elsiegee40 Posted September 2, 2019 Posted September 2, 2019 (edited) This is going to be a right pain in the backside... you are going to have to have your card on you even if you do use Apple or Android Pay Message from my card provider (my bold) We're getting in touch to let you know about new payment security measures that will start to be introduced from 14 September 2019, in response to a change in the law. The new system is called Strong Customer Authentication (SCA), and will apply whenever you make a purchase from all retailers. SHOPPING IN STORE You'll notice changes when making contactless payments in shops, including when using Apple Pay, Samsung Pay and payments via wearable technology such as smart watches. You may be asked to insert your card and key in your PIN. Chip and PIN payments will continue to work as normal. As the checks are random, you won't know in advance whether validation is required, and neither will store staff. So if you plan to use contactless payment, make sure you have the relevant card with you, or an alternative method to use, so you can continue with your purchase. Edited September 2, 2019 by elsiegee40
Soulfish Posted September 2, 2019 Posted September 2, 2019 That's a huge inconvenience, especially after just getting used to using Android Pay for transactions up to £100 rather than the £30 contactless limit! 1
elsiegee40 Posted September 2, 2019 Author Posted September 2, 2019 It kind of renders Apple and Android pay as pointless. Save time. Just use your card instead!
sted Posted September 2, 2019 Posted September 2, 2019 It kind of renders Apple and Android pay as pointless. Save time. Just use your card instead! i already was my phone case has a credit card holder in it so ive just been using that lol saves google knowing my credit card number
bald_pig Posted September 2, 2019 Posted September 2, 2019 I can't see how additional fraud prevention measures are a bad thing?
tg12 Posted September 2, 2019 Posted September 2, 2019 Yep, that’s completely ignoring the point of Apple Pay (I’ve never had experience with Android Pay so can’t comment there). Apple Pay is designed to be secure, adding a check is basically saying they’re not willing to trust it. I think these random checks are supposed to happen on contactless cards though, as far as I’ve read.
FishCustard Posted September 2, 2019 Posted September 2, 2019 While I'll never say no to additional (reasonable!) fraud prevention measures, I can't deny that this is going to be very annoying.
Jawloms Posted September 2, 2019 Posted September 2, 2019 I have a Co-operative bank card which isn't contactless, but have set it up on my phone, which obviously is. I don't carry my wallet with me usually, now I'm going to have to again. I can now lose my wallet/have it stolen again therefore making it less secure. I see this as a backward step.
sparkeh Posted September 2, 2019 Posted September 2, 2019 Forgive me if I being stupid here, but aren't Apple and Android Pay via a phone already more secure as you have to supply a fingerprint to authorise the transaction? Anyone can take a chip and pin card and wave it at a machine but they couldn't steal a phone and use it to pay for things... right?
hardtailstar Posted September 2, 2019 Posted September 2, 2019 Well this is annoying. I use Android Pay all the time so I dont have to carry a wallet around!
FishCustard Posted September 2, 2019 Posted September 2, 2019 Forgive me if I being stupid here, but aren't Apple and Android Pay via a phone already more secure as you have to supply a fingerprint to authorise the transaction? Anyone can take a chip and pin card and wave it at a machine but they couldn't steal a phone and use it to pay for things... right? You are right, but it seems that the banks cannot distinguish between a phone-pay transaction and a regular contactless one, and therefore are treating them all as the low-security variant. It makes sense from an infosec point of view - the best route forward would be to find a way to separate phone-pay from contactless cards. 1
elsiegee40 Posted September 2, 2019 Author Posted September 2, 2019 You are right, but it seems that the banks cannot distinguish between a phone-pay transaction and a regular contactless one, and therefore are treating them all as the low-security variant. It makes sense from an infosec point of view - the best route forward would be to find a way to separate phone-pay from contactless cards. They must be able to tell. IIRC Apple Pay didn’t work at first where contactless did. And Android Pay also had a delay. 2
FishCustard Posted September 2, 2019 Posted September 2, 2019 Hmmm interesting. I assumed that the phone just emulated whatever the card did.
elsiegee40 Posted September 2, 2019 Author Posted September 2, 2019 And your card issuer has to authorise your card to work through Apple Pay. So your card issuer knows
Kitkatninja Posted September 2, 2019 Posted September 2, 2019 It's not every time, Lloyds already does this; we found out when we tried to pay by contactless and was refused, got home and rung the bank and they informed us of this - that it's random... Majority of the times it goes thru without any problems, the biggest thing is if you forget your wallet and you need to validate or if you're like me and forget your pin every so often, haha...
PrimaryNetMan Posted September 2, 2019 Posted September 2, 2019 Well seeing as my Android Pay creates a virtual account, and my statement states it was via Google pay banks can distinguish between a phone-pay transaction and a regular contactless one.
elsiegee40 Posted September 2, 2019 Author Posted September 2, 2019 What they’re actually saying is we have implemented these changes and not made any distinction in the software we have had coded 1
FishCustard Posted September 2, 2019 Posted September 2, 2019 Yeah, that's probably it. I wonder whether there are technical barriers to doing so (e.g. massive amount of development time needed), or if it was just a cost-saving exercise!
elsiegee40 Posted September 2, 2019 Author Posted September 2, 2019 Or was it simply the legal liability thing. If they revert to chip and pin it’s their security. If they allow apple/android pay they are relying on a third party 1
JATSO Posted September 2, 2019 Posted September 2, 2019 I prefer cash but always have access to my card, never tempted to use apple or google to pay. Guess i am a bit of a dinosaur when it comes to flashing my phone at the till.
Localtechie Posted September 2, 2019 Posted September 2, 2019 Seems a backward step but that's modern banking these days. I tend to use google pay all the time but also carry my curve card which I have all my cards on but there are times I forget and could get caught out now. I have also gone cashless as well bar the barbers - I hate carrying cash even abroad now I just use my monzo card!
ZeroHour Posted September 2, 2019 Posted September 2, 2019 A Monzo staffer commented on it: It sounds like legacy banks are reading the rules in their own ways regarding this. I think Monzo people should be fine at least but hopefully they will confirm 100% but the tweet implies that. 2
mrcrazy04 Posted September 3, 2019 Posted September 3, 2019 I’ve got a feeling this is tied to new EU regulations relating to the open banking developments. Basically the banks are required to implement more 2FA checks on payments (including through internet banking). It seems the banks have come up with several different approaches to this, with different security/usability trade-offs.
Arthur Posted September 3, 2019 Posted September 3, 2019 This is going to be a right pain in the backside... you are going to have to have your card on you even if you do use Apple or Android Pay It won't be a pain if you are with a modern bank like Monzo or Starling. https://monzo.com/blog/2019/08/22/strong-customer-authentication/ I think the FCA are looking to delay the introduction of the EUs SCA PSD2 requirements due to Brexit. https://www.businessinsider.com/uk-delays-strong-customer-authentication-requirements-2019-8?r=US&IR=T
elsiegee40 Posted September 3, 2019 Author Posted September 3, 2019 It won't be a pain if you are with a modern bank like Monzo or Starling. https://monzo.com/blog/2019/08/22/strong-customer-authentication/ I think the FCA are looking to delay the introduction of the EUs SCA PSD2 requirements due to Brexit. https://www.businessinsider.com/uk-delays-strong-customer-authentication-requirements-2019-8?r=US&IR=T I have other cards. It looks like I shall be using a different one with Apple Pay. And having a go at this card provider (not my bank)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now