Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I tried Samsung Pay & Android Pay exclusively for a few days and gave up very soon. I even used Google Wallet (NFC) when it first came out.

There were a couple of times when Samsung Pay blocked all payments until an update was applied and the change log had nothing to do with payment functionality but with other useless & unrelated stuff like "better notifications" "better deals". NOTHING, absolutely NOTHING about a security issue, a flaw or a hole that was being used to steal money.

I havent had too many issues with Android Pay but still its the same issue ... instead of a simple swipe and go, and my ability to use my money in anyway I want and I am not at the mercy of an app developer who is acting as a gatekeeper to access my money so he/she/it can control what I need on my phone / my device to use my money whenever I want so they can push their agenda that has nothing to do with me using my money. no thanks.

thats not even including the additional cut the app provider takes and increases my price effectively. I'd rather pay one middleman.

Credit Cards dont need to be "fixed" or "solved". As a customer, its easy to use, widely accepted and my risks are covered 100% by the issuer. I cant say the same for phone payment methods.



I don't consider my risks to be 100% covered. I don't have to pay for fraudulent charges, but I still incur substantial costs in terms of time and hassle when a card is compromised and I have to get a new one. Time on the phone with the bank outlining which charges are legitimate. Time getting them to send me a new card (more complicated if I'm traveling). Time updating all of the automated payments or other accounts where the card number is stored. Hassle when my card is declined in the grocery store because the number was compromised and I didn't know yet. Hassle getting a late fee refunded (or service reinstated) because I forgot to update the card on one account and the automated montly charge failed. Hassle when the card is declined because the bank THINKS it's been compromised (theoretically less likely in a more secure system). And so on.

I've had cards compromised probably a dozen times (most in the forms of "mass compromise," where the bank shuts down my account and sends me a new card even though there were no fraudulent charges on my specific account). I'm glad I didn't have to pay any cash, but it has cost me a lot nonetheless.


I can't understand why virtual card numbers haven't been embraced across the industry. While it wouldn't solve every problem you mentioned it would make the need to update cards with services non-existent. I think it's safe to assume that a virtual card number per service would also allow them to more quickly assess where the breach occurred.


Bank of America still offered this last time I checked, but the stupid thing required Flash so I never bothered with it.


Only for BofA credit cards. For some reason they won't let you use it for their debit cards.


Not to mention requiring Bank of America. No thank you.


Agree. If Google and Apple can do per-app passwords for apps or websites that don't work with 2-factor authentication it seems like Visa should be able to kick out a per-merchant number for Comcast, Netflix, etc.

If the underlying credit card number is compromised, just change that and leave the virtual in place.


This used to work with Paypal virtual debit cards. At some point in the last 5 years they decided to cancel the program.


Just a quick chime in here - our system does in fact do that, and though I can't speak with authority about others, my understanding is that they do the same.


The biggest problem with virtual card numbers at the moment is when you show up at the hotel and cannot provide the card you reserved the room with. Notwithstanding that, they are quite successful in some parts of the world.


I have ~30 cards and a few get compromised every year. I've honestly never found it to be a big hassle.

My daily card has been compromised a few times—Chase just overnighted me a replacement and that was it.


> Credit Cards dont need to be "fixed" or "solved". As a customer, its easy to use, widely accepted and my risks are covered 100% by the issuer. I cant say the same for phone payment methods.

As a customer, you are paying more for products because credit cards are broken: retailers are passing on fraud-related expenses to you. You are paying for the inefficiencies in the system, even if the costs seem hidden.


I would use Android Pay if Google didn't restrict it to licensed unrooted stock versions of Android. Cyanogenmod supports Marshmallow on my phone where stock is still on KitKat, but I can't use Android Pay with it.


Can't these checks be subverted/modified?


I don't think they've ever been bypassed on custom roms that aren't based on an official rom. Basically it checks all the files in /system to ensure they match with one that's undergone certification. If you have a good rom but just rooted it, there are some tricks although I haven't tested them, but nothing has been done for cyanogenmod or anything else not based on a certified one.

http://www.howtogeek.com/241012/safetynet-explained-why-andr... has an explainer, and a link to more technical information.


Someone has to pay for the fraud and that's obviously getting to be the consumer in the end (indirectly through transaction cost).


Yes - but since the merchant is the one liable you can assume those costs are being passed down to you either way (key part being the contractual obligation visa/mastercard assert that prohibits the merchant from charging you more for using a credit card). Therefore in the meanwhile you can be covered for fraud and a) get your 1-2% back b) get airline miles - or c) none of the above. Seems like an obvious choice?


Fun fact: The contractual obligation says they can't charge you more for using a credit card. But it doesn't say they can't charge you less for using cash. This is how gas stations get around it. The gas is the higher price, but you get a 10 cent discount for using cash.


Merchants actually can charge more for credit card usage now. It's been permissible since a 2013 lawsuit, except in 9 states where it's prohibited by state law.


Gas stations have a special loophole for that


The point is that for the whole system it's beneficial to move to a more secure system with less fraud. For the individual user of course less so.


Visa and MasterCard have permitted surcharging for credit card use since 2013, as the result of a class action lawsuit.


I don't understand about the contractual requirement for no price differences. Gas stations do it everywhere ... a different price for cash vs cards.


It is an insane marketing speak thing. The contractual requirement isn't for no price differences. There may be a discount for using cash, but they can't word it as being charged more for using a card. The two might be equivalent in numerical terms, but it is the language that is important.


Ah, Apologies there were some changes to this recently (2013) which had slipped my mind (they mostly don't affect New England due to state-based restrictions - which is probably why I'd forgotten):

https://usa.visa.com/dam/VCOM/download/merchants/surcharge-c...


Samsung Pay has worked great for me at a number of locations. The only issue is one of my cards which I think should work wont register and when I try to pay I always get a fingerprint mismatch initially which takes up some time to do a second try




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: