business owners buying and sticking with iphones and the accompanying ecosystem, you can see how it's perhaps the smarter play to be an open platform here.
And for those even on Square Apple's ipads are still the preferred choice as far as I can tell. So there isn't much of a benefit other than fees.
For anything larger than a small fast casual you quickly run into greater integration needs with things like KDS (of which a few do use tablets, Toast, Fresh, etc, and even then I think ipads are preferred. I know Square integrates with a few of those as well as NorthStar so, I don't think they may have much to fear other than at the low end mom and pop stores.
If I go to the farmers market on the weekend, they all accept cash or tap-to-pay with a Square tap-only reader, and that’s it.
It looks like they are going through similar weird things with instant bank transfers. In Australia all the major banks just have instant transfers built in. I use the bank app to transfer to friends and they get notified. In the US you Venmo or PayPal or whatever.
The first time I was able to use ApplePay (as an American) was on a trip to NZ. In fact, the clerk at the gas station was shocked to see someone pay with their phone, even though this had been possible with Android for some time, and even though contactless itself was old hat there.
As for the SIM thing, that just depends so much on the business model and regulatory environment. Pay as you go is relatively unpopular in the US, and the availability reflects that. But it's not like Italy, where I had to hand over my passport (!) to get a SIM, or Germany, where I had to document where I was "living". I've heard it's even worse in, say, Chile, where you virtually need to be a citizen or permanent resident to get a SIM.
BUT contact free payment via card and Apple Pay contact free payments are slightly different and I’ve been to POS terminals that had one but not other. But the point was that there exists cards that don’t have nfc capabilities, including the one made by the company at center of article.
They are very, very similar that this surprises me. Apple/Google pay implement the same standards as wireless cards and it should Just Work(TM) everywhere the cards can be accepted. Obviously real life and 'should' don't always marry up.
But it was one of the big drivers of acceptance of the tech in most places - the infrastructure is already there! You probably don't even need to update the firmware on your reader!
> including the one made by the company at center of article.
Sure, but my point is that I believe that's deliberate, because they want you to use the contactless payment capability of your phone. I don't doubt there are other cards out there without the capability, I just think the apple one isn't a great example.
The US may be an anomaly here, but it always has been. The UK had chip and pin roll out while the US still had mag stripe being the most common; we slowly added chip and signature (we still don't have chip and pin), and now we still aren't anywhere close to universal in tap to pay.
In the USA maybe. Elsewhere it's already huge.
If the person who is ringing me up has an iPhone, and says "just tap this", there is a part of me that is wondering if this is the company's iPhone, or their personal device? Of course, this is easily resolved with the right surround which would remove this question, but I think it's somewhat valid.
Isn't this how it works in Apple stores (I'm not an apple person). Don't they walk around with iPhones in this big chunky yellow cases, and then you just pay for stuff through that? Maybe I'm wrong...
I don't see why you care anyway, they would be stealing from the store, not from you. You would already have whatever item you are buying.
Is the iPhone gonna print a receipt?
The merchant rings you up for $5, shows you the phone in their hand indicating the cost, and the Square Reader lights up to show it's ready for payment. You pay via inserting your credit card, which processes in a few seconds, and then the payment is complete. The merchant is no longer showing you the phone, and presumably hits "No Receipt".
However, the merchant actually has a second out of sight device that is set to charge $500 and is actually paired with the Square Reader. Because you've paid with a physical card, there's a good chance you won't notice the charge till you go to pay your credit card or check your bank account.
This would probably be a short-lived scam, as the merchant's malicious Square account would have to be linked to a bank (I think this is the only option), which would identify them. I'm pretty sure Square requires ID verification of some sort as well. So reporting this malicious transaction to your bank/credit card would flag them.
Additionally, if you're paying via a mobile wallet, you'll likely get an immediate notification saying "You paid $500 to Malicious Ice Cream Vendor".
Now let's think about Apple's new plan. It could be that Apple layer's it's own mandatory interface that shows "Pay $5 to Ice Cream Vendor" regardless of the app being used. Maybe this is actually the employee's phone instead of the company's device, but that's the same as the employee stealing cash out of the register, so not really your issue.
Or Apple could not layer it's own UI, and just open up the radio as an API. Apple could require that apps that use this API to have some additional verification to prevent someone from making an app that displays "Charge $5" when it's really charging $500.
All that being said, I only see smaller merchants using iPhones + Square Readers. Maybe some boutique stores, food trucks, etc. Once a store gets large enough, they usually want dedicated hardware, even if it's a Square Stand.
---
Here's Square's hardware page if you want visuals: https://squareup.com/au/en/hardware
Useful for double checking that something hasn’t gone wrong and I haven’t been charged the wrong amount! I’d also see if a fraudulent transaction went through.
The first time I used one of those strange little white terminals it seemed a bit dodgy ... but you pretty quickly come to trust that what's on the screen is what gets debited.
Also I doubt Apple would leave a nice app-accessible text field on the Tap To Pay dialog where I can insert my fake amount. Right ?!
I would like to go to a store where I trust the business, the employee, and the entire pipeline. I understand that is idealistic, but yes, this is how I feel. It's like saying "why do you care if the employee is underpaid, you're saving money", which describes the whole tipping culture in the US.
Why would you need a special surround? And why is that an issue for you the consumer?
I would be very surprised if Apple tried to enter the credit card processing industry. It isn't the sort of thing they're positioned to do well.
No.
It allows sole proprietors, freelancers and the like to not have to get a Square reader to take credit card transactions. That's super convenient, especially for getting a deposit from a client, for example.
It also requires a newish iPhone (iPhone XS or later device), so there will still be plenty of iPhones out there that won't support this.
We saw how it took 10+ years and a dominating market position for Apple to show their claws with controlling 3rd parties with the App Store. Make no doubt that once a significant portion of the market uses Apple hardware or services for transactions, that they will want control and a cut of the transaction.
Notice how they say: partner-enabled iOS app
This means Apple has to endorse each 3rd party, and they remain under Apple's control just like app developers.
