Rendered at 10:09:11 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
havaloc 17 hours ago [-]
I get why the banks are not happy, but I can tell them that I am not going to use Chase Wallet, Bank of America Wallet, Citi Wallet...just pay the fee and be thankful for the reduced payment friction, which they invariably make money from. PS: Nobody is going to use Paze (yet another half baked wallet), other than to collect the free $10 to sign up for it.
Somewhat related, even Walmart relented and now supports Apple Pay/Contactless. Every big merchant has now relented (Kroger, Home Depot, Walmart).
radialstub 15 hours ago [-]
This is the government's problem. I tend to be on the side of less government, but it is so obvious that payment facilitation should be a service provided by the government. The government is just allowing corporations to collect rents, because they are lazy and incompetent.
bnjms 14 hours ago [-]
They’re more like taxes than rents. It’s a constant cost applied to all goods because of the ubiquity of use means we pay with or without playing the credit card/payments game.
AnthonyMouse 13 hours ago [-]
This is fundamentally looking at it the wrong way.
Why do we need my bank to send money to your bank via Visa or the Federal Reserve or any such thing, instead of having my bank send money directly to your bank? All they need to do is both support the same openly specified protocol for transferring money.
It's not something irreplaceable but it's not trivial either.
havaloc 13 hours ago [-]
Listen to the Visa episode of The Acquired Podcast, and you'll change your mind.
AnthonyMouse 2 hours ago [-]
If you have an open standard decentralized protocol that banks are required to support, that's the network effect solved. Merchants and anyone making the software that merchants use would want to support it because you're getting rid of Visa's fees.
rietta 13 hours ago [-]
We used to call those checks!
owebmaster 11 hours ago [-]
That's what Brazilian pix does and the reason visa/Mastercard and the US government want to kill it
hdgvhicv 9 hours ago [-]
Most counties have such a system, many are more advanced than visa etc (seemless customer-customer payments too for example.
From NETs in singapore to girocard in Germany, Alipay to UPI.
guywithahat 15 hours ago [-]
It's not a government problem, it's a competition problem. Fundamentally 1-3% is actually a very competitive rate for organizing the easy transfer of money and handling fraud. Merchants would rather the cost be free, and banks may want a larger slice of the pie, but until someone comes up with a better way of paying money for both sides this is the best we have. If government got involved all that could happen is fees would increase and then we'd miss out on future efficiency improvements and savings.
stevesimmons 14 hours ago [-]
> Fundamentally 1-3% is actually a very competitive rate for organizing the easy transfer of money and handling fraud
This is a very US-centric take. In the UK, EU and Australia, interchange rates are capped at more like 0.2/0.3%.
gruez 14 hours ago [-]
That actually proves the point, because a market left to itself arrives at 2-3%, and it only goes lower if the government is dictating a rate.
Flimm 13 hours ago [-]
What you are missing is that a market left to itself is not necessarily competitive when monopolies/duopolies form.
wenc 9 hours ago [-]
There are distortions in that "market" because credit cards aren't just for payment acceptance and fraud handling (which are narrow functions).
In the U.S., many credit cards bundle short term credit, rewards, travel benefits, insurance etc. This bundling is why merchants can pay up to 2-3% in fees.
The payment clearance and settlement parts are much cheaper. That's why many countries are able to build domestic payment rails (e.g. Pix in Brazil) that process transactions at low cost.
overfeed 10 hours ago [-]
A duopoly is not "a market"
Dylan16807 13 hours ago [-]
Proves what point? GP was saying the government would only increase fees.
MBCook 14 hours ago [-]
0% because it’s a service that’s so obviously should be provided by the government is better.
coredog64 13 hours ago [-]
Having been a customer of a government run postal bank, I'm going to hard disagree.
93po 10 hours ago [-]
The USPS is overwhelmingly the most efficient and inexpensive way to ship things. Try sending a letter cross country with UPS - it costs $15. USPS costs $0.50.
Government doesn't always mean worse.
syvolt 16 hours ago [-]
Or Apple Pay can just be like Google Wallet is on Android? The alternative is not multiple apps.
shreddit 16 hours ago [-]
There is already apple wallet where i can put any of my banking cards…
ValentineC 14 hours ago [-]
Not "any". The bank themselves need to partner with Apple Pay and presumably pay Apple the percentage cut from the article.
fsckboy 11 hours ago [-]
if apple wallet works on android and I have a choice, that's competititon
if apple wallet requires apple phone, and google wallet require android phone, that not competition.
competition is good. no competition should be regulated out of existence.
kelvinjps10 16 hours ago [-]
I have used both but I dont know the difference
juiceland 16 hours ago [-]
How does it work on Google Wallet?
sgerenser 15 hours ago [-]
Article says Google wallet works just like Apple Pay, except they don’t charge a 0.15% fee.
juiceland 12 hours ago [-]
Do you mean this part?
> It points to Google's Android, which supports multiple wallets and does not collect a fee from card issuers for contactless payments. It suggests Apple would not be able to continue to charge "substantial fees" if it were forced to support other mobile wallets on Apple devices.
This described supporting multiple wallets, which I don’t care about. I don’t want multiple wallets, I want one wallet.
sgerenser 10 hours ago [-]
Android supporting multiple wallets isn’t a feature of Google Pay, it’s a feature of Android. Although the implication in the article is that Google not being able to charge the fee is a side effect of any app being able to act as a “wallet.” Which I’m not 100% sure is true.
11 hours ago [-]
ericmay 13 hours ago [-]
Why shouldn’t Apple be able to make money for the service they created?
