Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

AP Photo/Marcio Jose Sanchez
pay it forward

Explainer: How does Apple Pay (and mobile payments) actually work?

They’re going to be big, but what do we need to know about them?

QUITE A BIG deal has been made of mobile payments over the last few years, but it’s only until recently that people have started taking it seriously.

First Apple Pay was announced then Samsung and Google followed with their own versions. But while they’ve been covered extensively, you may not be familiar with the mechanics behind it.

So how does Apple Pay /Samsung Pay actually work?

While having different names and concepts, the core of all these payment systems is the same. Accessed through a fingerprint unlock or a PIN, you store your debit or credit card details within the device itself but it never shared with any companies.

All of these systems operate on a touch and go basis. Instead of getting your wallet, you just take your phone out and tap/ put it in front of a reader and it makes the payment

The difference between the two is in how payments are made. Apple Pay requires Near Field Communication (NFC) which means retailers need compatible equipment to use it.

Samsung’s version is more expansive as it uses technology from a company it bought called LoopPay. It uses Magnetic Secure Transmission allowing users to pay for goods using nearly every magnetic stripe payment gateway out there (that’s where you would normally swipe your card). The technology is embedded in Samsung’s latest phones, the Galaxy S6, and the Edge.

Android Pay doesn’t follow the same pattern. Instead, it’s a platform for third-party developers to design their own payment systems.

Apple Event Apple Watch will also feature Apple Pay allowing you to pay via smartwatch. AP Photo / Eric Risberg AP Photo / Eric Risberg / Eric Risberg

So what’s secure about this?

There are a few things to help prevent fraud or interception. The first is your credit card details such as number, security code and identity aren’t used when paying. Instead, you’re issued a Device Account Number that is encrypted and stored in your device. It is not shared with Apple, Samsung or any other party.

The only time your debit or credit card details are seen by Apple/Samsung is when you’re entering it into your phone.

The key feature of these services is tokenisation. What it means is that for every payment you make, a once-off token is generated and used in place of your credit card details. This is something that standard groups and major card players like Visa and Mastercard have been working on for a while.

It’s much like generating a new voucher for every transaction you make. Each one is for the specific transaction you make and even if it is intercepted, the token cannot be traced back to the buyer.

When you make a payment, it happens in two phases. the first is the authorisation of the card and the second is the transaction itself. The first goes through a number of checks for fraud and checks whether the cardholder has the funds (or credit line) to make the purchase.

This determines whether the transaction is allowed to happen or not and is done in the space of a few seconds.

But didn’t I hear about Apple Pay being used by scammers already?

You did, except it wasn’t by breaking the encryption. Instead, the credit cards used in this were already stolen and entered in by the thieves themselves.

That said, there are still some problems.  Secure doesn’t mean that unbreachable – anything can be hacked once you have the skills and put in enough time and effort to break it – and this is still new territory for these companies.

The other bigger problem, highlighted by the above example, is while the core of it is secure, the methods of verification aren’t.

There’s no real way to ensure the person entering the card data owns it, and that’s something that falls mainly on the banks and their verification system (although Apple and the card-makers should also push for it too). A service is only as strong as its weakest link and it’s a significant problem to solve.

Samsung Galaxy S6 phones unveiled Both the Galaxy S6 (Pictured) and the S6 Edge will support Samsung Pay. Laura Lean / PA Wire Laura Lean / PA Wire / PA Wire

What’s holding it back?

As well as the concerns mentioned above, their availability. Both Apple and Samsung’s payment systems are only available on two of their own devices (Samsung’s won’t be released until next month) meaning adoption rates are going to be slow. Also, such a system requires negotiation with the different banks in each country which is a slow process at the best of times.

The biggest barrier is the culture itself. While there was a lot of fuss and praise for Apple Pay when it first came out,  security will always be a issue for people until it becomes more widely adopted.

It’s still very early days for these type of payment systems so writing them off would be premature.

So when will any of these payment services arrive over here?

It’s unclear right now although there has been talk of it arriving in the UK in the summer time. Other card companies have introduced tokenisation in Europe recently so the path is clear for this to happen, but there are a number of loose ends to tie up first before we see it arrive here.

If we’re going to be optimistic, then the end of the year would be a good guess, but don’t hold your breath.

Read: This is why you’ll soon use your phone to pay for everything >

Read: “There’s going to be an incident so massive, it’ll make everyone rethink their security online” >

Your Voice
Readers Comments
29
    Submit a report
    Please help us understand how this comment violates our community guidelines.
    Thank you for the feedback
    Your feedback has been sent to our team for review.