Really? I thought Apple's position was fairly consistent and it took 10+ years for the companies using the App Store to get antsy.
The smaller fish got consistently screwed and no one was happy per se, but the sheer stupidity of Apple's recent actions do not help matters. For example, the app store cut is 30% unless you beg for scraps as a small business at which point you can get 15% until you start making $1 million. Income cliffs aren't how real taxes work (let's be clear here: Apple is pretending to be the government with taxes and fees and shadow court system of app review), they're just how Reagan demonized them back in the day.
Apple isn't Microsoft. When was the last time Apple created something consumer facing from scratch instead of using industry standards or market leaders if they exist? They generally don't explicitly compete with commodity businesses unless there's something unique they're attempting to accomplish. They do stuff just because they can.
They partnered with the banks to create Apple Pay.
They partnered with Goldman Sachs and MasterCard to create the Apple credit card.
Besides, it would be a huge undertaking to build out a payment platform like Square to compete with them. Of course they could have bought any number of payment processors if they wanted to if they wanted to go that route.
Stripe and Shopify already have millions of customers so it only makes sense to partner with them.
The obvious thing most people on this thread is this being the basis for Apple's cryptocurrency aspirations.
Tim Cook owns some and he said Apple as a company is looking into cryptocurrency [1]. It only makes sense that Apple will eventually support bitcoin and other transactions natively on the iPhone, peer to peer.
[1]: "Tim Cook said Apple is looking at cryptocurrency – Here’s what the company is likely to do" https://9to5mac.com/2021/12/28/comment-tim-cook-said-apple-i...
The M1 is also customer facing, vs partnering with Intel to make it
IIRC, Apple wanted Intel to fab their silicon, but Intel refused. It’s only since Gelsiner took over that Intel is open to fabbing other designs.
I'm too lazy to recall every detail, but it happened, often. Last exemple I have in mind is maps. As far as tech is concerned, I believe metal is their own inhouse invention?
Uh huh.
Last exemple I have in mind is maps.
They're working with several providers, including Yelp, Open Maps and Garmin. I've submitted corrections and additions to Apple Maps; anyone can do it.
As far as tech is concerned, I believe metal is their own inhouse invention?
Metal is a set of APIs for developers; it's not customer facing. Most users aren't going to know which graphics API their software uses. Apple supported and uses OpenGL for a long time and it's still available for backwards compatibility I believe.
So in those markets you will still need supporting hardware for the times you can’t accept contactless or risk losing the sale.
My bank allows for location based security. If my phone is not near the location the card is being used I then have to use chip and pin instead of contactless (dead battery, poor cell service, unable to get a decent location fix because of the building, all these can trigger the need to revalidate).
And a lot of people still don’t have banking apps on their phone (one of the reasons banks had to support SMS 2FA when implementing Strong Customer Authentication).
I’m not too sure if the banks/ Visa/MC would be too happy allowing users to enter their pins on the retailers phone as pin pads are supposed to be encrypted.
We are seeing cards come with biometrics and pin pads on them, these cards will help with “card terminal less” transactions, but both bans will have to start issuing them and card users will have to be happy using them (I still know quite a few people who refuse to use contactless at all).
So imo those BlueTooth card terminals will be with us for a while to come, they will just be used less, which is why imo Apple worked with partners who already have such terminals as a fall back for whenever contactless can’t be used.
So this allows for an iPhone/iPad/Android phone/tablet to implement EMV contact/contactless payments (obviously contact would require a physical card reader). Contactless payments above floor limits (eg in Australia $100) can require a PIN that would be entered through the tablet.
Running "software POS" on Android does not require any special "partnerships" with Google, as access to NFC is open.
https://www.pymnts.com/apple/2020/apple-buys-mobeewave-for-1...
It essentially turns an iOS device into a POS system.
Apple already gets 15 bps for all Apple Pay transactions. I'm curious to hear the additional monetization Apple plans to get for this.
Bits per second? Beets per sale? Blackened pieces-of-eight per scurvy-rat?
How on earth was what amounted to a userspace app able to talk to the NFC hardware to the extent necessary to process payments?!
Presumably the app received the relevant entitlements to be able to do this...?
How on earth was it done securely, within the Mobeewave app?
Disclaimer: I worked/work on this https://usa.visa.com/about-visa/newsroom/press-releases.rele...
> In January 2020, Visa first showcased the power of “Tap to Phone,” an industry-first solution that transforms current generation Android smartphones and tablets into contactless point of sale terminals. Tap to Phone was Visa’s first offering that let sellers accept payments on the devices they already own, just by downloading an app. As of December 2021, there were more than 300,000 devices across 54 countries using Tap to Phone.
I'm curious how the overall transaction/security flow works, broadly speaking.
It sounds to me like you managed to figure out a solution that satisfies the security posture of the ordinary app sandbox (ie without requiring any entitlements on iOS, or priv-app partnerships on Android). That's kind of incredible IMO. Are you using the Secure Enclave on iOS, and if you are, what are you actually storing in there? I'm curious if Android gets to play too given that it doesn't have the same sort of security guarantees, and if so, how.
I also get the impression the actual validation/verification (including steps that I would assume would typically happen on a payment terminal) has been moved to the cloud somehow. I'm very curious how that works too.
Presumably you would've also needed to design something capable of withstanding absolute worst-case scenarios like memory inspection on a rooted phone, or NFC sniffing/proxying/emulation.
Maybe you're just sending all the card data straight back to the cloud? That would pretty much solve everything :)
Also... while engineers are always going to gravitate towards balanced analyses of benefits and tradeoffs, the questions above are not coming from that perspective :) I'm very happy to hear whatever you can share about the security of the platform. (I'm just a random consumer who occasionally boggles at JavaCard when I pay for stuff lol)
We actually have a video that showcases the real-life usage. https://www.youtube.com/watch?v=OE6OmVd6Fxw&feature=youtu.be
A lot of what used to be done on Payment terminals are now done on the cloud.
