Fraud Rampant In Apple Pay 269
PvtVoid writes with this report from the New York Times, excerpting: An industry consultant, Cherian Abraham, put the fraud rate [for Apple Pay] at 6 percent, compared with a traditional credit card fraud rate that is relatively minuscule, 10 cents for every $100 spent. [i.e. one tenth of one percent]. The vulnerability in Apple Pay is in the way that it — and card issuers — "onboard" new credit cards into the system. Because Apple wanted its system to have the simplicity for which it has become famous and wanted to make the sign-up process "frictionless," the company required little beyond basic credit card information about a user. Nor did it provide much information to the banks, like full phone numbers and addresses, that might help them detect fraud early. The banks, desperate to become their customers' default card on Apple Pay — most add only one to their iPhones — did little to build their own defenses or to push Apple to provide more detailed information about its customers. Some bank executives acknowledged that they were were so scared of Apple that they didn't speak up.
Aren't these already compromised cards? (Score:5, Interesting)
The story doesn't really indicate how this could be much of Apple's problem - it sounds like the cards that are getting used are already stolen?
I guess what's happening is criminals are getting stolen CC info, and are then able to use it in a physical environment via Apple Pay where it previously would have required printing a forged card?
The article mentions that it's easier to get away with fraud in person because the lack of shipping delay leaves less time to catch it, which shows why they'd be so eager to jump to a method like this.
Re:Aren't these already compromised cards? (Score:5, Interesting)
This is exactly what it is. Already compromised cards being added as payment token. Banks are supposed to follow a protocol called "Yellow path" to prevent this fraud, but since everyone wants their ApplePay to work right away without having to call a call center, a lot of banks are lenient on the security checks. This is not a problem with Apple's technology, or the secure element on the phone, or the fingerprint reader. This is a bank allowing a card to be added to an ewallet, presumably because the party adding the card has all the relevant info (stolen identity) to make it work.
Re: (Score:2)
This sounds like some companies are fighting with Apple over who has to pay for the security checks. Since Apple is posting record profits, they see Apple as the one who needs to do it, even though the problem is clearly with how insecure credit cards always have been .
Re: (Score:2, Insightful)
American banks have ALWAYS sucked at security in the world of the credit card. that CCV number on the back of the card is the dumbest thing ever and offers zero security.
Re: (Score:3)
I've seen a 4-figure mail-order fraud fail to work because the crook couldn't give the CCV numbers over the phone.
Re: (Score:3)
I always assumed CCV was designed to offer basic protection against incidental photographs of the card being taken, and other situations where only one side of the card has been compromised.
Re:Aren't these already compromised cards? (Score:5, Informative)
I always assumed CCV was designed to offer basic protection against incidental photographs of the card being taken, and other situations where only one side of the card has been compromised.
Not really - Amex puts its CCV on the front of the card. The real purpose is that the CCV isn't encoded in the magnetic strip, and isn't embossed, so theoretically, someone using a magnetic swiper to steal data or someone dumpster diving for those old carbon paper-imprint style records would get the numbers but not the CVV.
But of course, the person who is stealing your credit card info is most likely your waiter, and they have a minute or two with your card over at the POS to copy down the CVV manually.
Re:Aren't these already compromised cards? (Score:4, Insightful)
But of course, the person who is stealing your credit card info is most likely your waiter, and they have a minute or two with your card over at the POS to copy down the CVV manually.
And this is why the United States needs to move to EMV (Chip & Pin) like the rest of the world. Rather than the waiter taking your card away, they bring you a hand-held terminal, which you then take and perform the last portion of the contract yourself, with the card never leaving your hands.
Re:Aren't these already compromised cards? (Score:4, Interesting)
But of course, the person who is stealing your credit card info is most likely your waiter, and they have a minute or two with your card over at the POS to copy down the CVV manually.
And this is why the United States needs to move to EMV (Chip & Pin) like the rest of the world. Rather than the waiter taking your card away, they bring you a hand-held terminal, which you then take and perform the last portion of the contract yourself, with the card never leaving your hands.
Yep. Great system, though a little awkward when tipping and they're standing over you staring as you go to push the 10- no, 15- no, [gulp] 20% button. Maybe that's why they don't tip much in Europe.