Dylan16807 13 hours ago [-]
The phone holds on to a credit card number and some extra information. What service is happening here? Is Apple doing something meaningful every payment?
juiceland 12 hours ago [-]
The phone doesn't store your card number. Apple brokers a token at setup, secures it on-device, and manages it afterward (suspend, re-issue).
Dylan16807 11 hours ago [-]
So it doesn't generate a second card number like other things I've used?
But anyway it sounds like the answer to my question is no, Apple is not doing anything meaningful per payment. They play a role in setting up a card and that's it. Is that accurate?
juiceland 11 hours ago [-]
When you add a card, your bank creates a device-specific Device Account Number, encrypts it, and sends it to Apple w/ a key used to generate a unique sec code for each transaction.
Dylan16807 11 hours ago [-]
And is that information stored on the phone? Do Apple's servers need to be running for me to make a purchase?
juiceland 8 hours ago [-]
Not if you're tapping in a store. Apple's servers re-encrypt the payment data for specific merchants if you buy in an app or on a website. Apple brokers requests for adding a card, or suspending one via Find My, or setting one up again whenever a person changes phones.
Muximize 13 hours ago [-]
A service for whom? It has already been paid for by the users when they bought the iPhone.
ericmay 13 hours ago [-]
Users aren’t paying the fee though
Muximize 12 hours ago [-]
Of course they are, passed on as increased prices for everyone, which is exactly the problem. Sure the banks here would like these fees gone, but it also hurts society in general.
hdgvhicv 8 hours ago [-]
And customer are also paying cash handling fees, which in the U.K. at higher than card handling fees.
Companies that prefer or only take cash tend to do it for tax evasion rather than cost purposes.
U.K. fees tend to be about 1-1.5% all in, for cash or card (excluding cost of employee taking cash to bank). Things like pix, net, grocers about 0.5-1%. Nets QR is cheaper than Nets rfid.
ericmay 11 hours ago [-]
That’s true of any cost that any company pays for any service.
add-sub-mul-div 15 hours ago [-]
Another alternative (in the US, at least) is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all. What an unforced error, to shovel more of your data at them needlessly.
jasode 15 hours ago [-]
> is tapping a piece of plastic instead of your phone and not inviting any of the tech giants into your transactions at all.
Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.
The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)
MBCook 14 hours ago [-]
All EMV transactions (including Apple Pay in a tap to pay scenario) don’t give the retailer the full card number.
cosmic_cheese 15 hours ago [-]
Importantly, this provides a degree of protection from compromised PoS terminals. Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges, whereas back when I was still tapping, inserting, or swiping my card I’d need to call and get a card or two replaced almost every year.
ValentineC 13 hours ago [-]
> Ever since I switched to nearly exclusively using Apple Pay for physical shopping I’ve had no unauthorized charges
BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.
I’m not super familiar with the implementation details but wouldn’t inserting not be as safe since there’s a physical connection?
With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?
notpushkin 13 hours ago [-]
Inserting and tapping is mostly the same process, apart from the physical layer of the protocol (NFC vs interfacing the chip directly).
Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.
ssl-3 12 hours ago [-]
> Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.
At least around where I am (Ohio, USA), at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.
In doing so, entire card is pushed all the way into the same slot that is also used for reading the magstripe, and to the same depth that is used for magstripe transactions.
This quality leaves the door open for magstripe skimming.
(It may be a stupid way of building things, but things exist in the real world that are built this way anyhow. Whether the information on the mag stripe still has any utility for a would-be thief in 2026 is a different matter.)
notpushkin 2 hours ago [-]
> at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.
Fairly standard for ATMs, yeah. I’ve always wondered why they do it like that.
And I think I’ve seen ticket machines like this in Finland – not a typical ATM-like receptacle, but you do insert the card all the way in and it locks it down. (I guess Ohio gas pumps also have something like that?)
So yeah, those things exist, but the “typical” terminal style where you only insert the card halfway is fairly safe at least. :-)
MBCook 11 hours ago [-]
The credit cards, I believe, have pledged to eliminate magnetic stripes. Although given how long it takes us to do anything for all I know that will be by 2060. They are also planning to extend credit cards past 16 digits, which may also require the magstripe to go away.
tialaramex 13 hours ago [-]
Physical connection doesn't matter. This isn't a Hollywood movie, there isn't some mega-virus which magically seizes controls of trivial objects by passing through a connector.
All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.
The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.
Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...
EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.
In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.
MBCook 11 hours ago [-]
There are two forms of wireless. The first was “magstripe emulation” and it’s exactly what you think it is. The card would hand over the exact data on the magstripe.
It’s also exactly as secure as you think: it’s not.
That hasn’t been used for a long time, and I don’t even think people accept it anymore. May not have for years. At least for credit cards. It’s quite possible that’s still how door access cards or maybe gym membership cards work. I don’t really know.
Everything now and for many, many many years, has been EMV over NFC. And you’re right on that one it is essentially identical to sticking your card in the EMV reader.
tialaramex 10 hours ago [-]
The exact technologies used for "access cards" have varied over the years, but last time I checked most of them still aren't doing anything even vaguely secure. The card says "I'm card 1234-5678" and the access system checks that is on the list, welcome in. Like magnetic stripes it isn't obvious to the human operator, but just like magnetic stripes you can just clone it by listening and reciting the same, "I'm card 1234-5678".
Now to be fair, you'd often find these systems are so clumsily installed that you don't need to clone a card anyway, the out-of-hours access has an "emergency" generic key you can buy from a hardware store, the controller was placed on the wrong side of the door - that sort of thing. But even a well-installed system is typically vulnerable to a competent intruder.
mrpippy 14 hours ago [-]
Or (common in the US) handing your card to a restaurant waiter who walks off with it to do the charge
bdangubic 15 hours ago [-]
don’t be silly, apple displays me exact amount on the screen, in plain fucking text, after each transaction - that’s crazy you wrote this
deltaknight 14 hours ago [-]
This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.
