upvote
There is already apple wallet where i can put any of my banking cards…
reply
Not "any". The bank themselves need to partner with Apple Pay and presumably pay Apple the percentage cut from the article.
reply
I have used both but I dont know the difference
reply
How does it work on Google Wallet?
reply
Article says Google wallet works just like Apple Pay, except they don’t charge a 0.15% fee.
reply
Do you mean this part?

> It points to Google's Android, which supports multiple wallets and does not collect a fee from card issuers for contactless payments. It suggests Apple would not be able to continue to charge "substantial fees" if it were forced to support other mobile wallets on Apple devices.

This described supporting multiple wallets, which I don’t care about. I don’t want multiple wallets, I want one wallet.

reply
Why shouldn’t Apple be able to make money for the service they created?
reply
The phone holds on to a credit card number and some extra information. What service is happening here? Is Apple doing something meaningful every payment?
reply
The phone doesn't store your card number. Apple brokers a token at setup, secures it on-device, and manages it afterward (suspend, re-issue).
reply
So it doesn't generate a second card number like other things I've used?

But anyway it sounds like the answer to my question is no, Apple is not doing anything meaningful per payment. They play a role in setting up a card and that's it. Is that accurate?

reply
A service for whom? It has already been paid for by the users when they bought the iPhone.
reply
Users aren’t paying the fee though
reply
Of course they are, passed on as increased prices for everyone, which is exactly the problem. Sure the banks here would like these fees gone, but it also hurts society in general.
reply
Another alternative (in the US, at least) is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all. What an unforced error, to shovel more of your data at them needlessly.
reply
> is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all.

Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.

The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)

reply
Importantly, this provides a degree of protection from compromised PoS terminals. Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges, whereas back when I was still tapping, inserting, or swiping my card I’d need to call and get a card or two replaced almost every year.
reply
> Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges

BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.

[1] https://stripe.com/en-sg/resources/more/what-are-bin-attacks...

reply
Inserting and tapping is just as safe.

Swiping is where the risk is.

reply
I’m not super familiar with the implementation details but wouldn’t inserting not be as safe since there’s a physical connection?

With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?

reply
Inserting and tapping is mostly the same process, apart from the physical layer of the protocol (NFC vs interfacing the chip directly).

Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.

reply
> Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.

At least around where I am (Ohio, USA), at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.

In doing so, entire card is pushed all the way into the same slot that is also used for reading the magstripe, and to the same depth that is used for magstripe transactions.

This quality leaves the door open for magstripe skimming.

(It may be a stupid way of building things, but things exist in the real world that are built this way anyhow. Whether the information on the mag stripe still has any utility for a would-be thief in 2026 is a different matter.)

reply
The credit cards, I believe, have pledged to eliminate magnetic stripes. Although given how long it takes us to do anything for all I know that will be by 2060. They are also planning to extend credit cards past 16 digits, which may also require the magstripe to go away.
reply
Physical connection doesn't matter. This isn't a Hollywood movie, there isn't some mega-virus which magically seizes controls of trivial objects by passing through a connector.

All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.

The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.

Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...

EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.

In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.

reply
Or (common in the US) handing your card to a restaurant waiter who walks off with it to do the charge
reply
All EMV transactions (including Apple Pay in a tap to pay scenario) don’t give the retailer the full card number.
reply
don’t be silly, apple displays me exact amount on the screen, in plain fucking text, after each transaction - that’s crazy you wrote this
reply
This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.

The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).

Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)

reply
> This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.

except of course it fucking doesn’t, I don’t have Chase or Amex apps on my phone… and yet my transactions are on my phone and watch and in a list inside my “wallet” and probably in the phone settings somewhere as well :)

reply
Man, its amazing how confident you are about this, considering I know individual people who independently work at Visa, Mastercard, AND Apple, who have worked on mobile payments who independently confirm that none of them know any personal info and that its all pass-through.

So, are you sure you know what you are talking about?

reply
This kind of appeal to authority [believe me because I say so!] doesn't really add much information, does it?

The report, above, is that previous transactions are visible within Apple's payment app. Apple agrees[1]. I'm willing to accept that this observation is based on reality and that it is reported in good faith.

Meanwhile, the suggestion is that Apple has no knowledge of transaction history.

Is there a way in which these two seemingly-conflicting concepts can be constructively combined into an understandable whole?

[1]: https://support.apple.com/en-us/104954

(For my part, I've never used Apple Pay and it's possible that I never will. I do not have a dog in this race.)

reply
This is baffling, there's all sorts of information on my phone that Apple has zero knowledge of, why would the transactions be different?

Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.

reply
> This is baffling, there's all sorts of information on my phone that Apple has zero knowledge of, why would the transactions be different?

It's kind of unique. It involves finances, and reporting transactions, and it involves their app with their branding that runs on hardware that they unilaterally control. They apparently even take cut from the middle of each of these transaction.

If Apple does all of this with zero knowledge, then I am willing to accept accept that...

> Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.

...but I'll only accept it if the functional operation can be explained.

This kind of non-explanatory browbeating doesn't further my understanding of anything at all. I have never endeavored to undertake a faith-based approach to understanding technology, and I'm certainly not going to begin doing so today.

reply
people will people :-)
reply
That is much better, but you're still paying visa/mastercard some percentage fee for a service which should be provided by e.g. the central bank.
reply
Banks in the Netherlands used to have their own system for 30 years. It was free. It worked.

But it was too much work and didn't make the banks money so now we are also left to the American Visa parasite.

reply
Yeah. But this is the US. This is all we’ve got. Having the central bank do it would be communism, and that’s bad. I learned about it from Saturday morning cartoons.
reply
Ironically it's the central bank (and associated regulations) that cause these intermediaries to exist to begin with.

A protocol to support decentralized payments is a hobby project for an individual. You give each institution an identifier (e.g. their domain name) and each institution gives each customer an account number. If you're account 123 at Chase then you sign in as #123@chase.com, tell Chase you want to send $5 to #456@bankofamerica.com, they send the money and Bank of America tells their customer they have a new deposit. If you want to collect money from someone, you tell your bank to send their bank a payment request and they can either approve it manually (e.g. so you can deliver the goods for a one-time purchase) or configure some rules for which accounts get approved automatically up to some threshold amount (e.g. for recurring payments). Also no reason for banks in different countries not to all support the same protocol.

That doesn't require a central bank or any centralized third party payments intermediary. All it requires is for banks to know how to send money to other banks, which they obviously already do and the specific implementation of that isn't even relevant to the customer-facing payments protocol. So how does this not exist? It can't be that no one wants it, so it's got to be that someone (e.g. Visa/MasterCard) doesn't want it.

reply
The banks all got together and created Zelle, so it exists. No Visa/Mastercard conspiracy needed.
reply
Zelle is an app rather than a protocol, which is why e.g. PoS terminals and web checkouts don't support it.
reply
Zelle, from my understanding, is a “protocol” – many banks support it in their own apps. (Scare quotes because I’m not entirely sure it’s a proper well-defined protocol.)

And there’s nothing preventing PoS from supporting individual wallet apps – see e.g. WeChat Pay / Alipay in China. (Alipay+ is also a “protocol”, i.e. other banks and wallets support it.)

reply
yea, feels like tech giants do not have access to this already? they know where you are and what you do every second of every day, keeping away from ( while they know I was a target ) what was the amount on my receipt is really giving it to them :)
reply