That said, there's a reason why the US is moving to Chip & Signature cards, but not Chip & PIN. The banks will tell you it's because they don't want to confuse or scare their customers who can't learn new systems, but the real answer is that legally, if there's fraud on regular credit cards or chip & signature, the banks can charge it back to the merchant, who must have failed to verify the signature or ID of the purchaser. If there's fraud on chip & PIN cards, legally, the banks have to eat it. So they're not moving to that until they have to.
Re: (Score:3, Informative)
The reason why in Europe tipping is less "rampant" is that the tip is a tip and not a the service charge. In most European countries, the service is calculated into the price of the meal, so you are paying the tip to encourage above average service and not to make sure the waiter gets paid at all.
Re:Aren't these already compromised cards? (Score:4, Insightful)
Re:Aren't these already compromised cards? (Score:5, Insightful)
ApplePay is part of the problem. Because it tries so hard to keep information away from banks and retailers it makes it harder to detect fraud. If Apple were providing things like names and phone numbers to the banks they could very easily see that a particular CC was not being used by the authorized owner or on a phone they had never used it with before.
To be fair, banks could have demanded that information during sign up, but didn't. There is plenty of blame to go around. What I'd like to know is who pays for it. Usually it is the merchant, in which case I'd expect to see some of them refusing Apple Pay.
Re: (Score:3)
This is exactly what it is. Already compromised cards being added as payment token. Banks are supposed to follow a protocol called "Yellow path" to prevent this fraud, but since everyone wants their ApplePay to work right away without having to call a call center, a lot of banks are lenient on the security checks. This is not a problem with Apple's technology, or the secure element on the phone, or the fingerprint reader. This is a bank allowing a card to be added to an ewallet, presumably because the party adding the card has all the relevant info (stolen identity) to make it work.
Here's what I don't understand. ApplePay is tied to a specific phone and has, or should have, access to user specific identification that it can share with the bank. If that doesn't match with the banks info, such as phone number on the account, then they could refuse ApplePay. They could send an email to the card holder or call an alternate phone number to verify the card is not compromised, or refuse to activate the card if a second phone with a spoofed phone number attempts to activate. They also have ac
Re:Aren't these already compromised cards? (Score:5, Insightful)
In fairess, it doesn't sound like there's a problem with Apple's implementation - it may well be perfectly(hah!) secure. But security is only as good as the weakest link, and if the banks aren't doing their job of verifying that the CC account being bonded to the Apple-Pay account is actually legit - well then there's a giant F'ing hole in the security that theives will enter by the busload. Nothing Apple can do about that, technologically at least - though if they're pressuring banks to provide a "painless" bonding experience, well then they do bear some responsibility.
Re:Aren't these already compromised cards? (Score:5, Informative)
...and stop calling me Shirley.
Re: (Score:2)
So everyone thought that apples system of implementation would be more secure? Cheap is as cheap does.
I don't think everyone thought the system is more secured. I think these people use Apple pay because it is convenient. They, however, may expect the security level to be up to par, which is not...
Re: Aren't these already compromised cards? (Score:5, Interesting)
Apples' implementation IS more *convenient* for the *fraudulent* user.
FTFY. By hiding some of the transaction information from the banks that clear the transactions, the fraud detection heuristics used by banks are less effective. By requiring no physical trace of the transaction, the merchants don't have any incentive to intervene to avoid chargebacks thus making it easier those in possession of stolen card numbers to rack up charges.
Actually this was quite predictable (and predicted by several industry folks), but fear of being left off the ship that was going to sail basically led the banks to just hope for the best as a cost of doing business.
Reminds me of a story a co-worker told me. Back many moons ago (~20years ago), he was a field engineer for mainframes. One day he got an emergency call from a customer that needed a mainframe fixed as some ridiculous hour of the morning. When he got there, his boss was there along with a half-a-dozen Bank presidents in suits in the computer room hovering and watching him work.
Later he found out from his boss that it was a mainframe that did real-time credit card approvals and the bank was basically approving nearly all transactions blind whilst they waited for the computer to be fixed. The theory was that if they didn't do this, people would just take out another card and they would lose all the business for potentially several days (the once bitten twice shy on c-c declines). Apparently all the Bank presidents were there as part of an agreement to verify if he wasn't able to fix the computer within that hour, they would start denying large transactions and they expected to lose tens of millions dollars in lost merchant fees if they did that (and something like that needed their immediate approval). That's why his boss didn't tell him that before he started working on the machine. No pressure...