The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).
Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)
bdangubic 11 hours ago [-]
> This information comes from the card issuer directly, after the transaction has completed. It usually requires the mobile banking app to be installed.
except of course it fucking doesn’t, I don’t have Chase or Amex apps on my phone… and yet my transactions are on my phone and watch and in a list inside my “wallet” and probably in the phone settings somewhere as well :)
11 hours ago [-]
tekla 15 hours ago [-]
Man, its amazing how confident you are about this, considering I know individual people who independently work at Visa, Mastercard, AND Apple, who have worked on mobile payments who independently confirm that none of them know any personal info and that its all pass-through.
So, are you sure you know what you are talking about?
ssl-3 14 hours ago [-]
This kind of appeal to authority [believe me because I say so!] doesn't really add much information, does it?
The report, above, is that previous transactions are visible within Apple's payment app. Apple agrees[1]. I'm willing to accept that this observation is based on reality and that it is reported in good faith.
Meanwhile, the suggestion is that Apple has no knowledge of transaction history.
Is there a way in which these two seemingly-conflicting concepts can be constructively combined into an understandable whole?
(For my part, I've never used Apple Pay and it's possible that I never will. I do not have a dog in this race.)
epistasis 14 hours ago [-]
This is baffling, there's all sorts of information on my phone that Apple has zero knowledge of, why would the transactions be different?
Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
ssl-3 13 hours ago [-]
> This is baffling, there's all sorts of information on my phone that Apple has zero knowledge of, why would the transactions be different?
It's kind of unique. It involves finances, and reporting transactions, and it involves their app with their branding that runs on hardware that they unilaterally control. They apparently even take cut from the middle of each of these transaction.
If Apple does all of this with zero knowledge, then I am willing to accept accept that...
> Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
...but I'll only accept it if the functional operation can be explained.
This kind of non-explanatory browbeating doesn't further my understanding of anything at all. I have never endeavored to undertake a faith-based approach to understanding technology, and I'm certainly not going to begin doing so today.
bdangubic 11 hours ago [-]
people will people :-)
Elfener 15 hours ago [-]
That is much better, but you're still paying visa/mastercard some percentage fee for a service which should be provided by e.g. the central bank.
expedition32 13 hours ago [-]
Banks in the Netherlands used to have their own system for 30 years. It was free. It worked.
But it was too much work and didn't make the banks money so now we are also left to the American Visa parasite.
MBCook 14 hours ago [-]
Yeah. But this is the US. This is all we’ve got. Having the central bank do it would be communism, and that’s bad. I learned about it from Saturday morning cartoons.
AnthonyMouse 14 hours ago [-]
Ironically it's the central bank (and associated regulations) that cause these intermediaries to exist to begin with.
A protocol to support decentralized payments is a hobby project for an individual. You give each institution an identifier (e.g. their domain name) and each institution gives each customer an account number. If you're account 123 at Chase then you sign in as #123@chase.com, tell Chase you want to send $5 to #456@bankofamerica.com, they send the money and Bank of America tells their customer they have a new deposit. If you want to collect money from someone, you tell your bank to send their bank a payment request and they can either approve it manually (e.g. so you can deliver the goods for a one-time purchase) or configure some rules for which accounts get approved automatically up to some threshold amount (e.g. for recurring payments). Also no reason for banks in different countries not to all support the same protocol.
That doesn't require a central bank or any centralized third party payments intermediary. All it requires is for banks to know how to send money to other banks, which they obviously already do and the specific implementation of that isn't even relevant to the customer-facing payments protocol. So how does this not exist? It can't be that no one wants it, so it's got to be that someone (e.g. Visa/MasterCard) doesn't want it.
fragmede 13 hours ago [-]
The banks all got together and created Zelle, so it exists. No Visa/Mastercard conspiracy needed.
AnthonyMouse 13 hours ago [-]
Zelle is an app rather than a protocol, which is why e.g. PoS terminals and web checkouts don't support it.
notpushkin 13 hours ago [-]
Zelle, from my understanding, is a “protocol” – many banks support it in their own apps. (Scare quotes because I’m not entirely sure it’s a proper well-defined protocol.)
And there’s nothing preventing PoS from supporting individual wallet apps – see e.g. WeChat Pay / Alipay in China. (Alipay+ is also a “protocol”, i.e. other banks and wallets support it.)
AnthonyMouse 3 hours ago [-]
What I mean by protocol is that there is an RFC or equivalent and anyone who implements the spec and has a bank account can then talk to their bank using the standardized protocol. If that exists for Zelle then where's the spec?
notpushkin 2 hours ago [-]
I’ve searched for ‘zelle spec’ and came across this line:
> Zelle® is available in over 2,400 banking and credit union apps.
so I’m pretty sure there is a spec because there is no way in hell this many banks are using ad-hoc protocols to talk to each other and/or a centralized system. But yeah, I don’t see anything published.
Chances are it’s something ISO 20022-ish. (Either that or an Excel spreadsheet.) Speaking of which...
