Apple Pay: “The most secure payments scheme on the planet”

Kevin Harwood:

> For Apple Pay, Apple has worked with the payment processing networks to create end-to-end security for the user leveraging the EMVCo specification, completely removing the actual credit card number from any part of the payment process and instead generating one time payment tokens that are useless after they are processed. Simply put, the Target and Home Depot breaches would not have even been possible with Apple Pay. Tom Noyes, a former credit card executive, goes so far as saying that Apple Pay is “… the most secure payments scheme on the planet.” Now that’s secure.

Apple will deliver convenience and security—the best of both worlds.



11 thoughts on “Apple Pay: “The most secure payments scheme on the planet”

  1. I think Apple Pay is cool and all, but cut the B.S. about being the most secure on the planet. Let’s see:

    1) You still have your credit card, you still need it, there’s still a number on it. It’s still in your wallet, and will be for perhaps a few more years.

    2) You have to pull out a $750 device and bring it right up to the reader at the checkout line. A plastic card is worthless. Your liability is $50 if something gets stolen (usually $0). Showing your shiny iPhone 6 all over the place, that’s less secure.

    3) If you aren’t at a checkout with a human there, when you are under duress there’s no mechanism by which you can disable the thing. A credit card pin requires your cooperation (your mind holds the PIN safe). Your hand can be forced onto Touch ID to pay someone’s reader. You can’t surreptitiously disable it by putting your pinky on it. Sure, you can get your money back later, but that won’t stop a criminal from putting you through this ordeal so they can walk away with something. And your iPhone will also be taken of course.

    4) Emails will be sent in the clear (unencrypted) with info on your purchase. Yet more may be sent when various of your devices use Apple Pay for the first time. Credit card companies don’t do that (generally).

    I dunno, this is just off the top of my head. Apple made things super easy, but may have made things LESS secure from various points of view.

  2. Anyway, I have my shiny iPhone 6 and can’t wait to try Apple Pay and use it. Been waiting for this for a long time. Step 1 to eliminate my wallet… and just carry the iPhone. Even with the security drawbacks.

  3. 1) Why do you need to carry your credit card? I have several cards. I’ll be able to put all of them in my phone, something I carry with me anyway, and then get rid of all but one from my wallet. Here in the United States, at least through much of next year, we don’t have the more secure chip-and-pin cards that are elsewhere. If my wallet gets lost or stolen, that’s a lot of charges someone could rack up while I’m trying to cancel all of them. In my iPhone, if they steal that, I can not only wipe the phone and brick it with Find My iPhone, but my carrier will give me another phone (if I am using their insurance/security program). The phone will automatically brick itself if I have a passcode put in and a limit on the number of tries they have to figure it out.

    2) Unless you leave your $750 shiny at home, there is a chance it is going to be stolen or lost anyway. You wave it around every time you make a phone call or look at it for a message or to check something on the Internet. This is a non-issue used as filler in your argument.

    3) Again, here in the US,we don’t have chip-and-pin. And a real criminal holding a gun to your head to get you to use your TouchID is probably going to shoot you for not entering a PIN also. Again, I’m not seeing this as a valid argument.

    4) As far as I’ve read the only thing transferred between the phone and the merchant is a randomized number given to you by the credit card company. Your actual card number and information about you does not pass over. There will be no information on emails related to your card. I won’t even get a receipt with the last four digits of my card on it now because the merchant never got my actual card number. (Which should make it fun for me to enter my receipts in my accounting software at the end of the day.) Can you direct me to this information you have about everything being handed over, in the clear or not, by ApplePay?

    Personally, at least here in the USA for the time being, this is going to be way more secure than carrying around a wallet full of stripe cards that anyone can use by entering my ZIP code from my driver’s license as confirmation. In fact, I can’t wait for chip-and-pin to get here, and ApplePay is a way to get that now for the most part.

  4. Now I wish Apple played that “Target/Hope Depot breaches” angle up in their Sep. keynote.
    It would’ve added much more credibility to the new service category.

    The last time Apple ventured into a new service category and nailed it was iCloud .

  5. These are the best you can come up with? I say they instead prove Apple Pay is pretty secure, could be the most secure like the article claimed even.

  6. Behaviorally, there is immense pleasure in paying for something without using your card or cash. Seriously.

    If for no other reason, it will be popular because of that.

  7. I assume it requires a data connection, right?

    Seems logical but I don’t want to take my iPhone’s out to test if they don’t work (test devices so no data).

    This is also an issue in rural areas, depending on your carrier, in Texas. So many towns here where connections for calls are about all you can get.

    Good stuff though, ready for this launch!

  8. Why would they do that when they need merchants like Target and Home Depot to support Apple Pay? And that would look pretty bad considering they were in the middle of an iCloud celebrity scandal.

  9. ApplePay seems brilliant in its simplicity. But let’s reserve superlatives like “best of both worlds” and “most secure” until it has been used in the wild for some time.

Leave a Reply

Your email address will not be published. Required fields are marked *