Re:Aren't these already compromised cards? (Score:5, Informative)
I read another article on this. As the article tries to expose, the fault lies not in Apple Pay, but rather in (as the article suggests), the process by which cards are authorized for use with Apple Pay during the onboarding process. There are two paths, the Green Path and the Yellow Path when authorizing a card. The difference is the types of information collected and passed. Most cards go down the Green path. But, when a card has incomplete information, it goes down the Yellow path and is subject to less stringent and, sometimes, manual intervention. It is down this pathway where the fraud occurs.
While a card is being approved during the Yellow pathway, the card can be used using the card number, expiration date and, not always, the security check value.
It is up to the banks and card issuers to secure their onboarding process. Apple (via Apple Pay) is not responsible for ensuring this takes place. Thankfully, the fraud is easy to detect and remedy. Next year, when our cards all have chips in them, the exposure via the Yellow Path will all be eliminated.
Apple supporters were right to call out Mr. Abraham - he is biased and attempting to create FUD against Apple and Apple Pay. The real fault and finger pointing needs to be directed to the banks and they need to get their houses in order.
Re:Aren't these already compromised cards? (Score:4, Insightful)
Apple supporters were right to call out Mr. Abraham - he is biased and attempting to create FUD against Apple and Apple Pay. The real fault and finger pointing needs to be directed to the banks and they need to get their houses in order.
Indeed.
If the banks had the courage to confront Apple and demand that Apple Pay include more information then this wouldn't have happened. Its entirely the banks fault for being scared of Apple (which probably has a larger war chest than all those banks combined).
Re: Aren't these already compromised cards? (Score:2)
Geez, if Apple told you to jump off a cliff, you have to, right? I mean they have "such a large war chest."
At a certain point surely the responsibility of bankers to keep their customers' accounts secure entails-- it's the very basis of their profession.
and anyway, what exactly are they afraid of? Did they even ask to implement the necessary security features? Did they ask, and did Apple refuse? Has Apple threatened any sort of sanctions against banks that don't comply? It's all very amorphous, and again,
Re: Aren't these already compromised cards? (Score:5, Funny)
Actually an apple employee will show up and push you off the cliff if you dont jump. It's a part of the customer care program.
Re:Aren't these already compromised cards? (Score:5, Interesting)
It may not be Apple's fault (exactly), but it sure as hell is their problem. If more than 1 in 20 ApplePay transactions are fraudulent, what merchant in their right mind is going to accept it as a payment method? (Remember that fraud is paid by the merchants, not the banks.)
Even if it isn't Apple's fault, it sure is their problem to solve.
Re:Aren't these already compromised cards? (Score:5, Insightful)
Re:Aren't these already compromised cards? (Score:5, Informative)
Anyhow, allowing transactions using only the card numbers themselves is horribly flawed because anyone can just take a photo of a card to get its numbers. So the credit card companies have come up with these other methods to "verify" the card's authenticity. (I put it in quotes because it doesn't actually verify the card's authenticity, just reduces the chances the card is not authentic.) Apparently Apple refused to forward much if any of this information to the banks when a fresh card is first being loaded into Apple Pay, making it easy to load a stolen credit card - easier than actually using the card for a purchase. And the banks were too cowed to make an issue of it, landing them in the mess they're in.
On the one hand it's the bank's fault for not speaking up and pressing a vital security issue. On the other hand it's Apple's fault for being an 800 pound gorilla which uses its market clout to force concessions from its partners. Stuff like this is why you always want at least two strong competitors in a given market - so if one makes unreasonable demands of a business partner, the partner is not afraid to tell them to go jump in a lake. It's the same reason we allow unions - because the hiring employer has a lot more clout than the individual employees.
Re: (Score:3)
On the one hand it's the bank's fault for not speaking up and pressing a vital security issue. On the other hand it's Apple's fault for being an 800 pound gorilla which uses its market clout to force concessions from its partners. Stuff like this is why you always want at least two strong competitors in a given market - so if one makes unreasonable demands of a business partner, the partner is not afraid to tell them to go jump in a lake.