Probably the most interesting story I read about the payment terminal space was about someone who happened to be working on an application/middleware integration and had figured out a cute way to use coroutines in C to (presumably/extrapolating a bit) multiplex the payment-online step while simultaneously settling the payment-offline step, so both could move forward simultaneously and the receipt could print almost immediately (in an era of dialup and maybe ISDN). The auditor who came out to validate and approve the middleware had a brain-BSOD and loudly protested that what he was seeing with his own eyes was not possible, and had to be convinced that the solution wasn't playing fast and loose with the spec requirements to do its thing :D
The payment terminal space seems like it was (and will probably remain for some time) an interesting engineering niche to work in (in terms of crazy application integration and whatnot). Been curious about it for a while with all the janky flickering I see on the screen when the receptionist swipes my healthcare card at the doctor's office (which can process both bank cards and healthcare cards though what looks like a custom application). It'll be very interesting to see how the banking space moves to the cloud and off-the-shelf consumer devices start to replace proprietary terminals and whatnot (and then other industries slowly follow suit, maybe, in a decade or so). I note the press release mentions this infrastructure is available in Australia, but I incidentally haven't seen this in person yet (two years on). Will definitely be keeping an eye out now, and I obviously need to start shopping at more interesting places :P
Thanks for taking the time to share about this!
https://support.apple.com/guide/mac-help/use-wallet-apple-pa...
Otherwise, you can add cards to your Mac just like on an iPhone or iPad!
I don't think there will be any extra monetization - this is presumably just an API in a future iOS 15.x that can be enabled via entitlements Apple assigns, so unless Stripe says "extra 0.3% fee for iPhone PoS payments" they likely won't make any money from it. Think of it as a funnel for getting the last 20% of businesses to accept Apple Pay.
This isn't just Apple Pay. You can tap your plastic credit card to pay using this. This is all contactless transactions, not just Apple Pay.
Obviously they are going to vet which processors are allowed, but as a consumer you want that so you can be confident that the iPhone you are tapping your card against isn't skimming your account.
I suspect there is a revenue agreement with the processors allowed on.
From a quick google: https://ieeexplore.ieee.org/document/9220841
I do also remember reading about researchers at Cambridge University who were looking at this maybe 7-8 years ago.
Either way though, this is different from skimming. Skimming allows the skimmer to make future transactions which is much much worse.
Right now with most contactless in shops in the UK you're left thinking "did they key that amount in right?" and if you're paranoid you ask for a receipt (from the machine, although merchants often drag their feet or try to give you one from the till not the reader!) and/or you check on the phone afterwards (which would be a pain if it showed an issue because by then it's a bit late!)
There will be no way of an app to display a fake payment screen in front of the real one, or accessing the NFT apis themselves. It's clearly one of the key reasons why Apple have not opened up the NFC hardware for outside developers.
The main protections against this are maximum limits for unverified contactless purchases (about €50, depending on the country) and banks outright guaranteeing customers against fraud (https://europa.eu/youreurope/citizens/consumers/financial-pr...).
No idea how that can translate directly onto phone-based terminals though. On cards, the extra-validation backup for suspicious/over the daily limit transactions is that the contactless machine asks you for your pin, but there's no way anybody should be typing their card pin into a random stranger's iPhone.
(page 18, with pages 10 and 12 showing the Visa/MC limits) https://i.blackhat.com/asia-20/Thursday/asia-20-Galloway-Fir...
You can guarantee that the merchants collateral, or any unpaid funds will be taken and used to automatically refund anyone that went near their readers, and if the money can't be claimed from the merchant, then the payment processor or acquirer will be forced to cough up.
All the card networks take this type of fraud very seriously. They understand that they only get to keep their very lucrative positions in this world if people 100% trust card readers to not rip them off, and to get easy compensation if they do. So they come down hard on businesses that threaten that trust.
That way the customer phone never actually sends anything directly to the business, and the only thing sent to the customer is basically public (sure, pay my invoice if you want...)
Skimming happens because you have to enter trusted things into _their_ device w/o any authentication mechanism for the device you're interacting with (the pump).
For example, I recently had movers. I went out of my way to get a cash tip for them earlier. It would have been nice to skip that and just ping it at them somehow without awkwardly saying "Hey friend do you have Venmo? Apple Pay? CashApp? I'd like to tip you. What's your phone number?! Let me get that, thanks, bye, delete.".
This is NFC and a bit different but just my thoughts.
Regardless of how you personally feel about US wages and the 20% I already prepaid for tip through the company to them, to be able to send money to others would be useful.
There could be other cases besides tipping.
I think an on-the-ground solution that caters to the long tail would be the only thing that would basically survive. Everything else would succumb to social forces and basically just fizzle out.
AirDropping Apple credit could be an interesting pilot study, but I doubt Apple would do something like that sadly :/
Personally I also find it exhausting to have to judge every single service I get. So I just tip a standard amount, there’s absolutely no feedback involved. So there is no point.
There are lots of downsides with very few upsides.
For situations that aren't codified into law like that, it can more legitimately be modulated according to how the service made you feel, from zero to "keep the change" to a couple bucks to sky's the limit.
The former should be solved by abolishing tipping. The latter should be solved by technology that's somehow as frictionless as cash.
The law does not allow for sub-standard wages, however. If everyone stopped tipping today, wait staff would get the same minimum wage as any other job.
If an employee lets their employer know they did not earn enough tips to meet minimum wage, then the employer must pay them more to ensure they get minimum wage.
Also, in many jurisdictions of the US where the same minimum wage applies to traditionally tipped employees, the tipping dynamic has remained. For example in California, Oregon, and Washington, the cultural expectation is that customers will still tip waiters, even though the waiters are earning the same minimum wage as everyone else.
However, I think the point being advocated in this thread is that businesses should have to pay minimum wage (before tips). That said, it would be interesting how employers would respond if that was required by law - since removing tips would not save the employer any money, I wonder if that would result in less hiring.
