Somewhat related, even Walmart relented and now supports Apple Pay/Contactless. Every big merchant has now relented (Kroger, Home Depot, Walmart).
Why do we need my bank to send money to your bank via Visa or the Federal Reserve or any such thing, instead of having my bank send money directly to your bank? All they need to do is both support the same openly specified protocol for transferring money.
This is a very US-centric take. In the UK, EU and Australia, interchange rates are capped at more like 0.2/0.3%.
> It points to Google's Android, which supports multiple wallets and does not collect a fee from card issuers for contactless payments. It suggests Apple would not be able to continue to charge "substantial fees" if it were forced to support other mobile wallets on Apple devices.
This described supporting multiple wallets, which I don’t care about. I don’t want multiple wallets, I want one wallet.
Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.
The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)
BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.
[1] https://stripe.com/en-sg/resources/more/what-are-bin-attacks...
Swiping is where the risk is.
With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?
Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.
All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.
The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.
Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...
EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.
In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.
The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).
Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)
So, are you sure you know what you are talking about?
The report, above, is that previous transactions are visible within Apple's payment app. Apple agrees[1]. I'm willing to accept that this observation is based on reality and that it is reported in good faith.
Meanwhile, the suggestion is that Apple has no knowledge of transaction history.
Is there a way in which these two seemingly-conflicting concepts can be constructively combined into an understandable whole?
[1]: https://support.apple.com/en-us/104954
(For my part, I've never used Apple Pay and it's possible that I never will. I do not have a dog in this race.)
Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
It's kind of unique. It involves finances, and reporting transactions, and it involves their app with their branding that runs on hardware that they unilaterally control. They apparently even take cut from the middle of each of these transaction.
If Apple does all of this with zero knowledge, then I am willing to accept accept that...
> Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
...but I'll only accept it if the functional operation can be explained.
This kind of non-explanatory browbeating doesn't further my understanding of anything at all. I have never endeavored to undertake a faith-based approach to understanding technology, and I'm certainly not going to begin doing so today.
A protocol to support decentralized payments is a hobby project for an individual. You give each institution an identifier (e.g. their domain name) and each institution gives each customer an account number. If you're account 123 at Chase then you sign in as #123@chase.com, tell Chase you want to send $5 to #456@bankofamerica.com, they send the money and Bank of America tells their customer they have a new deposit. If you want to collect money from someone, you tell your bank to send their bank a payment request and they can either approve it manually (e.g. so you can deliver the goods for a one-time purchase) or configure some rules for which accounts get approved automatically up to some threshold amount (e.g. for recurring payments). Also no reason for banks in different countries not to all support the same protocol.
That doesn't require a central bank or any centralized third party payments intermediary. All it requires is for banks to know how to send money to other banks, which they obviously already do and the specific implementation of that isn't even relevant to the customer-facing payments protocol. So how does this not exist? It can't be that no one wants it, so it's got to be that someone (e.g. Visa/MasterCard) doesn't want it.
And there’s nothing preventing PoS from supporting individual wallet apps – see e.g. WeChat Pay / Alipay in China. (Alipay+ is also a “protocol”, i.e. other banks and wallets support it.)
But it was too much work and didn't make the banks money so now we are also left to the American Visa parasite.
It was all so hilariously badly designed compared to tap and pay.
I don't really care about any of Apple's business partners being upset about their business terms with Apple. Developers want a bigger cut, banks want a bigger cut, Foxconn wants a bigger cut.
My interests as an Apple user are aligned with Apple. But even if I wasn't an Apple user, market forces determine what the "fair" cut is for everyone.
So, it’s not unlimited cost here.
The fact right now is that handling cash is more expensive than handling card- even with the fees, which is why Sweden, Estonia etc; are essentially cash-free countries.
At some point the fee’s will make you break-even I guess?
There already is a public option in the US, FedNow. In EU there's SEPA instant.
I won't use $bank-wallet either but that's a seperate issue which is that the bank is not really any better than Apple or PayPal or anyone else. The only reason they "fight" Apple tax is because they want to do $bank tax.
Cards get linked to accounts automatically behind the scenes based on first6/last4 card number tracking, then everyone else self-selects to punch their phone number on the screen.
Same reason Walmart Radio is such gruesome auditory cancer, it's part of the data collection and advertising vehicle.
Millions of transactions a day, over thousands of stores, it can make a huge difference in time saved.
I don't really get how this can be possible. A person can definitely get their card out of their wallet in less time than it takes the cashier to finish scanning their items.
Obviously if the customer is confused then it can take arbitrarily long, but how is a phone less confusing than a card? People don't get to the register only to realize that their card's battery is run down or it's the first time they've used a phone for payments and then they want to stand there for 15 minutes in front of you trying to set it up.
Cashier must explain: No tap. Best case is the customer shrugs and inserts card. Bad case is the customer is confused or argues about it. Horrible case is that the customer must fish through his belongings for a credit card or cash and takes minutes to realize he has neither.
I guess Walmart figured that these scenes repeating daily was not worth whatever its strategy was.
The transaction itself doesn't touch any Apple severs. In case anyone is wondering if there is an operational cost. There is a set up cost though with the initial verification and sometimes Apple do charge a one time fee per card set up.
There is a privacy angle with using Apple Pay. But I am unsure how much info banks and network is not getting because of it.
However Apple is providing something in all this. Apple Pay requires biometrics which (in theory) should help lower fraud costs for everyone. So it’s not like they’re just rent seeking for nothing.
I don’t know how it went for everyone else, but I don’t remember tapped pay getting popular until after Apple Pay and Apple pushing it. I know that coincided with when EMV terminals really started to get popular because the credit card companies were forcing it. But I honestly wonder if they helped push it to the mainstream, even for people just using tap cards.
It's regional—tap with cards was fairly popular in Canada before Apple Pay came along, but every time I visited the US I remember being surprised at how many retailers supported only the magnetic stripe.
The lawsuit was files in 2022, and apple opened access to the NFC chip in 2024 (iOS 18.1). Searching I could find alternative wallet apps that offer contactless payments, but only in EEA, eg [0, 1, 2]. It is supposed to be accessible in the US, but I am not sure why there are no apps there, unless I have missed them.
IANAL but if access to NFC is open since 2024 and (assumingly) the amount banks etc pay for apple pay has not really decreased, wouldn't that mean that their main argument is not really substantive?
[0] paypal @germany https://www.macrumors.com/2025/05/13/paypal-contactless-paym...
[1] curve pay @eu(?) https://www.macrumors.com/2025/05/23/curve-pay-launches-ipho...
[2] Vipps mobilepay @norway https://vippsmobilepay.com/en-NO/news/2024/12/09/vippsmobile...
Pix is doing exactly the right thing, as ECB/SEPA is as well.
The national co-integration is actually not a problem,asmost modern stacks are build on ISO20022 mainly, to the basis for co-integraion exists. Its just that attention on these topics is not that big. You could easily connect Brazil to the ECB with a correct setup.
Hacker News seems generally not interested in private payments or how terrible the banking system is, which is disappointing.
But I haven’t heard of it happening with the wild-west Android NFC payments, much less widespread problems with the essentially unconstrained use of QR code payments on SE Asia (e.g. Alipay).
So as an iPhone user I’m happy for Apple’s lockdown going away. I just hope it doesn’t mean that in future I’ll need to install a dozen payment apps and have to figure out which when I buy things.
I have no intention of using it. I have a feeling it’ll be crap. That’s how this stuff usually is. And I’m absolutely not going to use a different app for each card.
So I wonder if this will end up being a Pyrrhic victory.