I like the looks of Apple Pay, and think it's a great move forward but even as an Apple fan, it seems bizarre for Apple to move forward on their own payment standard rather than the industry creating one. I mean, I know they did it so that they could skim profits off the top, and that they got away with it because they're worth 700 gazillion dollars and could probably make demands of the ocean, but I really wish this had come about via an industry standard.
Of course then, it'd probably suck.
Re: (Score:2)
Apple Pay is built on top of standardized front-end payment infrastructure, and competing systems can be (and are being) built on that infrastructure as well. It's analogous to being able to visit, say, either Google or Bing from the same computer; the world doesn't need to agree on a single standard search engine if multiple search engines can be accessed via the same front-end (in that case, the web browser and user's Internet connection), and in fact user choice is better enabled if it doesn't.
ApplePay uses industry standard tech (Score:2)
I like the looks of Apple Pay, and think it's a great move forward but even as an Apple fan, it seems bizarre for Apple to move forward on their own payment standard rather than the industry creating one.
ApplePay uses industry standard technology that was not created by Apple. Apparently you were not aware of this. Plenty of merchants already have the necessary tech to use ApplePay whether or not they elect to accept it. The only thing Apple did was to make setting up and using the whole thing FAR easier. I fully expect ApplePay to get copied in part or in whole by the Android and Windows ecosystems.
Re: (Score:2)
Nah, what's going to happen is Visa/Mastercard is going to do it themselves, and cut out all of the middlemen (Apple, Google, etc.)
Re: (Score:2)
Nah, what's going to happen is Visa/Mastercard is going to do it themselves, and cut out all of the middlemen (Apple, Google, etc.)
Really? How are they going to get access to the phones without going through Apple, Google or Microsoft? Curious how you think that is going to happen. If you say they're going to do it through an app I'll laugh my ass off.
Re: (Score:3)
Re: (Score:2)
But what if Apple, Microsoft and Google ban such apps from using NFC for payment or they have proprietary API not shared with app developers that you need to make an Apple Pay clone? After all, despite millions of apps, only 4 or 5 app stores exist in the mobile world and they belong to Apple, Google, Microsoft and other mobile OS vendors.
Re: (Score:2)
Re: (Score:2)
I like the looks of Apple Pay, and think it's a great move forward but even as an Apple fan, it seems bizarre for Apple to move forward on their own payment standard rather than the industry creating one. I mean, I know they did it so that they could skim profits off the top, and that they got away with it because they're worth 700 gazillion dollars and could probably make demands of the ocean, but I really wish this had come about via an industry standard.
You don't get to be first to market by waiting for an industry standard. In fact, if you wait for that to happen you probably won't even get into the market. You build it out as fast as you can using as much existing infrastructure as you can, then pivot if and when the industry gets around to creating a standard. In the meantime you build a leading market share and can even leverage that during the standards creation process.
Re: (Score:2)
I know they did it so that they could skim profits off the top...
You claim to be an "Apple fan"; yet you make a tell-tale comment like that?
.00018% of aggregate transaction fees from each member bank (sorry, I can't find where I read that right now); but, according to what I read, has no way of checking nor enforcing such fees; so it doesn't look like they designed the system with that as an important monetization feature; but rather as a general-purpose fund to help offset the administration costs of the setup procedure, of whi
Apple supposedly receives something like
Re: (Score:2)
Apple is just one of the many vendors supporting the global NFC standard. Cognizant of all those stories coming out of Europe about wallet-brushing skimming devices, Apple Pay is just a more secure implementation of the standard.
Re:Aren't these already compromised cards? (Score:5, Insightful)
So if you use Apple Pay, you have less of a chance of getting YOUR credit card data stolen... However if your credit card had already been stolen, Apple Pay means there is a higher chance of it getting used. Because you won't need to face someone who may question your identity.
Apple does not obfuscate transaction info (Score:5, Informative)
It's Apple's problem because they're not providing enough information to the banks and credit card companies. For instance if it just shows up as "APPLE PAY" on my credit card statement, instead of "AP: WHOLE FOODS FL"
That does not happen. When I use ApplePay it shows up on my credit card statement as WALGREENS #3493 or similar. I just looked at a statement to confirm. Apple doesn't even appear on the statement line anywhere unless I'm actually buying something from Apple themselves (like through iTunes). They're providing all the information the merchants need to do the transaction and do it securely. If the banks cannot be bothered to secure their credit cards then that is a problem Apple needs to work out with the banks.