Generally, restaurant prices are higher (minimum $25 per meal per person without alcoholic drinks), but tipping is still expected by the waiters for waited service. Bottom line is waiters earn more money, but possibly fewer people can afford to eat out and maybe there are fewer waiters overall.
I dislike waited food service anyway, I much prefer to just buy at the counter and bus my own table, and it might result in more restaurants like that.
Not only will the personal service be minimal, but the only part you can even judge at that point is how well they took your order... who knows if something will go south! So it's clearly just about keeping menu prices artificially low.
If it was not there, then depending on who I was with, I would either walk out or eat the cost and then never go back and leave a review that says they bait and switch pricing.
Tipping is about price segmentation / discrimination. Good for the seller, bad for the buyer.
Clearly, you have no idea of how the moving industry works. Everybody's a contractor of a contractor of a franchisee. The person who picks up your stuff is not always the person who delivers it.
When I move (frequently), I make sure to tip each person packing my stuff $50, each person loading my stuff $50, and the driver $100 for < 1,000 miles, or $200 > 2,000 miles.
Lifting and carrying and handling other people's prized possessions isn't an easy job. This is how I show appreciation when the job is done well.
It's really no answer to say I need to understand how each industry works.
Why would I? And why should I? It's the government's responsibility to understand the nuances of, and regulate, each industry.
Do we really want to live in a world where consumers need to understand the detail of how each industry operates so they can ensure sub-sub contractors can be remunerated appropriately?
"Teach a man to fish," they say, and I believe I did it on that day. I encourage everyone else to do the same.
What specifically did you have them set up?
> By the end of the exchange, they were both very happy with the arrangement and thanked me profusely for setting them up to use the future of currency, although I was still in the process of explaining its importance.
https://www.newyorker.com/humor/daily-shouts/l-p-d-libertari...
This is satire, right?
My bank is digital, it doesn't have a local branch, and most ATMs around me dispense cash in $20 bills. So I can make a small purchase near the ATM if it's in a shop and then ask them to give me change in smaller bills, but usually there's nothing I want. I don't have a local branch to drive to, but maybe other banks would help split bills? It's not awful, but it is pretty inconvenient.
Of course, the way to fix that might not be for everyone to standardize on iPhones, it might be to just have more ATMs that dispense smaller bills. But I do see why someone would find tipping primarily over, say, Venmo preferable, even though I don't think that appeal is enough to outweigh the benefits of cash tips (privacy, universal compatibility, simplicity, etc) in many situations.
Or I could just start tipping everyone everywhere in increments of $20 bills I guess, but I'm not that generous.
----
[0]: assuming you did actually mean it as an analogy for dropping cash for digital payments
If I was a bit more consistent about occasionally just paying for something normal with cash it would possibly be more sustainable, right now I usually try to break apart small bills specifically when I'm completely out of them or when I know I'm going to need to tip someone in like an hour.
Also yeah, having a stockpile would probably be a good idea, since right now I typically only keep enough small bills to get me though my immediate tipping needs and no further, so any surprise situations mean I'm immediately out of small bills and can only pay for things by card.
Regardless, definitely more management than I would like to do, so I get why people might want a system that doesn't force them to think about that stuff at all. It's just that the alternative digital systems come with other downsides.
I also had movers, and wanted to tip them. When I asked what they took. I was shocked when they said Bitcoin!
They said some person that they had helped move before had helped them set up bitcoin addresses.
They were so excited by this. It was also pretty easy to convince them to read me both their public and private keys for those addresses (I told them that if I sent it to their public key, it would be public so their boss and the IRS would find out, however, if they gave me the private key, it would be completely private).
I then tipped both of them $50. They were so overjoyed.
Then later that night, I emptied both of their wallets.
(By the way, to the OP, thanks for teaching them about cryptocurrency, and for the $10).
/s just in case anybody is confused
Let's not turn hn into a discord channel about how crypto is going to disrupt all the things and make them more "decentralized" by having "federated exchanges" that allow you to "stake" your assets where, otherwise, it would be impossible to form a "liquidity provider" since, of course, without it why would you even want to live.
I'm surprised all you got was a "Bless you, bless you" response and not a shiv or a fist sandwich.
I'm talking museums asking for donations. To street performers in the tube. They're everywhere.
For context: I don't know if they're a thing in the States but in most male toilets in nightclubs (and more 'clubby' bars) in the UK there's usually an annoying guy in the toilet who turns off the hand driers and gives you paper to dry your hands whilst passively aggresively demanding a tip in return for a lollipop or a spray of various aftershaves/deoderants.
I know that would open them up to lots of KYC requirements, as well as require them to do some of the evil things that financial laws require (eg. tracking all payments, closing accounts and banning users for certain things while not being able to tell the users why, freezing users money till they can present documents they don't have, etc.)
But it still seems worth it to take over the payments space from venmo, cashapp and paypal, make the wall to switching to android a little taller, etc.
I totally agree.
At a parking garage the other day, there was a long line of people trying to get their cars back from the valets because one person was trying to tip with some random app.
"Oh, you need to download this. Yeah, open the App Store. Then download it. Yeah, it take a while. OK, now sign up. --five minutes elapse-- OK, now what's your username so I can send you the money? Did you say 'e' or 'v?' Was that '4114' or '1144?' OK. Sending now..."
It took like ten minutes.
- Stripe as the first user of the SDK vs Square: For any small business starting this spring, I can't think of a reason why they wouldn't use and iPhone+Stripe to start off. Zero hardware cost (assuming they have an iPhone), no need to wait for hardware delivery.
- NFC will be coming to the iPad.
- The ability to keep the same hardware but switch payment network lowers switching cost for small businesses. Payment platforms will have to differentiate on ecosystem as well as cost.
