Jump to content

Additional security measures for Apple and Android Pay - is there any point using it now?


Recommended Posts

Posted (edited)

This is going to be a right pain in the backside... you are going to have to have your card on you even if you do use Apple or Android Pay

 

Message from my card provider (my bold)

 

We're getting in touch to let you know about new payment security measures that will start to be introduced from 14 September 2019, in response to a change in the law.

 

The new system is called Strong Customer Authentication (SCA), and will apply whenever you make a purchase from all retailers.

 

SHOPPING IN STORE

You'll notice changes when making contactless payments in shops, including when using Apple Pay, Samsung Pay and payments via wearable technology such as smart watches. You may be asked to insert your card and key in your PIN. Chip and PIN payments will continue to work as normal.

 

As the checks are random, you won't know in advance whether validation is required, and neither will store staff. So if you plan to use contactless payment, make sure you have the relevant card with you, or an alternative method to use, so you can continue with your purchase.

Edited by elsiegee40
Posted
That's a huge inconvenience, especially after just getting used to using Android Pay for transactions up to £100 rather than the £30 contactless limit!
  • Thanks 1
Posted
It kind of renders Apple and Android pay as pointless. Save time. Just use your card instead!

 

i already was my phone case has a credit card holder in it so ive just been using that lol saves google knowing my credit card number

Posted

Yep, that’s completely ignoring the point of Apple Pay (I’ve never had experience with Android Pay so can’t comment there). Apple Pay is designed to be secure, adding a check is basically saying they’re not willing to trust it.

 

I think these random checks are supposed to happen on contactless cards though, as far as I’ve read.

Posted
I have a Co-operative bank card which isn't contactless, but have set it up on my phone, which obviously is. I don't carry my wallet with me usually, now I'm going to have to again. I can now lose my wallet/have it stolen again therefore making it less secure. I see this as a backward step.
Posted

Forgive me if I being stupid here, but aren't Apple and Android Pay via a phone already more secure as you have to supply a fingerprint to authorise the transaction?

 

Anyone can take a chip and pin card and wave it at a machine but they couldn't steal a phone and use it to pay for things... right?

Posted
Forgive me if I being stupid here, but aren't Apple and Android Pay via a phone already more secure as you have to supply a fingerprint to authorise the transaction?

 

Anyone can take a chip and pin card and wave it at a machine but they couldn't steal a phone and use it to pay for things... right?

 

You are right, but it seems that the banks cannot distinguish between a phone-pay transaction and a regular contactless one, and therefore are treating them all as the low-security variant. It makes sense from an infosec point of view - the best route forward would be to find a way to separate phone-pay from contactless cards.

  • Thanks 1
Posted
You are right, but it seems that the banks cannot distinguish between a phone-pay transaction and a regular contactless one, and therefore are treating them all as the low-security variant. It makes sense from an infosec point of view - the best route forward would be to find a way to separate phone-pay from contactless cards.

 

They must be able to tell. IIRC Apple Pay didn’t work at first where contactless did. And Android Pay also had a delay.

  • Thanks 2
Posted
It's not every time, Lloyds already does this; we found out when we tried to pay by contactless and was refused, got home and rung the bank and they informed us of this - that it's random... Majority of the times it goes thru without any problems, the biggest thing is if you forget your wallet and you need to validate or if you're like me and forget your pin every so often, haha...
Posted
Or was it simply the legal liability thing. If they revert to chip and pin it’s their security. If they allow apple/android pay they are relying on a third party
  • Thanks 1
Posted

I prefer cash but always have access to my card, never tempted to use apple or google to pay.

Guess i am a bit of a dinosaur when it comes to flashing my phone at the till.

Posted

Seems a backward step but that's modern banking these days.

 

I tend to use google pay all the time but also carry my curve card which I have all my cards on but there are times I forget and could get caught out now.

 

I have also gone cashless as well bar the barbers - I hate carrying cash even abroad now I just use my monzo card!

Posted

A Monzo staffer commented on it:

It sounds like legacy banks are reading the rules in their own ways regarding this. I think Monzo people should be fine at least but hopefully they will confirm 100% but the tweet implies that.

  • Thanks 2
Posted
I’ve got a feeling this is tied to new EU regulations relating to the open banking developments. Basically the banks are required to implement more 2FA checks on payments (including through internet banking). It seems the banks have come up with several different approaches to this, with different security/usability trade-offs.
Posted
This is going to be a right pain in the backside... you are going to have to have your card on you even if you do use Apple or Android Pay

It won't be a pain if you are with a modern bank like Monzo or Starling.

 

https://monzo.com/blog/2019/08/22/strong-customer-authentication/

 

I think the FCA are looking to delay the introduction of the EUs SCA PSD2 requirements due to Brexit.

 

https://www.businessinsider.com/uk-delays-strong-customer-authentication-requirements-2019-8?r=US&IR=T

Posted
It won't be a pain if you are with a modern bank like Monzo or Starling.

 

https://monzo.com/blog/2019/08/22/strong-customer-authentication/

 

I think the FCA are looking to delay the introduction of the EUs SCA PSD2 requirements due to Brexit.

 

https://www.businessinsider.com/uk-delays-strong-customer-authentication-requirements-2019-8?r=US&IR=T

 

I have other cards. It looks like I shall be using a different one with Apple Pay. And having a go at this card provider (not my bank)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...