Paypal used to have the same exact problem but now provide lots of details on my statement instead of just "PAYPAL."
Different company, different product, different procedures. Not remotely relevant to this discussion because Apple does not do that.
Re: (Score:2)
Come on, random haters gotta hate. They don't have to care or know how things actually work. They just need to throw up something that sounds sorta, maybe, plausible, and hates on.
Re: (Score:2)
All they care about is that Slashdot be made Apfelrein.
Re: (Score:2)
Well Miami is pretty bad for scams.
Re: (Score:2)
Duh! (Score:2)
Re: (Score:2)
Except that you could switch out "Apple Pay" for the upcoming "Samsung Pay" or "Google Wallet" or "Contactless Payments" and still have the same problem.
This is not fraud happening because someone has cracked Apple Pay - this is bad people doing what they would have done before, only using stolen credentials and information on an iPhone.
Also, I love the meaningless statistic at the top of the summary - a 6% fraud rate, out of how many transactions? And that 0.1% fraud rate on traditional magswipe transacti
Re: (Score:2)
Absolutely. Contactless is pointless and expensive as fuck for merchants. I can't imagine many businesses where the "neat-o" factor from a few phone enthusiasts to be able to pay with their phones is going to outweigh the costs.
Not pointless at all (Score:2)
Contactless is pointless and expensive as fuck for merchants.
If your customers like it then it is not pointless. Furthermore most merchants either already have the tech or will have it within the next year. The costs get passed on to customers anyway so the only relevant comparison is if one merchant is getting a better deal than another merchant. If both accept the same methods of payment then there is effectively no cost to the merchant at all. You need to familiarize yourself with the concept of Incidence of Payment.
I can't imagine many businesses where the "neat-o" factor from a few phone enthusiasts to be able to pay with their phones is going to outweigh the costs.
Because it won't be just a few phone enthusi
Re: (Score:2)
Or the ones that don't accept the payment are
Re: (Score:2)
Absolutely. Contactless is pointless and expensive as fuck for merchants. I can't imagine many businesses where the "neat-o" factor from a few phone enthusiasts to be able to pay with their phones is going to outweigh the costs.
You do realize that newer EMV cards support contactless payments as well, right? No phone needed. You get the convenience of "tap and go" with the added security that EMV provides.
Re: (Score:2)
Re: (Score:2)
So you value convenience over security.
I specifically avoid tap and pay and insisted the issuers give me cards without it to avoid the massive security hole it provides.
Chip and PIN takes approximately 10 seconds longer, and is infinitely more secure.
Fees and fraud prevention procedures (Score:2)
Apple Pay is simply going to get too expensive for all but the most clueless merchants to use, both from the fraud and from Apple's eventual fees.
Anything Apple might charge will be a rounding error compared to the 3-5% the credit card companies charge merchants. Furthermore those fees get passed on to the customers so merchants only give a shit if their competition doesn't have to pay the same fees.
Regarding the fraud, it sounds like the banks aren't following their own security procedures which results in... duh, fraud.
It was a bad idea to begin with, and it's a bad idea now.
I could not disagree more. I'm not an Apple fanboi but I've used ApplePay and it's fantastic for customers. It's easily the best
Re: (Score:2)
Apple Pay is simply going to get too expensive for all but the most clueless merchants to use, both from the fraud and from Apple's eventual fees.
Anything Apple might charge will be a rounding error compared to the 3-5% the credit card companies charge merchants. Furthermore those fees get passed on to the customers so merchants only give a shit if their competition doesn't have to pay the same fees.
Regarding the fraud, it sounds like the banks aren't following their own security procedures which results in... duh, fraud.
Apple will probably charge 30%
Re: (Score:2)
90% of sales in brick and mortar stores are card-based (as opposed to cash). No sane merchant is going to give up 0.5%-1% of total sales or whatever Apple ends up charging so their customers can have a "gee whiz neato" moment at check out.
And no, it's not 3-5%. It's closer to 2-2.5% for medium and large sized merchants.
Re: (Score:2)
Anything Apple might charge will be a rounding error compared to the 3-5% the credit card companies charge merchants. Furthermore those fees get passed on to the customers so merchants only give a shit if their competition doesn't have to pay the same fees.