Stripe's bread and butter is payment backends, while Square was the point-of-sales system
Before smart phones and generic hardware was a thing, I worked at a company that wrote software for field services (“sending people places to do things”) we had to resell and maintain custom ruggedized windows mobile devices, mobile satellite receivers (cell phone data wasn’t reliable), etc. We were glad to transition to generic smart phones. At later jobs, when I worked in the same space, we used generic Samsung Android tablets.
Microsoft doesn’t even really care if you buy an XBox, it’s a loss leader. They would be more than happy if you bought their subscription gaming service and ran it on someone else’s hardware.
You're right, but it's a strategic mistake. Hardware comes with more loyalty and brand awareness. How many consumers are aware of Square (cute little hardware squircle) vs Stripe? That brand awareness allowed Square to launch Cash App.
I think this extends to the rest of big tech too. Amazon and Facebook would do well to learn from this. Amazon and Facebook's most favourably viewed products are all hardware (Alexa, Kindle, Oculus)
Apple is bad for business. When they come to your industry, be afraid.
Software companies like MS, Adobe and most of the streaming services don’t even allow you to pay for access through the App Store.
Anyone selling physical good if they are using any sort of Apple payment, they are using Apple Pay and paying standard credit card processing fees like Uber.
As far as Tap to Pay, they are charging the standard merchant amount that all other payment facilitators charge.
As far as “owning your customer”, I don’t want every Tom, Dick and Harry to have my personal information. I use “Hide My Email” whenever possible. Owning your customer also means jumping through hoops to cancel (see NYT).
Yes, Apple is huge multinational company that pays a little taxes as it can legally get away with; however, as of 2017, it was the largest tax payer in the world: https://www.apple.com/newsroom/2017/11/the-facts-about-apple...
I mention Zettle because it's hugely popular in the UK. A lot of market traders use them, which has probably saved a lot of businesses that would traditionally be cash-only. COVID has helped to encourage cashless purchasing too. Europe generally has always been pretty ahead with contactless payments (Zettle was a Swedish fintech before PayPal bought them).
https://9to5mac.com/2014/10/24/nfc-ipad-air-2-secure-element...
Maybe because of this they will add it to new iPads going forward.
If they transact like a credit card processor, there are fees.
This is setup so that you can run an existing merchant app (launching with Stripe) and collect money with all of the same fee requirements as using stripe normally.
edit: typo
That being said, I use Apple Pay all the time to send money between my partner and me. It is tied to iMessage but since we are always texting anyways it is super convenient. But the convenience may largely be due to already having my payment information as part of Apple Pay to begin with. But it just uses my debit card to send money, it doesn't need access to my bank account.
FedNow instant payments will provide coverage for all US banks within 2-3 years.
so its a non-starter for me.
although one time I did a chargeback on a Venmo transaction, and Venmo banned me. that was an inconvenient few months before I maybe tricked their system. maybe as in I'm not sure they are just tolerating me.
A couple reasons when eating that credit card fee is worth it for me:
1) Although it is accurate that paying the merchant fees yourself as a consumer makes it a loss on the credit card points, the points themselves can have a much higher exchange rate with transfer partners, which makes it not a loss. For example, with the credit card company their points are range from a value of half a cent to 2 cents each, a hotel or airline may have a fixed exchange rate based on a different metric such as quality or distance, that is completely decoupled from the current dollar value of the good and service. (ie. a fancy hotel might cost $300 one night and $1,700 another night, but only costs 25,000 points all nights. better to just have a balance of points)
2) Many of my purchases are expenses I deduct against my taxable earnings, and that makes me less price sensitive and more spend sensitive. The points I can use solely for my consumptive activities, which makes play time free.
If a rando retail person pulls out their iPhone and asks me to tap... that's kinda strange in my mind. Something about "how do I know that isn't their personal phone?" would pop in my head.
But things that seem awkward can become commonplace.
Like a work uniform, it doesn't really serve any immediate purpose but it gives the transaction authenticity.
Why would that be a concern to you?
Either way you pay, get receipt, take your goods, and leave. It's not like you are stealing.
Are you worried the clerk would MITM your payment and leave you without normal return/refund policy, since it wasn't a legit transaction?
This flow summarizes almost every transaction I have had at Banana Republic, Gap, and the Apple Store, to name a few retailers. I have not had reason to distrust the clerk, disheveled or otherwise. Once I receive a notification from my credit card that an entity with the same name as the store has posted a transaction to my card, I walk out the door with my purchase. I have not once thought (or cared) about the store receiving the money once I am out the door.
What's the reason for the distrust?
In every experience you describe, the device they use is not just a standard iPhone. It usually has a special case with a card scanner and reciept printer for starters. At the Apple store they wear apple badges and have branded clothing. I haven't been to the Gap in a long time, but I'm guessing they have some sort of way of identifying themselves. You even said yourself you wait for the notification that you were charged by the right entity name, which is another clue that you made a legit purchase.
I have no problem making my purchase from someone with nothing more than an iPhone, as long as there are other clues that they actually work there. But I do feel it is my responsibility as a member of society to at least attempt to verify their veracity.
- Our inventory system went down so I have to type in your total
- All set, it just automatically e-mails you the receipt
- (Who are you?) Corporate sent me, I'm in a different store everyday
This has probably been done before.
Sure, it's the store's job to make sure people aren't impersonating their employees and stealing their receipt papers, so that's on them right?
That being said, the Apple store has security guards up front and it's generally a pretty small space where someone faking it would be noticed.
The Apple system is not set up to skim either way, and if they have a good or service you want, just go through the motions. This is as secure as it gets.
Is it just me feeling that Apple is again playing gatekeeper to iPhone APIs and hindering true competition by "working with leading platforms" aka. the big players, like Stripe or PayPal, essentially leaving startups and smaller players disadvantaged.
Why not just finally open the NFC API?
Or why not provide an extra approval process for the NFC API?
On the other hand they were not so concerned with bad actors when releasing AirTags.
Feels more that it's about control than safety and like that kind of decision that got them into all the antitrust probes in the first place.
And providing extra approval process for the NFC API is exactly what they're doing here.
