Banks generally hate anything that takes away their branding. Less sleek of this -- i.e. reprogrammable Visa cards -- have been around for a few years but banks never supported them, again because of branding.
I also am not certain that Apple Pay "massively encourages" a single default card. It looked quite easy in the demo to display multiple cards and switch between them. Looked easier than taking a card out of a crowded wallet and putting it back in, actually.
Also there are some practical in RL issues that come up with most NFC payment readers (namely a lot of the installed readers have short range, and awkward pad placement) which makes non default much less attractive.
As for the display issue, the issuers concern is that they are pretty limited as far as making things distinct. I mean hell, every card company is going to have black cards. There are no sideways cards, no premium materials, no metallics, etc. They have a relatively small image, which has to still look good even if cropped to lose the bottom 80%. Basically they get space for bank logo, card logo, and a non distracting background.
So if they are willing to give up on all that and a fee, it doesn't seem all that out of the question for them to allow their logos to be used on a flexible card, and (presumably) not pay a fee.
[1] http://clover-developers.blogspot.com/2014/09/apple-pay.html
Just a guess! but it would avoid some pretty massive technical hurdles to international acceptance.
But yeah, they obviously found a way to implement ApplePay - hell, Apple probably did it for them.
They are famous last words, but in this case they seem justified.
• "Chip and PIN is Broken" (Murdoch/Drimer/Anderson/Bond, 2010) [PDF] http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...
• "Chip and PIN is Broken" (Murdoch, 27C3, 2010) [Video]: http://www.youtube.com/watch?v=Ks_w352BS-Q
• "Chip & PIN is definitely broken" (Barisani/Bianco/Laurie/Franken, 2011) [Video]: http://www.youtube.com/watch?v=JABJlvrZWbY ...and slides [PDF]: http://dev.inversepath.com/download/emv/emv_2011.pdf
They can certainly get cardholder names and that sort of thing though. Maybe they've figured out a way to generate a unique token based only on non-secure data.
In the demo they buy coffee, etc. with it. You couldn't buy something more expensive with it because the bank would deny the charge.
NFC is similar. You can use it for small transactions, but not larger ones.
Their attack uses offline PIN mode. This is further expanded upon in section III.
The simplified attack is such: Basically the PIN signed block doesn't get sent to the bank. Verification is only between the terminal and the card, and the card (or rather MITM hardware) returns a "all is well, transaction approved" message when in fact no such thing happened. The terminal doesn't go online and talk to the bank and verify the signed PIN block.
This is essentially misconfiguration of the merchant terminal that ignores the result of the PIN verification.
This is similar to when you tap a card to buy something. If the merchant system doesn't go online to verify it -- which it often doesn't for small transactions (<$10) then you can game the system.
And cloning is still almost impossible. The largest risk appears to be copying card details which allows the fraudster to use cards online or in countries that don't yet have Chip and PIN. Personally I would like to see separate account numbers and details on the Chip compared to the main card number - i.e. you could copy some of the chip details but this wouldn't actually let you get anywhere because the number would immediately be flagged if it was found anywhere else. You'd then have another card number (maybe the one actually printed on the card) that you could use online.
Or perhaps we could just scrap the whole card thing for non-physical use...
(And I'm saying this as a guy who makes some of his money at this game)
Knowing the transaction amount is not possible from the "sender" portion of a magstripe. You're simply handing over a credit card number. The credit card amount is negotiated over the phone/internet between the bank & merchant.
This means that the Plastc card likely has one hardcoded number that switches payments serverside. Similar to the Wallaby card or Google Wallet card.
This works perfectly fine with chip & pin. The merchant charges the Plastc card which in turn forward the transaction to the correct bank.
They clone the magnetic stripe part of a chip and pin card and then have their own chip and pin layer that they put on top.
In the UK the only reason you can't use magnetic stripe is because no shops allow it (if they do then they are completely reliable for the authenticity of that transaction) - if you could add a chip and pin layer on top of mag strip data then this might work (would still require a lot of fiddling and as far as I can see transactions would have to go via platc like google wallet).
They probably don't have to worry about fraud, since the barrier to entry is $155 and they charge your card immediately.
The only thing that might be tricky is whether they get the 'card present' rates or not.
"*Plastc card will be available to use across all participating locations and with all participating payments types following an over-the-air firmware update in 2015 to enable Chip and PIN and contactless payments."
Sounds like they are working on those partnerships.
If this is using the EMVCo tokenization stuff, which it is widely believed that Apple is using, I don't think they would have to partner with banks. They'd just have to register with a Token Service Provider.
Here's an interesting article on this: http://www.aviso.io/apple-pay-brings-new-problems-acquirers/
The chip contains an application for Plastc, this is (like Amex) always acquired by Plastc (and will probably then only be allowed at participating retailers). Part of the Issuer Private Data sent in the transaction is which one of your pre-registered accounts you wish to use. That account is then charged in the background. It would work a bit like a physical Paypal.
Because unless something major has changed, I can't see banks being keen to hand over private keys to third parties.
They may get the NFC component to work with all the providers which allow them to, just like you can currently use your phone to make NFC payments. :)
EMV and EMVco are the same thing. It's the standard also implemented by RFID cards such as Mastercard PayPass and apps like Google Wallet.
However, the standard can allow for other things as well - it can allow for users to generate a new token per-merchant which could be used online or in person. Or merchants could generate a new token from a customer's card that'll only be usable with that merchant for storage, thus standardising what the likes of Stripe do while implementing a significant amount of backwards compatibility with the existing system.