Apple doesn't charge Merchants; it charges BANKS. And the fees are "aggregated" and VERY small (like around a thousandth of a percent). So "rounding error", indeed.
Re: (Score:2)
Oh, and I'm sure the banks are doing it for free and won't change the rate on Apple Pay payments like they constantly raise the rates on regular cards. I love how banks are always giving away free things!!
Come on... (Score:2, Interesting)
I could see the big bad CEOs being scared when Jobs was in charge, but Cook?
God, bankers are even bigger pussies than I thought.
Re: (Score:2)
I could see the big bad CEOs being scared when Jobs was in charge, but Cook?
God, bankers are even bigger pussies than I thought.
Are you saying that gay guys can't be scheming sociopaths? Remember, Jobs chose him as his replacement.
Calculated risk (Score:2)
For credit cards, frauds are nothing to banks. They just pay it from their profits, and the customer doesn't have to worry. Maybe it is the same here? Perhaps it still pays off for the banks and Apple to do that extra business, and it works out in their calculation.
Re:Calculated risk (Score:5, Informative)
No, they charge the merchant all different rates based on the risk of that particular transaction. There are hundreds of categories of cards, swiped vs non-swiped, address info vs no address info, etc. Apple Pay is going to be absurdly expensive for the merchants dumb enough to take it.
Re: (Score:2, Informative)
And then on top of that, when fraud is caught they just take the money back out of the merchant's account.
In no way do they ever "pay it from their profits".
Re: (Score:2)
Re: (Score:2)
And then on top of that, when fraud is caught [the banks] just take the money back out of the merchant's account. In no way do they ever "pay it from their profits".
This. A hundred times this.
I don't know if it's changed recently, but from reading Internet discussions on credit card fraud etc., it was always clear that people thought that- despite a notoriously sloppy and too-lazy-to-fix-the-obvious-flaws attitude towards security, the party paying for the banks' apparent fecklessness was the banks themselves.
Except, it isn't- it's the merchants. If there's a fraud, the money gets yanked back from the merchant, and that's the last he'll see of it. (No, you *won't
Re: (Score:2)
Except that Apple Pay is at contractually negotiated rates, below the "card not present" rates that online retailers already happily pay.
Re: (Score:2)
. They just pay it from their profits, and the customer doesn't have to worry. No, they charge the merchant all different rates based on the risk of that particular transaction. There are hundreds of categories of cards, swiped vs non-swiped, address info vs no address info, etc. Apple Pay is going to be absurdly expensive for the merchants dumb enough to take it.
Hey fucktard! APPLE DOESN'T CHARGE MERCHANTS [digitaltransactions.net]
Learn to READ.
Re: (Score:2)
Re:Calculated risk (Score:4, Interesting)
For credit cards, frauds are nothing to banks. They just pay it from their profits
No. Nearly all the cost of fraud is pushed onto the merchants, who pass it on to consumers in the form of higher prices. So you are paying for credit card fraud even if you pay cash.
This is the problem with credit card fraud. The banks are in the best position to fix the problem, but have little incentive to do so, since they don't bear the cost.
Bank problem (Score:2)
Both of the banks and the on CC card I have on ApplePay required I read an email, click a link and login to my account and explicitly authorize the use of the card before it was usable.
You mean there are companies NOT doing this?!
Re: (Score:2)
Both of the banks and the on CC card I have on ApplePay required I read an email, click a link and login to my account and explicitly authorize the use of the card before it was usable.
You mean there are companies NOT doing this?
I could swear I read this exact article some time ago, before the NYT published it so maybe the "toughened standards" banks talk about were already enacted quite a while back and we're just now hearing about the problem?
Re: accounts (Score:5, Informative)
My bank and CC companies verified my request to add the card to ApplePay after I added it to my phone but before it was usable.
I had to login to THEIR sites, not Apples.
Are they still on the job? (Score:2)
Some bank executives acknowledged that they were were so scared of Apple that they didn't speak up.
And such officials are still employed? In my opinion, such employees are good candidates for immediate termination.
But wait! We're gonna hear about the usual vitriol from these banks. I will go something like this:
"We take [the] security of our operations and clients' accounts with us very seriously."