AirTags actually have a lot of design in them to thwart bad actors so your comment there is incorrect or ignoring all the anti stalker measures in there.
Not only must you be reviewed by the App Store, but your app will require security entitlements to act as a payment processor. And you'll have to be a registered Apple developer in good standing.
If a malicious actor went through all this trouble to grab some transactions, they'd be shutdown within hours of the scam and Apple would refund the money.
Also, who's going to trust or want to use "Bob's rando payment processor"? No merchant is going to do that.
In this case, it's a different sort of application that provides the merchant side of the EMV transaction, provisioned as part of the PCI SPoC standard (https://www.pcisecuritystandards.org/assessors_and_solutions...).
SPoC relaxes some of the physical security requirements while enhancing online monitoring (of the application and security of keys etc) and approval of an end-to-end implementation.
So the SPoC standard will allow merchant side payment processing without needing specific PA-DSS compliant readers etc, because the end-to-end between the secure PIN reader (SCR-P standard) and the SPoC monitoring replaces that.
(Interim while the above URL currently doesn't work: https://web.archive.org/web/20200217151824/http://ramtin-ami...)
The author(s) maintain the site out of personal interest.
It's very amusing that as you get to the bottom the "Vulnerable to" starts to disappear :) and yet you can download the bootrom anyway~ hmmmmm :D
I thought most bank cards used RFID per se as opposed to full NFC.
Plus (and much more significantly) there's the fact that the phone is doing the magic voodoo sekret handshake thing that has been the stomping ground of credit card terminals for only the past two decades or so.
My understanding was that Apple Pay stuck Apple in the middle as an intermediary to the payment, which was internally settled via backend servers. I *think*. I don't think the phones behave as credit cards in the strictest sense - my (pulled out of thin air) guesstimate is that it emulates a credit card to the extent that it make the payment terminal happy, but in such a way that the actual payment settlement is done out of band. Or... something.
Hmmmm, maybe something similar is going on here, where the phone talks the protocol but not strictly exactly the way a payment terminal would, such that Apple ultimately intermediates the final settlement of the transaction.
I feel super dumb here, mostly because this whole world is (sigh very understandably) clandestine. I would be very interested to learn about any high-level "oh okay!" type info on the subject that might be out there!
other digital wallets = crypto?
Yes! WWDC should be pretty interesting this year: https://9to5mac.com/2021/12/28/comment-tim-cook-said-apple-i...
A few months ago a street vendor was selling a book he had written. He seemed like a nice guy and I wanted to support his initiative. The book was only $10.
He didn’t take cash, nor Venmo, nor PayPal. He took cash app, Apple Pay and a bunch of other things I had never heard of. I don’t use cash app and wouldn’t sign up just for him.
We tried to use Apple Pay but couldn’t figure out how to add his contact info and send money. I’m sure we could have eventually figured it out, but we gave up. He also had an android phone with some apps there but couldn’t work with my iPhone.
This sounds like it would have been really useful. I’ll settle with “just give $10 to this person who has an iPhone, I don’t care about anything else” as a step closer to “just give $10 to this person who has anything”
Apple pay is not a big improvement on normal tap to pay, although it still feels cool 5 years later to pay for stuff using my watch. The gamechanger exceptions are:
- Transit. I can use my watch/apple pay for transit in many cities. From experience, I have only used it in 2 cities. Slow and annoying in Vancouver, but much less annoying than the alternatives. In Japan, instant and more convenient than using my suica card or suica function of my phone. Back in 2016 I bought an Apple watch within hours of learning that it supported suica. The only slight inconvenience is that I prefer to wear my watch on my left hand, and the card reader at gates is always on the right.
- Online commerce. Only twice have I had the good fortune of finding something I wanted to buy online available using apple pay. But wow, was it a good experience. No login[1], no entering my address or details. Just approve apple pay by fingerprint or faceid, confirm my address, and wait for the goods to arrive.
[1] I have a common name, and an email address several dozen people think they own. Making a new account on any site/service is a nightmare. If I can even make an account, Logging in 1 year later is usually impossible because someone has tried to reset "their" password 50 times. Fixing an account on any service that profits from its users (eg venmo) is usually impossible. They won't cancel an account misusing my email so long as the transactions go through.
I don't really understand why a merchant would use this feature.
If you already use a PoS, why would you replace it with another one that only supports customers who own an Apple device?
If you accepted only cash, maybe it's a small improvement because you can use your existing iPhone if you had one to accept cashless payments from Apple customers...
Does Tap to Pay only make sense in the second case or am I missing something?
It's not only Apple Pay:
> US merchants will be able to accept Apple Pay _and other contactless payments_
What makes you think it only supports payment from Apple devices? The press release is pretty clear:
At checkout, the merchant will simply prompt the customer to hold their iPhone or Apple Watch to pay with Apple Pay, their contactless credit or debit card, or other digital wallet near the merchant’s iPhone
Did you read the article?
At checkout, the merchant will simply prompt the customer to hold their iPhone or Apple Watch to pay with Apple Pay, their contactless credit or debit card, or other digital wallet near the merchant’s iPhone, and the payment will be securely completed using NFC technology.
This will accept contactless cards, Google Pay, etc. as well.
Imagine if there was a regulation that required interoperability. Or if the banks were forced to allow (authenticated) payments between systems without transaction fees.
We're 20 years overdue for this.
https://usa.visa.com/about-visa/newsroom/press-releases.rele...
Note: I worked on this
Apple-style solution to this is to buy Apple Watch which authorizes payments without face scanning.
However, you should be able to hurry it along to prompt for a password. Apple doesn’t make it easily discoverable, but if you tap on the status message when it’s trying to decide whether it recognizes you, it will prompt you for a password instead (while logging in, and I imagine during Apple Pay as well).
That is why you will never be able to give money to a friend this way. You give $100, but they receive $99. They give it back after a week, and you receive $98.
