Not really because the Apple Pay KYC process as well as the restrictions that can be put into place would make this attack non viable.
If I skim your card in Chicago I can bill $2000 in a “coffee place” in Manila.
The same doesn’t work with NFC tags which not only can and likely will be geofenced but there’s no details to skim and the payment goes through Apple Pay not the credit card network which anyone can access.
Which doesn’t work because you’ll have to pass Apple KYC’s process, and it doesn’t scale since the NFC payment is much more limited than your credit card limit.
Comments
When the universe of approved partners is large enough, the security considerations will be non-trivial.
Not really because the Apple Pay KYC process as well as the restrictions that can be put into place would make this attack non viable.
If I skim your card in Chicago I can bill $2000 in a “coffee place” in Manila.
The same doesn’t work with NFC tags which not only can and likely will be geofenced but there’s no details to skim and the payment goes through Apple Pay not the credit card network which anyone can access.
Apple Pay is not giving away any shared secrets over the air that are useful to steal.
I think the attack would be to place a sticker that causes unsuspecting users to pay you instead of the intended merchant.
Which doesn’t work because you’ll have to pass Apple KYC’s process, and it doesn’t scale since the NFC payment is much more limited than your credit card limit.
My best guess is that you'll have to pay and register with Apple to create NFC tags which will be attached to the payment.
Essentially as soon as somebody reports you to Apple your account will be burned.
Of course, it's up to Apple to implement and administrate it, they are generally pretty sensible about this kind of stuff.