> and has a bank account can then talk to their bank using the standardized protocol
...if you’re a big enough business, you probably can also speak ISO 20022 to your bank. If you want it on your personal account however, well, that makes two of us, but from practical standpoint what I care more about is that I can punch in an account number and send money near instantly, which Zelle seems to provide in the US (but I have to make do with whatever Wise provides, probably regular ACH judging by speeds).
bdangubic 15 hours ago [-]
yea, feels like tech giants do not have access to this already? they know where you are and what you do every second of every day, keeping away from ( while they know I was a target ) what was the amount on my receipt is really giving it to them :)
wmf 17 hours ago [-]
A possible compromise is to allow Apple Pay to be a monopoly as long as it doesn't charge any fees.
braiamp 15 hours ago [-]
How about I do you one better compromise: create a payment network that don't rely on private institutions rent seeking behavior, like Pix in Brazil.
dd8601fn 11 hours ago [-]
How about Chase continues to eat shit on that 0.15% extra profit they really want to capture, but aren’t owed… and everyone else goes on with their day?
braiamp 59 minutes ago [-]
I don't know how your solution makes any sense considering that I'm denying everyone rent seeking behavior
Scoundreller 5 hours ago [-]
> Somewhat related, even Walmart relented and now supports Apple Pay/Contactless.
Walmart USA.
Walmart Canada allowed contactless pretty much from the start over a decade ago
Always confused me on trips to USA when I’d have to insert a card
MBCook 14 hours ago [-]
Remember CurrenC? The thing a bunch of them tried to make that failed horribly during test with no consumers liking it? If I remember a description it involved using an app where you had to scan a QR code, and then the point of sale terminal had to scan a QR code on your phone or something like that.
It was all so hilariously badly designed compared to tap and pay.
kstrauser 12 hours ago [-]
I took great joy in watching its downfall. It also only worked with debit cards, meaning you didn’t get the buyer protections you use from buying things on a credit card.
CurrentC was designed to collect all your transaction info so that its owners could analyze your buying habits. I’m delighted that not-CurrentC won that war.
(I personally use Apple Pay, but my understanding is that Google Pay has the same privacy advantages for end users. Both of them are light years ahead of the other boondoggle.)
MBCook 11 hours ago [-]
Yeah, but it meant they didn’t have to pay credit card fees. And isn’t that what’s really the most important thing here? Lol.
As far as I know, the current Google Pay is identical to Apple Pay: it’s just EMV tap-to-pay. So it would be the same protections. Samsung pay too.
It was kind of neat that Samsung had that thing for a short while that would somehow trick the magstripe reader in a POS terminal by blasting magnetic fields at it to think that you had swiped your card.
I think there was a different one before that that was not, but I’m also pretty sure that’s long gone. And I think it was more like Apple Pay on the web, where it was really for paying in a non-card environment. But I’m not an android person, so I’m not sure.
Despegar 16 hours ago [-]
Now do developers.
I don't really care about any of Apple's business partners being upset about their business terms with Apple. Developers want a bigger cut, banks want a bigger cut, Foxconn wants a bigger cut.
My interests as an Apple user are aligned with Apple. But even if I wasn't an Apple user, market forces determine what the "fair" cut is for everyone.
caycep 17 hours ago [-]
granted i am a bit of schadenfreude at the thought of poor poor megabanks having to pay....fees...
otterley 17 hours ago [-]
Ultimately it comes out of their customers’ wallets.
dijit 15 hours ago [-]
Probably, but there is an upper limit on what people will be able to tolerate, everyone is aware of it and capitalism is trying to make products that meet it.
So, it’s not unlimited cost here.
The fact right now is that handling cash is more expensive than handling card- even with the fees, which is why Sweden, Estonia etc; are essentially cash-free countries.
At some point the fee’s will make you break-even I guess?
wasm777 17 hours ago [-]
[flagged]
HotGarbage 16 hours ago [-]
I would use my non-profit credit union Wallet if it meant less fees on their end.
grafmax 14 hours ago [-]
Another argument for turning finance into a public utility. Instead we have different factions of rentier capital competing for who gets to parasitize us.
gruez 14 hours ago [-]
>Another argument for turning finance into a public utility
There already is a public option in the US, FedNow. In EU there's SEPA instant.
grafmax 14 hours ago [-]
Not quite. FedNow is public payment infrastructure for institutions. Apple Pay is consumer-facing.
kotaKat 17 hours ago [-]
Walmart only relented because they finally broke through the final missing link of the contactless issue. They got customers conned into giving their phone numbers at checkout, just like it's the grocery store.
Cards get linked to accounts automatically behind the scenes based on first6/last4 card number tracking, then everyone else self-selects to punch their phone number on the screen.
Same reason Walmart Radio is such gruesome auditory cancer, it's part of the data collection and advertising vehicle.
havaloc 17 hours ago [-]
That could be part of the reason, but also I think insisting on chip all this time just really slows down a store that doesn't really spend on cashiering all that much. Tap to pay can shave off a few seconds on every transaction (ever been behind someone in the store who finally pulls out their wallet, finds the business end of their card, inserts it, waits 20 seconds...).
Millions of transactions a day, over thousands of stores, it can make a huge difference in time saved.
massysett 15 hours ago [-]
This is even worse now that tap to pay has proliferated. Customers who are not Walmart regulars (and some that are) will wave their credit card, phone, or watch over the terminal and wonder why it’s not working.
Cashier must explain: No tap. Best case is the customer shrugs and inserts card. Bad case is the customer is confused or argues about it. Horrible case is that the customer must fish through his belongings for a credit card or cash and takes minutes to realize he has neither.
I guess Walmart figured that these scenes repeating daily was not worth whatever its strategy was.
AnthonyMouse 13 hours ago [-]
> Tap to pay can shave off a few seconds on every transaction
I don't really get how this can be possible. A person can definitely get their card out of their wallet in less time than it takes the cashier to finish scanning their items.
Obviously if the customer is confused then it can take arbitrarily long, but how is a phone less confusing than a card? People don't get to the register only to realize that their card's battery is run down or it's the first time they've used a phone for payments and then they want to stand there for 15 minutes in front of you trying to set it up.