I was second in line behind a younger guy who asked to use his iPhone tap to pay, the clerk shrugged and pointed to the card scanner. Guy taps his phone and the scanner bricks, hard. The young man was somewhat embarrassed for holding up the line and sheepishly dug some old school greenbacks out of his pockets to pay before slinking out the door.
The clerk confusedly tried without luck to recover the register, before giving up and asking me and the other 6 people in line to move to another register. I had a little mini panic because all I had was a card, no cash, and about $20 worth of snacks. What do we do when electronics fail?
Apple declined to be part of it and thus it was expected that they release there own version soon.
Now they are directly allowing payments from the phone. No need for readers at all. Next will be the iPad as the integrated terminal with NFC and no external equipment.
But there remains the next one. Cryptocurrency payments which both of them are still in.
Square is down 61% since October.
Square is an instant POS that small business owners can use to accept payments for their shops.
Stripe Terminal allows platforms and tech-forward companies to integrate with the Stripe API—to deploy and customize in-person payments for bespoke checkout flows (think Shopify, Lightspeed, or HouseCall Pro).
Teladoc is down 77%
Fastly is down 77%
Pinterest is down 71%
DraftKings is down 70%
Zoom is down 69%
Palantir is down 66%
DocuSign is down 62%
DoorDash is down 61%
Twilio is down 57%
Twitter is down 55%
Roblox is down 55%
Etsy is down 54%
DigitalOcean is down 53%
Shopify is down 50%
Cloudflare is down 50%
Unity is down 49%
Netflix is down 42%
CrowdStrike is down 39%
Okta is down 36%
Atlassian is down 35%
Salesforce is down 31%
And so on. The air also continues to leak out of the meme garbage stocks.
For ~6-8 years there was 24/7 talk of: "is the bubble ending? when will it end?". Then the bubble actually ends and everybody stops talking about it - because it finally actually happened and that's a lot more terrifying than speculating on ifs and whens. Trillions of dollars in paper wealth are going to vanish. A lot of these hyper multiple tech stocks are about to enjoy a long stretch of compression with far lower to negative returns, in the style of the post Nasdaq bubble years.
Or is it more akin to the BBPOS Chipper readers and still needs a custom mobile app to interact with?
ie: can a platform built on Stripe use this for their customers without needing to supply a mobile app?
As a future product option I'd love to be able to treat these as standalone terminals, so we can offer a web based POS app (running on a different device) and the phone as a payment terminal without having to deploy our own mobile app.
It's possible to do this through a process called "personalization," where in general, a secure element has "initialization" keys that are installed at manufacture, but then the keys get updated (personalized) once the user gets it.
I'd speculate that Stripe could get integrated using a personalization protocol, with new keys over the existing protocols, and not require its own intitialization keys in the SE. A further speculation would be that Apple's pay partnership with GS may have facilitated a different protocol that uses more manageable asymmetric keys for doing reconciliations, and all the complexity is in integrating with generic payment terminals, whereas for anything that doesn't depend on that, you can use more sensible protocols that aren't freighted with backward compatability to chip/pin cards.
Square would probably be the easier integration, but Stripe may have some secret sauce for this. Anyway, wildly speculative, and would be interested what's way off in that.
I know you could theoretically use Zelle/Paypal/Venmo, but it seems much easier to just be able to accept a card payment. Plus, I wouldn't have to give strangers my email, phone number, or username, which would be needed for those payment methods.
PayPal allows free C2C transactions that are much higher in any case.
The only issue would be liability shift for a card that has EMV but doesn't have contactless and thus has to be processed as magstripe, but those cards are getting rarer as most issuers are replacing with NFC-enabled ones.
With this announcement I can very much see Square being removed from the equation in this small business without fixed store front scenario.
Eventually they'll just be an app that runs on the phone, making it significantly easier for a business to signup to use their service.
Now small cafes, tradies, etc getting on their feet can use the hardware they already have to start processing straight away.
I ripped this off some marketing material that I found for a popular EFTPOS terminal in Australia:
A merchant service fee is a fee you pay to your EFTPOS provider to process your transaction payments. This fee is calculated as a percentage (or fixed fee) of every transaction where a customer swipes, inserts, or taps their card at your terminal.
For every transaction, your bank pays fees which include: a fee to the issuing bank (e.g. the bank that issued the card), the scheme fee (e.g. Visa, Mastercard, EFTPOS), and the switch fee (who processes the transaction).
Is it possible that "contactless" actually refers to lack of electrical contacts (i.e., not using the gold pads)? We already have plenty of words for this idea: radio, wireless, inductive. Or is the intent to mean no physical contact whatsoever such that a tap would only be accidental?
The reason why the users are instructed to slam the card or device is because users fail to perform required actions if simply told to hold the card or phones just right. Spatial cognition isn’t a forte for many.
The reason why tap is used in VISA contactless over touch is probably because Suica system used by JR East uses the phrase “Suica is touch 1-second”.
I always assumed the term tap to pay caught on since the early EFTPOS terminals had the NFC antenna in a separate portion of the terminal, or under a non-touchscreen panel, so the tap of a credit card wasn't detrimental to the user experience, and now we're stuck with the term.
It's three syllables, it rolls off the tongue when you say it, it takes maybe 450ms to speak, and the brain can encode it using similar (or maybe the same?) mechanisms to how brand names and word combinations are captured without parsing/questioning when very young. This is one of many factors that contributes to a sort of "flow" that combats the "oooooooooh that sounds complicated"-of-death that stands to kill new complex digital products that need to be adopted en mass to function.
"Tap" also encodes "move near reader" but does so by suggesting that you move too close. Thus you'll either have people moving well within the active area (at which point the transaction may even be able to start and complete by the time it's been tapped). It's also physically easier for me to physically execute "tap object against other object" than "hover object 1cm in front of other object", especially when moving.
If you want something to scale, you need fail-safe design. My local bus transit system has a giant (but featureless) NFC pad with a screen saying "Tap here " above it. The number of people I see tapping the screen is... the screen should obviously say "below", the active area should have a ring of LEDs around it, etc etc etc; it's broken design. However, I've also seen people doing the same thing (tapping the screen) with payment terminals. In situations like this, you're designing the system to be viable for the dumbest user.