"We process in excess of several billion transactions daily and although fraud is part of our industry, it constitutes less than 0.1% of our business." "Our bank is committed to providing the best security t
Re: (Score:2)
No, that 's not it. You see, these people get paid the big bucks to make the tough decisions. They are our best and brightest, just like the folks on Wall Street, so whatever they do, you cannot question them. After all, they know what they're doing.
Meanwhile on Google Wallet.. (Score:3)
.. I had to electronically send in a picture of a government-issued photo ID and a recent utility bill showing my home address.
Short story: Retailers should probably trust Google's platform more when it comes to fraud.
Re: (Score:2)
Right until Google drops the axe on it. They're already well into phase one: ignoring it's existence.
Why I won't be using Google Wallet (Score:2)
.. I had to electronically send in a picture of a government-issued photo ID and a recent utility bill showing my home address.
Google can kiss my shiny-white-hiney if they think I'm going to share any of that with them. They already know too much about me. My bank has more than adequate information to confirm my identity to Apple or Google. They don't need more than they already have.
Short story: Retailers should probably trust Google's platform more when it comes to fraud.
Right because it would be so hard to forge a picture of a government photo ID and utility bill...
Re: (Score:2)
Right because it would be so hard to forge a picture of a government photo ID and utility bill...
It's pretty difficult to do for each one of a file full of CC numbers you bought from a Russian hacker.
Actually, though, I should point out that the photo ID, etc. aren't part of the normal Google Wallet onboarding flow. Google Wallet does request information about name, address etc. which are cross-checked with the bank to confirm your identity. I'm not sure why the GP had to go further. Likely something triggered a fraud risk alert, which invoked the need for stronger verification. Note that I said "str
Re: (Score:2)
Just think of the absolute treasure trove of personal data... that google has OCR'd, indexed, and MONETIZED! Damn. I'm with you. Fuq em.
Google doesn't use the ID verification data for anything else. Actually, it's not clear what it would be useful FOR. How does knowing your driver's license number help Google to decide what ads to show you?
Plus, the vast majority of users of Google Wallet don't have to submit this data. It's not the normal case.
Re: (Score:2)
Why would a merchant trust a computer manufacturer or a search engine company with payment processing in the first place...?
How about because the "search engine company" processes tens of billions of dollars worth of payments annually, and achieves very low fraud with its internal risk engine -- mainly because it has a bunch of people who are really good at extracting important signals from large amounts of data (which is what both search and fraud risk analysis are about).
Simplicity? (Score:5, Informative)
How on earth does Apple Pay have more simplicity than a credit card? Here's how it works with a credit card:
1. Touch card or even whole wallet on reader.
2. Done!
And for more expensive transactions (over 20GBP, soon to be 30):
1. Insert card.
2. Enter PIN.
3. Done.
It doesn't get much simpler than the first one, really. I don't even have to extract my card.
Re: (Score:2)
In the states, we current use magnetic stripe for physical transactions. The "security" offered is in signature. I hate it, it's dumb, it's getting fixed supposedly, but it is what it is for now.
For us, Apple Pay means not having to extract a card, and with Touch ID it offers a somewhat real level of physical security as well.
Re: (Score:2)
Another thing, Apple Pay provides a different card number to merchants than your regular card. That way if something looks fishy, you can disable that card number on Apple Pay and re-enroll with a new number, rather than having to deal with canceling your main card.
That said, I wish they took it one step further and provided a one-time-use CC number for every transaction. This way anyone who manages to steal that information would not be able to use it again.
Re: (Score:2)
Actually that is exactly what Apple Pay does. and is precisely why I have begun using Apple Pay as much as possible The phone generates a new one-time use credit card number for each transaction. So even if the number given to the merchant is compromised somehow, it will be rejected if someone tries to make a
Look Ma, No Card (Score:2)
Re: (Score:2)
I think you've missed out the bit where your credit card contains a contactless chip. At which point it can facilitate all the things you describe, without your having to give a percentage to Apple.
You could even tape the card to your phone :-)
Re: (Score:3)
In terms of convenience, ApplePay is about as easy as a contactless credit card. It takes me about 3 seconds to pay with ApplePay and at least for me it's faster than even a contactless card because I keep my phone in a more accessible pocket than I do my wallet.