Brian_K_White 13 hours ago [-]
"My short term convenience trumps all" is why everything sucks and we have far worse short and long term convenience and efficiency in everything. Thanks for that.
I won't use $bank-wallet either but that's a seperate issue which is that the bank is not really any better than Apple or PayPal or anyone else. The only reason they "fight" Apple tax is because they want to do $bank tax.
ksec 15 hours ago [-]
It is estimated Apple Pay does anywhere between $5T to $10T transaction per year. That is everything from Credit Card to Debit Card. If we average out at 0.1% per transaction over $5T, that is $5B per year.
The transaction itself doesn't touch any Apple severs. In case anyone is wondering if there is an operational cost. There is a set up cost though with the initial verification and sometimes Apple do charge a one time fee per card set up.
There is a privacy angle with using Apple Pay. But I am unsure how much info banks and network is not getting because of it.
MBCook 14 hours ago [-]
Retailers may get less than using their own app, but I agree I don’t really see how it affects the processors or the banks.
However Apple is providing something in all this. Apple Pay requires biometrics which (in theory) should help lower fraud costs for everyone. So it’s not like they’re just rent seeking for nothing.
I don’t know how it went for everyone else, but I don’t remember tapped pay getting popular until after Apple Pay and Apple pushing it. I know that coincided with when EMV terminals really started to get popular because the credit card companies were forcing it. But I honestly wonder if they helped push it to the mainstream, even for people just using tap cards.
gucci-on-fleek 13 hours ago [-]
> but I don’t remember tapped pay getting popular until after Apple Pay and Apple pushing it
It's regional—tap with cards was fairly popular in Canada before Apple Pay came along, but every time I visited the US I remember being surprised at how many retailers supported only the magnetic stripe.
MBCook 11 hours ago [-]
I know it was in Europe FAR before the US too. I’m speaking from a very US centric perspective as that’s all I personally experienced.
No one wanted to put on EMV terminals because they didn’t want to pay the upgrade cost. Even if they bought them because they were the only thing, they wouldn’t turn any of the EMV stuff on. You still did everything like 1995. It was the liability shift that finally forced people to start. And that coincided well with Apple Pay. Which obviously was planned by Apple.
I also remember people hating it and trying to avoid it because it was so slow early on.
On the other hand, a lot of places that supported tap to pay didn’t even know. Lots of times when I started using Apple Pay I got confusion from the person checking me out. “What did you do, how did you pay” or “I didn’t know you could do that”. Multiple times retailers I used it at stopped taking it later. I assume they found out people were using it and freaked out because they didn’t know it was on.
There are still lots of retailers where the signs don’t say you can use it, or even the screens on the terminals, but it works fine. It’s still kind of mess but it generally works almost everywhere.
Cider9986 16 hours ago [-]
I hope we get tap to pay on GrapheneOS in the US soon. You can already use it in the EU with Curve and PayPal. It's a blocker for a lot of people.
Hacker News seems generally not interested in private payments or how terrible the banking system is, which is disappointing.
Pix and the other variants are the way to go for money transfer, it's just that these monopolies won't be happy to forfeit their easy money, both credit, banks as well as Apple. They are all fighting for monopolies, they must cease to exist for the good of the common folk.
KellyCriterion 16 hours ago [-]
Well, fortunately Pix is statedriven/stateenforced/strateregulated, so it contains some of the most important ingredients to become some type of standard - the only reason why Mastercard et.al. are so powerful is because this area/field of tech was long no recognised as critical/relevant enough.
Pix is doing exactly the right thing, as ECB/SEPA is as well.
gchamonlive 16 hours ago [-]
Totally, and hopefully if standardisation isn't possible that we will at least see some form of integration between these systems, even if under an international transaction fee.
KellyCriterion 15 hours ago [-]
Working in this field:
The national co-integration is actually not a problem,asmost modern stacks are build on ISO20022 mainly, to the basis for co-integraion exists. Its just that attention on these topics is not that big. You could easily connect Brazil to the ECB with a correct setup.
gchamonlive 15 hours ago [-]
I find this technology fascinating, I'm looking for different fields to apply myself to, if there's job openings for developing Pix here in Brazil I think I'll look into the tech more carefully.
freehorse 14 hours ago [-]
> Apple has changed its policies since the lawsuit was filed. As of iOS 18.1, developers are able to offer NFC contactless payments in their apps.
The lawsuit was files in 2022, and apple opened access to the NFC chip in 2024 (iOS 18.1). Searching I could find alternative wallet apps that offer contactless payments, but only in EEA, eg [0, 1, 2]. It is supposed to be accessible in the US, but I am not sure why there are no apps there, unless I have missed them.
IANAL but if access to NFC is open since 2024 and (assumingly) the amount banks etc pay for apple pay has not really decreased, wouldn't that mean that their main argument is not really substantive?
Initially I was casually (didn’t dig into the issue) fine with Apple allowing only a single access to payment via NFC due to the opportunity for fraud, which was Apple’s justification.
But I haven’t heard of it happening with the wild-west Android NFC payments, much less widespread problems with the essentially unconstrained use of QR code payments on SE Asia (e.g. Alipay).
So as an iPhone user I’m happy for Apple’s lockdown going away. I just hope it doesn’t mean that in future I’ll need to install a dozen payment apps and have to figure out which when I buy things.
Danox 11 hours ago [-]
What the banks want, and all the other financial institutions want is a free ride on someone else’s technology, without paying for it and it’s ironic because the Apple Pay system was only created by Apple because all of the other existing financial institutions believed at that time that the Apple ecosystems was too small to support, but once it became successful, all of a sudden they wanted in and cried foul to government to help them out.