I’m not saying I’m against privacy. I am all for not being tracked, but we are approaching absurdity.
I really want to see all of you who praise “privacy” go fully offline and use only cash. No cards. No bank account. Nothing. Salary? Cash, because earnings could also be sold and used for advertising. Groceries? Cash. Gas? Cash. No checks also, as they can be tracked /s Also, while we are at it, no Android, no iOS, no Windows or Macs. Only Linux, because we can’t trust UE vendors.
Really, maybe we should start spending our energy in convincing legislators that PII should not be sold along with transaction data/histories. Matter a fact, let’s rally for universal privacy laws. How about that?
Let’s not go 50 back in evolution just because “visa bad”. I’m happy not to lose cash or reach for my wallet anymore.
Why would people have to choose between using only cash and sharing their data with everyone? The normal thing to do is limit who can access the data as much as possible. And if people don’t do that, why would legislators care?
Because some other people started ranting about cashless payments, payment processors and their privacy.
> "Why would people have to choose between using only cash and sharing their data with everyone?"
Because that's how other people put it. I was just raising the point that we shouldn't have to give up QoL improvements, instead push for more privacy-focused laws, like limiting PII-data being sold along with transaction histories.
On the one hand, we have threads about how browsers are fingerprintable and some app is using telemetry and endless discussions on theoretical zero-knowledge protocols and the importance of cryptography and Snowden saying this and that that get voted up to the top.
On the other hand, something like this comes up which is basically another step along the "no-one accepts cash" funnel and so now everything you ever buy with metadata is part of the borg. Like, you've literally deliberately introduced an MiTM.
I don't get this blind spot. Paying with cash is literally the easiest thing I do to reduce my data trail.
I personally like using a credit card because it creates a data trail I can use to review my spending and budgets.
I can't count the amount of times I've lost or been robbed physical bills. Never once have money siphoned out of my online bank. I don't use cash anymore, I'm all digital, and still use a VPN to watch porn.
Turns out different people have different threat models. My threat model includes my neighbour, my ISP (to a certain extent), my employer (again, to a certain extent), private companies like Google or Facebook, burglars, thieves, and scammers.
It doesn't include the NSA, the government, the NSO group, banks, or North Korean government-sponsored hackers. If you think you can defend yourself against the NSA, lol. Good luck.
For example, your credit score is penalized if your have high utilization on your card doesn’t matter if you never default on a payment, Low credit score results in low limits in turn keeps utilization high.
Bank knowing I defaulted on a card as a risk parameter is one thing, them knowing how much I spend every month and likely on what line items is not ideal when they can control a lot of your life.
Bad credit score can mean high interest rates , higher down payments rejected for loans that can have major impact on your life.
It is also likely bank or payment processors can indirectly sell our buying patterns for targeting ads.
It would be one thing if Credit Score for a government run central thing, couple of private companies having all your spending data without your consent at all seems major invasion of privacy.
Scoring methodology depends on sharing my private spending data to others, data that I cannot control being resold or have full visibility into its use. CRAs will try to charge you to "freeze" your credit or even see your own data!.
This is extremely anti-consumer, CRA industry did not develop for consumers or their protection, it is merely a tool for businesses to improve their operations.
Imagine if FB had a "social credit" and that is now used every social gathering as an eligibility criteria, and Facebook charged you to see your own data, that is how the current system feels.
This already happens. My closest NFL and MLB stadiums do not accept cash for anything inside the park.
https://www.nytimes.com/2020/01/23/nyregion/nyc-cashless-ban... - Note the date
Of course it isn't as private as cash, but it is a step forward from mag-swipe.
Square has a good explainer if you want to read more: https://squareup.com/us/en/townsquare/what-does-tokenization...
I agree with the GP, this is a huge privacy blind spot.
There are multiple attack vectors. One of them is "why did I just get another charge from that place we visited last June". Another being "oops, we plugged our pin into a skimmer", etc.
Agree that letting Visa/MC/whomever know everything about your transactions is a choice...
Otoh if they pay you 3ish % for it, you might decide you're more than happy to.
Basically like privacy.com, but why use a new card per merchant?
So now Apple gets to know what Visa knows. Still, for the time being, they don't seem to know individual items. And many here seem to think Apple is more trustworthy than random anonymous data broker.
More recently, an additional identifier uniquely identifying the underlying card has also been added [1]. That one persists even across multiple devices and token deletions.
[1] https://www.level2kernel.com/payment_account_reference.html
If it's actually encrypting information (not just signing it), then that's another thing entirely, but signatures don't hide data.
But that's not necessarily the case either, as somebody else brought up the fact that identifiers ARE in fact passed to the merchant.
Though at least in the EU the mag-swipe method was phased out and replaced with a chip based method years ago. (A chip with secure module, requiring PIN if you pay for more then a small amount, or otherwise unusual.)
And as far as I know that method is still more secure then Apple pay and similar.
Sure, if you prioritize anonymity in your transactions over convenience cash is much better.
OTOH, contactless pay with your phone is so much better than handing your card to a random server to make an imprint or whatever - and more secure/privacy maintaining than using the card itself if done right.
It's not a binary decision.
https://www.investopedia.com/terms/m/merchant-discount-rate....
I'm not sure what's the exact revenue share model / contractual agreements between Apple and its partner payment platforms(Stripe, etc).
Both my plumber and the guy who fixed our washing machine used SumUp, as did most of the market-stall holders at the Christmas market this year. All of them were using the phone-linked version (rather than the one with its own SIM).
Sure, it's not right for everyone, but it will be perfect for a lot of people.
The target user is a US-based merchant. Most likely, it's a small business, perhaps a sole proprietorship, that uses a small Square reader today. This gives that business one more way to accept payments, but without the extra hardware.
A business with multiple employees/points of sale has alternatives. This is probably not the solution for them.