Fraud Rampant In Apple Pay
PvtVoid writes with this report from the New York Times, excerpting: An industry consultant, Cherian Abraham, put the fraud rate [for Apple Pay] at 6 percent, compared with a traditional credit card fraud rate that is relatively minuscule, 10 cents for every $100 spent. [i.e. one tenth of one percent]. The vulnerability in Apple Pay is in the way that it — and card issuers — "onboard" new credit cards into the system. Because Apple wanted its system to have the simplicity for which it has become famous and wanted to make the sign-up process "frictionless," the company required little beyond basic credit card information about a user. Nor did it provide much information to the banks, like full phone numbers and addresses, that might help them detect fraud early. The banks, desperate to become their customers' default card on Apple Pay — most add only one to their iPhones — did little to build their own defenses or to push Apple to provide more detailed information about its customers. Some bank executives acknowledged that they were were so scared of Apple that they didn't speak up.
I read another article on this. As the article tries to expose, the fault lies not in Apple Pay, but rather in (as the article suggests), the process by which cards are authorized for use with Apple Pay during the onboarding process. There are two paths, the Green Path and the Yellow Path when authorizing a card. The difference is the types of information collected and passed. Most cards go down the Green path. But, when a card has incomplete information, it goes down the Yellow path and is subject to less stringent and, sometimes, manual intervention. It is down this pathway where the fraud occurs.
While a card is being approved during the Yellow pathway, the card can be used using the card number, expiration date and, not always, the security check value.
It is up to the banks and card issuers to secure their onboarding process. Apple (via Apple Pay) is not responsible for ensuring this takes place. Thankfully, the fraud is easy to detect and remedy. Next year, when our cards all have chips in them, the exposure via the Yellow Path will all be eliminated.
Apple supporters were right to call out Mr. Abraham - he is biased and attempting to create FUD against Apple and Apple Pay. The real fault and finger pointing needs to be directed to the banks and they need to get their houses in order.
How on earth does Apple Pay have more simplicity than a credit card? Here's how it works with a credit card:
1. Touch card or even whole wallet on reader.
2. Done!
And for more expensive transactions (over 20GBP, soon to be 30):
1. Insert card.
2. Enter PIN.
3. Done.
It doesn't get much simpler than the first one, really. I don't even have to extract my card.
SJW n. One who posts facts.
My bank and CC companies verified my request to add the card to ApplePay after I added it to my phone but before it was usable.
I had to login to THEIR sites, not Apples.
Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
...and stop calling me Shirley.