MBCook 14 hours ago [-]
If the banks win and other stuff is allowed on the iPhone, that’s fine.
I have no intention of using it. I have a feeling it’ll be crap. That’s how this stuff usually is. And I’m absolutely not going to use a different app for each card.
So I wonder if this will end up being a Pyrrhic victory.
gumby 14 hours ago [-]
The problem is if merchants stop accepting Apple Pay or any other privacy-supporting payment system.
MBCook 11 hours ago [-]
I can stop shopping at places that decide to make it hard for me. It’s easier than ever to find someone else willing to sell me the same thing.
Especially since no one sells unique stuff anymore, it’s mostly the same discount crap from China. So it’s not like I can’t get it elsewhere.
wronex 12 hours ago [-]
How come my MasterCard is only a MasterCard. We need to sue them! It should be an Visa and an IKEA card too!
Bluescreenbuddy 12 hours ago [-]
The irony of them bitching about fees. They make billions off of charging fees to the low income. F*ck them.
The only time the People have anything in our sick phony republic protected is when their interests happen to coincidentally align with those of an adversarial oligarch. Not interested in digging through the 15 layers of competing interests, corporate spin, lies, and economics to determine if that’s the case here but it’s sad in any case that stories like this are the only hope we the People have of getting any crumbs out of this system.
Somewhat related, even Walmart relented and now supports Apple Pay/Contactless. Every big merchant has now relented (Kroger, Home Depot, Walmart).
Why do we need my bank to send money to your bank via Visa or the Federal Reserve or any such thing, instead of having my bank send money directly to your bank? All they need to do is both support the same openly specified protocol for transferring money.
It's not something irreplaceable but it's not trivial either.
From NETs in singapore to girocard in Germany, Alipay to UPI.
This is a very US-centric take. In the UK, EU and Australia, interchange rates are capped at more like 0.2/0.3%.
In the U.S., many credit cards bundle short term credit, rewards, travel benefits, insurance etc. This bundling is why merchants can pay up to 2-3% in fees.
The payment clearance and settlement parts are much cheaper. That's why many countries are able to build domestic payment rails (e.g. Pix in Brazil) that process transactions at low cost.
Government doesn't always mean worse.
if apple wallet requires apple phone, and google wallet require android phone, that not competition.
competition is good. no competition should be regulated out of existence.
> It points to Google's Android, which supports multiple wallets and does not collect a fee from card issuers for contactless payments. It suggests Apple would not be able to continue to charge "substantial fees" if it were forced to support other mobile wallets on Apple devices.
This described supporting multiple wallets, which I don’t care about. I don’t want multiple wallets, I want one wallet.
But anyway it sounds like the answer to my question is no, Apple is not doing anything meaningful per payment. They play a role in setting up a card and that's it. Is that accurate?
Companies that prefer or only take cash tend to do it for tax evasion rather than cost purposes.
U.K. fees tend to be about 1-1.5% all in, for cash or card (excluding cost of employee taking cash to bank). Things like pix, net, grocers about 0.5-1%. Nets QR is cheaper than Nets rfid.
Apple doesn't see individual transactions when Apple Pay is used at retail stores' tap-to-pay terminals. The secret card payment token is sent from the phone to the credit-card's issuing bank and bypasses Apple servers. In this way, using Apple Pay is more secure and private than plastic cards because the real card number details remains hidden from the merchant.
The iPhone does contact Apple servers to add a new card to the digital wallet. Apple servers then contacts the issuing bank to get the secret token the bank generates and then puts it in the digital wallet. Conceivably, the "add a new card to digital wallet" could also have been done without Apple in the middle but it would require a much more convoluted, less secure, and more user-hostile workflow to do it. (e.g. the end user would have to know what bank endpoint to contact, manually enter the long and cryptic digits of the secret token, or maybe scan a QR code on a computer screen that's vulnerable to interception and phishing.)
BIN attacks [1] are still a thing. Your banks are probably just better at blocking them.
[1] https://stripe.com/en-sg/resources/more/what-are-bin-attacks...
Swiping is where the risk is.
With tapping I could see how that is more secure but if they’re still providing the card details versus the secure token or something well… maybe it’s not?
Unless there’s a hidden magnetic reader in the chip-reading portion of the terminal, in which case the scammers could read like 1/3 of the magstripe data? Which doesn’t seem that useful tbh.
At least around where I am (Ohio, USA), at gas pumps and ATMs: Inserting the card for contact EMV typically means inserting the whole card.
In doing so, entire card is pushed all the way into the same slot that is also used for reading the magstripe, and to the same depth that is used for magstripe transactions.
This quality leaves the door open for magstripe skimming.
(It may be a stupid way of building things, but things exist in the real world that are built this way anyhow. Whether the information on the mag stripe still has any utility for a would-be thief in 2026 is a different matter.)
Fairly standard for ATMs, yeah. I’ve always wondered why they do it like that.
And I think I’ve seen ticket machines like this in Finland – not a typical ATM-like receptacle, but you do insert the card all the way in and it locks it down. (I guess Ohio gas pumps also have something like that?)
So yeah, those things exist, but the “typical” terminal style where you only insert the card halfway is fairly safe at least. :-)
All three modern technologies ("original" Chip & PIN, wireless or a phone) are basically the EMV protocol, which is a fairly crap protocol which wasn't reviewed by experts before deployment - but is at least designed by people who have heard about cryptographic security and wanted to do that.
The original credit cards are just numbers written on a card. Clerk sees your number, memorizes it, now they can make arbitrary transactions indistinguishable from yours. Basically no security.
Magnetic stripe cards look more sophisticated but the stripe is basically the same numbers again but in a way humans cannot read. "Cloning" is just a matter of a machine copying those numbers onto another card's magnetic stripe. There's no real security improvement, though it is more convenient for the bank...