More importantly, ApplePay is significantly easier to use than chip-and-pin or traditional cards, which is where its competition really is (because that is what most people use in the U.S. who are just now starting to migrate). And also significan
Re:Yes simplicity (Score:4, Informative)
ApplePay is significantly less hassle than a credit or debit card
I don't have to do any of that to pay with my debit card. I touch my wallet to the reader and I'm done.
Yeah, that doesn't work.
Yeah it does.
Certainly doesn't work from inside my wallet and even if it did I'd still be asked to show the card and/or my ID.
My wallet is not a farady cage, and I've never been asked to reveal my card. Hell many of the places I use it aren't even manned.
You must not do much shopping in the US because you definitely have to here.
Nope, almost none, seeing as I live in Europe.
Re: (Score:3)
We have the same readers here in Canada--or at least the same basic concept. I have my card in a thin (Bellroy) wallet, and even with it open I can't get the touch-to-pay to work without pulling out the card a bit to expose the little symbol. Or at least, it doesn't work reliably.
Paying with my phone wouldn't be any less burden, but it wouldn't be any MORE burden either, and it would save me some space. When I go on long bike rides, I always have my phone, but I may leave my wallet at home and only bring a
Re: (Score:2)
Simply type 20gbp [google.co.uk] into Google; the very first result is its value in USD, together with a handy graph of its value over the last five years.
20 British Pound Sterling equals 29.46 US Dollar
Re: (Score:3)
I wish I could attach a video of how it's done in Europe-land. I can buy a beer in a pub with a contactless card: I simply touch it on the card reader; it never leaves my hand. And I don't need to provide a fingerprint or carry a many-hundred-dollar identity widget.
The bar likes it because they don't have to handle the cash. And if I lose my card I can have it disabled remotely with a single phone call.
Oh, and one more thing, if I lose my card and I need cash, I can phone the bank and get a six-digit c
Re: (Score:3)
Though apparently fraud is rampant so it's actually worse.
Except that it's not, since the fraud isn't affecting Apple Pay users specifically. It's affecting everyone, but Apple Pay users are actually subject to less fraud.
The fraud being encountered here is that data which was stolen in credit card hacks last year is now being used to establish fraudulent Apple Pay accounts, even if that person doesn't own a single Apple device. It stems from a twofold problem:
1) It's a failure of the pre-existing systems to properly secure their data in the first place. Apple Pay
Re: (Score:2)
Re: (Score:2)
There was no need for them to "band together," as Apple Pay allows each card issuer to individually choose how much verification to do.
Six percent figure from where? (Score:2)
While I'm sure there is fraud, and maybe it is rampant, Abraham's 600bps statement is backed by no source. He might as well pulled out the old, "some people say" line to use with it.
Comment removed (Score:3)
Re: (Score:2)
Mastercard and Visa are the only two companies that handle credit card transactions at the end of the day, and theyve often admitted theyre effectively the same company.
Don't American Express handle their own too?
Re: (Score:3)
Re: (Score:2)
Mastercard and Visa are the only two companies that handle credit card transactions at the end of the day
Actually, Mastercard and Visa aren't even companies. They're associations of banks. There are incorporated entities under those names (many of them, actually, one per country, plus Mastercard International and Visa International, which themselves have many national subsidiaries), but they don't issue credit cards, and only operate some pieces of the transaction processing networks.
theyve often admitted theyre effectively the same company.
As someone who regularly meets with representatives from both, discussing areas where the competitors are trying to collaborate
Re: (Score:2)
Apple is acting as a credit card processor
You're confusing Apple Pay with Google Wallet and Current-C.
.
By design, Apple is specifically not in the CC processing business. Once set up, Apple has absolutely zero visibility into individual transactions. That remains strictly the purview of the Banks and Merchants. Apple simply isn't involved, period
Got it?
Laugh (Score:2)
At this point Apple has become synonymous with "insecure".
I don't know... Seems secure to me (Score:3)
When I added an AMEX Business card to my ApplePay, it required me to contact AMEX and then be put through the ringer of answering a bunch of obscure questions including responding as to whether I lived at the addresses they proffered. Some from decades ago. It's pretty freaky that a credit card company would know all that about you. There was probably little question that the card I was adding to ApplePay was assigned to me.
Re: (Score:2)
Apple Pay is for stupid people.
and comments like yours make /. for stupid people too.
Re: (Score:2)
Apple Pay is for stupid people.
I take it that you use Apple Pay daily then?