As others said, chances are the phone will still show you a payment takes place, allowing you to reject it, presumably while showing the amount to be paid and the payee.
I would also guess that:
- the first payment to a new payee to have a bit more UI.
- the phone’s setting to contain settings such as max amount to be paid per week or month, and max amount to be paid in one transaction.
- those tags to have some cryptographic signature with Apple vetting those wanting to get a key. A service like this can be highly successful if only a limited number of companies (¿a few hundred?) can produce such tags.
- Apple acting as an intermediary between iOS user and payee to protect their user’s privacy.
It also is possible that Apple will withhold payment for a few days or even weeks, to give time to detect and correct fraudulent transactions, and give its customers time to challenge payments.
If such challenges are handled by always repaying the iOS user, this won’t be more dangerous than allowing selected companies to withdraw money from your bank account whenever they see fit, something that millions of people in the world do because it is so convenient.
For example, if Londoners enable auto top up for their Oyster card (https://oyster.tfl.gov.uk/oyster/link/sso/0002.do), transport for London could transfer £1000 from their bank account the next day, even if they destroy that card seconds after signing up.
I would even expect that they can do that from any bank account even if it’s owner hasn’t applied for auto top up, or even has an Oyster card. This system is built on trust.
if Londoners enable auto top up for their Oyster card, transport for London could transfer £1000 from their bank account the next day, even if they destroy that card seconds after signing up
This statement is sensationalist and not true, as the maximum load on a Oyster Card is £90.
Yes, that £1000 is a bit sensationalist, but the limit on an Oyster card doesn’t matter. Apart from a trust chain, there is no link between Oyster cards and bank accounts. If they were fraudulent, they could withdraw money from your bank account without topping up any card.
London transport must send thousands of payment requests to banks each day. Banks will honor them without checking anything, as there’s no way (apart from contacting the customer) for them to verify that London transport has the right to request those transfers of money to them (“here’s the form this customer signed last year” doesn’t say anything about whether the customer withdrew permission later)
The contract between the bank and London Transport likely says something about the amount of money they can request to be transferred to them each week, month or year, _may_ limit the amount per item, and says the contract will end if London Transport misuses the trust the banks give them, but that will be about it.
Huh? Apple pay requires double-tapping the power button and then authenticating with Face ID before the payment gets processed. Where did you get the idea that you can get charged automatically by "some anonymous dude"?
I think there point is that you might not be able to verify the identity of the person you're paying. Like you might intend to pay someone but the nfc sticker has been overridden.
Comments
What is written: > Imagine tapping your phone on a scooter or a parking-meter and paying for it without signing up or downloading an app first.
What I read:
Basically, the entire planet is now 'fair game' as a skimmer.
As others said, chances are the phone will still show you a payment takes place, allowing you to reject it, presumably while showing the amount to be paid and the payee.
I would also guess that:
- the first payment to a new payee to have a bit more UI.
- the phone’s setting to contain settings such as max amount to be paid per week or month, and max amount to be paid in one transaction.
- those tags to have some cryptographic signature with Apple vetting those wanting to get a key. A service like this can be highly successful if only a limited number of companies (¿a few hundred?) can produce such tags.
- Apple acting as an intermediary between iOS user and payee to protect their user’s privacy.
It also is possible that Apple will withhold payment for a few days or even weeks, to give time to detect and correct fraudulent transactions, and give its customers time to challenge payments.
If such challenges are handled by always repaying the iOS user, this won’t be more dangerous than allowing selected companies to withdraw money from your bank account whenever they see fit, something that millions of people in the world do because it is so convenient.
For example, if Londoners enable auto top up for their Oyster card (https://oyster.tfl.gov.uk/oyster/link/sso/0002.do), transport for London could transfer £1000 from their bank account the next day, even if they destroy that card seconds after signing up.
I would even expect that they can do that from any bank account even if it’s owner hasn’t applied for auto top up, or even has an Oyster card. This system is built on trust.
This statement is sensationalist and not true, as the maximum load on a Oyster Card is £90.
Yes, that £1000 is a bit sensationalist, but the limit on an Oyster card doesn’t matter. Apart from a trust chain, there is no link between Oyster cards and bank accounts. If they were fraudulent, they could withdraw money from your bank account without topping up any card.
London transport must send thousands of payment requests to banks each day. Banks will honor them without checking anything, as there’s no way (apart from contacting the customer) for them to verify that London transport has the right to request those transfers of money to them (“here’s the form this customer signed last year” doesn’t say anything about whether the customer withdrew permission later)
The contract between the bank and London Transport likely says something about the amount of money they can request to be transferred to them each week, month or year, _may_ limit the amount per item, and says the contract will end if London Transport misuses the trust the banks give them, but that will be about it.
Huh? Apple pay requires double-tapping the power button and then authenticating with Face ID before the payment gets processed. Where did you get the idea that you can get charged automatically by "some anonymous dude"?
I think there point is that you might not be able to verify the identity of the person you're paying. Like you might intend to pay someone but the nfc sticker has been overridden.
They will probably be signed, like HTTPS sites are...
I imagine they will have thought of this — there's probably an authorization step like Face/Touch ID or entering your Apple ID password.
You still agree on the built in dialog, and sign with your finger/face id. You just don't need a special app for it.