EMV ("Chip and PIN") is rather more complicated and could in principle be entirely secure - they could make it implausibly expensive to "clone" an EMV card, and require that you actually know your PIN for every transaction, so then crooks would need to learn your PIN and have the actual card, and that's a high bar.
In practice we didn't do much of that because it would be inconvenient, and so there are technical deficiencies, but realistically that XKCD "wrench" thing applies. Difficult technological attacks rarely happen, crooks threaten to stab you if you don't co-operate or they break into your home and steal your stuff, they do not come up with breakthrough cryptanalytic attacks on protocols. Mostly.
It’s also exactly as secure as you think: it’s not.
That hasn’t been used for a long time, and I don’t even think people accept it anymore. May not have for years. At least for credit cards. It’s quite possible that’s still how door access cards or maybe gym membership cards work. I don’t really know.
Everything now and for many, many many years, has been EMV over NFC. And you’re right on that one it is essentially identical to sticking your card in the EMV reader.
Now to be fair, you'd often find these systems are so clumsily installed that you don't need to clone a card anyway, the out-of-hours access has an "emergency" generic key you can buy from a hardware store, the controller was placed on the wrong side of the door - that sort of thing. But even a well-installed system is typically vulnerable to a competent intruder.
The wallet app has a way to get the information, but it’s not from the tap itself. The tap interaction is not able to provide this information back to the phone (because the transaction auth happens long after the tap interaction completes).
Taps are designed to work with fully offline devices (which is why you can tap a plastic card, it is powered by the card terminal for the duration of the tap only, and requires no online interaction)
except of course it fucking doesn’t, I don’t have Chase or Amex apps on my phone… and yet my transactions are on my phone and watch and in a list inside my “wallet” and probably in the phone settings somewhere as well :)
So, are you sure you know what you are talking about?
The report, above, is that previous transactions are visible within Apple's payment app. Apple agrees[1]. I'm willing to accept that this observation is based on reality and that it is reported in good faith.
Meanwhile, the suggestion is that Apple has no knowledge of transaction history.
Is there a way in which these two seemingly-conflicting concepts can be constructively combined into an understandable whole?
[1]: https://support.apple.com/en-us/104954
(For my part, I've never used Apple Pay and it's possible that I never will. I do not have a dog in this race.)
Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
It's kind of unique. It involves finances, and reporting transactions, and it involves their app with their branding that runs on hardware that they unilaterally control. They apparently even take cut from the middle of each of these transaction.
If Apple does all of this with zero knowledge, then I am willing to accept accept that...
> Do you think Apple has complete copies of everything? I don't understand where this supposed contradiction is supposed to exist, unless you think that Apple has complete knowledge of all phone contents, which would require complete ignorance of the entire platform.
...but I'll only accept it if the functional operation can be explained.
This kind of non-explanatory browbeating doesn't further my understanding of anything at all. I have never endeavored to undertake a faith-based approach to understanding technology, and I'm certainly not going to begin doing so today.
But it was too much work and didn't make the banks money so now we are also left to the American Visa parasite.
A protocol to support decentralized payments is a hobby project for an individual. You give each institution an identifier (e.g. their domain name) and each institution gives each customer an account number. If you're account 123 at Chase then you sign in as #123@chase.com, tell Chase you want to send $5 to #456@bankofamerica.com, they send the money and Bank of America tells their customer they have a new deposit. If you want to collect money from someone, you tell your bank to send their bank a payment request and they can either approve it manually (e.g. so you can deliver the goods for a one-time purchase) or configure some rules for which accounts get approved automatically up to some threshold amount (e.g. for recurring payments). Also no reason for banks in different countries not to all support the same protocol.
That doesn't require a central bank or any centralized third party payments intermediary. All it requires is for banks to know how to send money to other banks, which they obviously already do and the specific implementation of that isn't even relevant to the customer-facing payments protocol. So how does this not exist? It can't be that no one wants it, so it's got to be that someone (e.g. Visa/MasterCard) doesn't want it.
And there’s nothing preventing PoS from supporting individual wallet apps – see e.g. WeChat Pay / Alipay in China. (Alipay+ is also a “protocol”, i.e. other banks and wallets support it.)
> Zelle® is available in over 2,400 banking and credit union apps.
so I’m pretty sure there is a spec because there is no way in hell this many banks are using ad-hoc protocols to talk to each other and/or a centralized system. But yeah, I don’t see anything published.
Chances are it’s something ISO 20022-ish. (Either that or an Excel spreadsheet.) Speaking of which...
> and has a bank account can then talk to their bank using the standardized protocol
...if you’re a big enough business, you probably can also speak ISO 20022 to your bank. If you want it on your personal account however, well, that makes two of us, but from practical standpoint what I care more about is that I can punch in an account number and send money near instantly, which Zelle seems to provide in the US (but I have to make do with whatever Wise provides, probably regular ACH judging by speeds).
Walmart USA.
Walmart Canada allowed contactless pretty much from the start over a decade ago
Always confused me on trips to USA when I’d have to insert a card
It was all so hilariously badly designed compared to tap and pay.
CurrentC was designed to collect all your transaction info so that its owners could analyze your buying habits. I’m delighted that not-CurrentC won that war.
(I personally use Apple Pay, but my understanding is that Google Pay has the same privacy advantages for end users. Both of them are light years ahead of the other boondoggle.)
As far as I know, the current Google Pay is identical to Apple Pay: it’s just EMV tap-to-pay. So it would be the same protections. Samsung pay too.
It was kind of neat that Samsung had that thing for a short while that would somehow trick the magstripe reader in a POS terminal by blasting magnetic fields at it to think that you had swiped your card.
