Remix.run Logo
▲ jasode 44 minutes ago

> is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all.

Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.

The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)

▲MBCook 20 minutes ago | parent | next [-]

All EMV transactions (including Apple Pay in a tap to pay scenario) don’t give the retailer the full card number.

▲cosmic_cheese 30 minutes ago | parent | prev | next [-]

Importantly, this provides a degree of protection from compromised PoS terminals. Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges, whereas back when I was still tapping, inserting, or swiping my card I’d need to call and get a card or two replaced almost every year.

▲MBCook 19 minutes ago | parent [-]

Inserting and tapping is just as safe.

Swiping is where the risk is.

▲bdangubic 42 minutes ago | parent | prev [-]

don’t be silly, apple displays me exact amount on the screen, in plain fucking text, after each transaction - that’s crazy you wrote this

▲deltaknight 7 minutes ago | parent | next [-]

This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.

The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).

Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)

▲tekla 37 minutes ago | parent | prev [-]

Man, its amazing how confident you are about this, considering I know individual people who independently work at Visa, Mastercard, AND Apple, who have worked on mobile payments who independently confirm that none of them know any personal info and that its all pass-through.

So, are you sure you know what you are talking about?