{"id":3976,"date":"2014-09-10T10:00:47","date_gmt":"2014-09-10T14:00:47","guid":{"rendered":"http:\/\/me-en.kaspersky.com\/blog\/?p=3976"},"modified":"2017-09-24T18:38:00","modified_gmt":"2017-09-24T14:38:00","slug":"apple-pay","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/apple-pay\/3976\/","title":{"rendered":"Apple Pay: is it safe to pay with your iPhone?"},"content":{"rendered":"<p>On the 9th of September, Apple showed some new devices and its new payment system based on an NFC chip, Touch ID sensor and Passbook app. So we had a look to find out how it works, what it gives us and how well this system is protected.<\/p>\n<p>The 100-minute Apple event, which took place in the Flint Center in California, showed the world a couple of new devices, traditionally split the spectators into three usual groups like \u2018Apple is not as good as it used to be\u2019, \u2018We already have seen it on Android\u2019 and \u2018Shut up and take my money!\u2019 We don\u2019t want to associate ourselves with any of these as there is something much more interesting than a screen size and holy wars \u2014 Apple Pay, the new payment system which was developed by Apple with the involvement of Visa, MasterCard and AmEx, and based on an NFC chip, Touch ID sensor and an app called Passbook. Apple wants to make your iPhone do the same things your wallet and credit cards do, but is it secure enough to be sure your money won\u2019t end up in criminals\u2019 pockets?<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/09\/05111630\/New-iPhone6-1-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-5965\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2014\/09\/05111630\/New-iPhone6-1-1.png\" alt=\"New-iPhone6 (1)\" width=\"640\" height=\"480\"><\/a><\/p>\n<p>Apple Pay (yes, it seems the company is getting rid of that \u2018i\u2019 prefix now) is a mobile payment system, which combines the principal of providing transactions with some interesting technological solutions. NFC, Touch ID, Passbook \u2014 everything here works together to make your shopping more comfortable and secure. At least so the keynote told us.<\/p>\n<p>So, how does it work? Actually pretty much the same way as PayPass or PayWave cards do: all you need to do is just hold your NFC-enabled payment device near the reader for a moment and then confirm the transaction. In a case of a credit card it is a PIN code, but Apple Pay uses the new iPhones\u2019 Touch ID scanner which you need to hold your finger on while making a payment.<\/p>\n<div class=\"pullquote\">Apple Pay looks secure, but storing all your credit card information on your iPhone may be bad for your money.<\/div>\n<p>To make it work first you need to scan your credit cards with your iPhone so all the info like card number, expiration date and such stuff goes right to the Passbook application. And then comes the most interesting and complicated part of Apple Pay technology. Instead of using your actual credit or debit card numbers during the payment process, a unique Device Account Number is used. Once created, this kind of token is assigned to a device, where the card information is, and securely stored (encrypted, of course) in a dedicated chip in the new iPhones and Apple Watch. So you pay with a non-identifiable special code, not with your real credentials.<\/p>\n<p>Such approach is good for at least two reasons. First, neither a shop, nor a criminal (who can try to intercept the data) could get your credit or debit card information during a transaction. In the worst scenario an attacker could have only a token number. Second, even if the number is compromised, it\u2019s worth nothing, because it works only when transmitted from the specific device which this number was created on. If the device is stolen, then comes Touch ID protection. In any case, there\u2019s always the Find My iPhone service, which you can use to lock your iPhone or even wipe all the info from it, including card information, so you won\u2019t need to lock your credit cards or bank accounts to protect your money from being stolen.<\/p>\n<p>But is this system really secure? Dmitry Bestuzhev, an expert from Kaspersky Lab, says there\u2019s a problem: \u201cTouch ID doesn\u2019t always work properly. That\u2019s why Apple allows you to enter a PIN. For example, when your fingers are wet the Touch ID may not wok. The same shortcut scheme may be abused by cybercriminals while authorizing payments.\u201d Keeping in mind that paying with Apple Watch doesn\u2019t require any extra interaction, chances are that your devices may be used without your permission to drain your bank account.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Soon you\u2019ll be able to make payments with just your #iPhone or #Apple Watch. Will it be safe?<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FD43v&amp;text=Soon+you%26%238217%3Bll+be+able+to+make+payments+with+just+your+%23iPhone+or+%23Apple+Watch.+Will+it+be+safe%3F\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>There\u2019s one more concern: the way the card information is stored. As you know, almost every kind of data stored on an iPhone can be synchronized with a number of trusted iOS devices. And it\u2019s not just photos or browser tabs, but also passwords, which are stored within an app called Keychain. So if credit and debit card credentials are stored in a same way, enabling the device to synchronize with some other smartphones, it can be very bad for you and your money. Besides that, an attacker can do the same thing as you \u2014 enter your Passbook and get all the information about your cards, unless Apple makes it impossible or very difficult to do this. We\u2019ll know in October if it will be so or not, when Apple Pay officially goes live across more than 200,000 US stores. We will keep you updated, so stay tuned.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 9th, Apple showed some new devices and its own payment system, which utilizes an NFC chip, Touch ID sensor and Passbook app. So we had a try to find out how it works, what it gives us and how well this system is protected.<\/p>\n","protected":false},"author":214,"featured_media":3977,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[791,483,792,97,793],"class_list":{"0":"post-3976","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-apple-pay","9":"tag-mobile-payments","10":"tag-nfc","11":"tag-security-2","12":"tag-touch-id"},"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/apple-pay\/3976\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/apple-pay\/4073\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/apple-pay\/4464\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/apple-pay\/4722\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/apple-pay\/5161\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/apple-pay\/5964\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/apple-pay\/3939\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/apple-pay\/4769\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/apple-pay\/5161\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/apple-pay\/5964\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/apple-pay\/5964\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/apple-pay\/","name":"Apple Pay"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/214"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=3976"}],"version-history":[{"count":1,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3976\/revisions"}],"predecessor-version":[{"id":6702,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/3976\/revisions\/6702"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/3977"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=3976"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=3976"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=3976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}