I think there was a different one before that that was not, but I’m also pretty sure that’s long gone. And I think it was more like Apple Pay on the web, where it was really for paying in a non-card environment. But I’m not an android person, so I’m not sure.
I don't really care about any of Apple's business partners being upset about their business terms with Apple. Developers want a bigger cut, banks want a bigger cut, Foxconn wants a bigger cut.
My interests as an Apple user are aligned with Apple. But even if I wasn't an Apple user, market forces determine what the "fair" cut is for everyone.
So, it’s not unlimited cost here.
The fact right now is that handling cash is more expensive than handling card- even with the fees, which is why Sweden, Estonia etc; are essentially cash-free countries.
At some point the fee’s will make you break-even I guess?
There already is a public option in the US, FedNow. In EU there's SEPA instant.
Cards get linked to accounts automatically behind the scenes based on first6/last4 card number tracking, then everyone else self-selects to punch their phone number on the screen.
Same reason Walmart Radio is such gruesome auditory cancer, it's part of the data collection and advertising vehicle.
Millions of transactions a day, over thousands of stores, it can make a huge difference in time saved.
Cashier must explain: No tap. Best case is the customer shrugs and inserts card. Bad case is the customer is confused or argues about it. Horrible case is that the customer must fish through his belongings for a credit card or cash and takes minutes to realize he has neither.
I guess Walmart figured that these scenes repeating daily was not worth whatever its strategy was.
I don't really get how this can be possible. A person can definitely get their card out of their wallet in less time than it takes the cashier to finish scanning their items.
Obviously if the customer is confused then it can take arbitrarily long, but how is a phone less confusing than a card? People don't get to the register only to realize that their card's battery is run down or it's the first time they've used a phone for payments and then they want to stand there for 15 minutes in front of you trying to set it up.
I won't use $bank-wallet either but that's a seperate issue which is that the bank is not really any better than Apple or PayPal or anyone else. The only reason they "fight" Apple tax is because they want to do $bank tax.
The transaction itself doesn't touch any Apple severs. In case anyone is wondering if there is an operational cost. There is a set up cost though with the initial verification and sometimes Apple do charge a one time fee per card set up.
There is a privacy angle with using Apple Pay. But I am unsure how much info banks and network is not getting because of it.
However Apple is providing something in all this. Apple Pay requires biometrics which (in theory) should help lower fraud costs for everyone. So it’s not like they’re just rent seeking for nothing.
I don’t know how it went for everyone else, but I don’t remember tapped pay getting popular until after Apple Pay and Apple pushing it. I know that coincided with when EMV terminals really started to get popular because the credit card companies were forcing it. But I honestly wonder if they helped push it to the mainstream, even for people just using tap cards.
It's regional—tap with cards was fairly popular in Canada before Apple Pay came along, but every time I visited the US I remember being surprised at how many retailers supported only the magnetic stripe.
No one wanted to put on EMV terminals because they didn’t want to pay the upgrade cost. Even if they bought them because they were the only thing, they wouldn’t turn any of the EMV stuff on. You still did everything like 1995. It was the liability shift that finally forced people to start. And that coincided well with Apple Pay. Which obviously was planned by Apple.
I also remember people hating it and trying to avoid it because it was so slow early on.
On the other hand, a lot of places that supported tap to pay didn’t even know. Lots of times when I started using Apple Pay I got confusion from the person checking me out. “What did you do, how did you pay” or “I didn’t know you could do that”. Multiple times retailers I used it at stopped taking it later. I assume they found out people were using it and freaked out because they didn’t know it was on.
There are still lots of retailers where the signs don’t say you can use it, or even the screens on the terminals, but it works fine. It’s still kind of mess but it generally works almost everywhere.
Hacker News seems generally not interested in private payments or how terrible the banking system is, which is disappointing.
https://eylenburg.github.io/payments.htm
https://walt.is/
https://walt.is/
Pix is doing exactly the right thing, as ECB/SEPA is as well.
The national co-integration is actually not a problem,asmost modern stacks are build on ISO20022 mainly, to the basis for co-integraion exists. Its just that attention on these topics is not that big. You could easily connect Brazil to the ECB with a correct setup.
The lawsuit was files in 2022, and apple opened access to the NFC chip in 2024 (iOS 18.1). Searching I could find alternative wallet apps that offer contactless payments, but only in EEA, eg [0, 1, 2]. It is supposed to be accessible in the US, but I am not sure why there are no apps there, unless I have missed them.
IANAL but if access to NFC is open since 2024 and (assumingly) the amount banks etc pay for apple pay has not really decreased, wouldn't that mean that their main argument is not really substantive?
[0] paypal @germany https://www.macrumors.com/2025/05/13/paypal-contactless-paym...
[1] curve pay @eu(?) https://www.macrumors.com/2025/05/23/curve-pay-launches-ipho...
[2] Vipps mobilepay @norway https://vippsmobilepay.com/en-NO/news/2024/12/09/vippsmobile...
But I haven’t heard of it happening with the wild-west Android NFC payments, much less widespread problems with the essentially unconstrained use of QR code payments on SE Asia (e.g. Alipay).
So as an iPhone user I’m happy for Apple’s lockdown going away. I just hope it doesn’t mean that in future I’ll need to install a dozen payment apps and have to figure out which when I buy things.
I have no intention of using it. I have a feeling it’ll be crap. That’s how this stuff usually is. And I’m absolutely not going to use a different app for each card.
So I wonder if this will end up being a Pyrrhic victory.
Especially since no one sells unique stuff anymore, it’s mostly the same discount crap from China. So it’s not like I can’t get it elsewhere.