Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The way google/apple/samsung pay work is that there is a secure element that is running its own OS that contains applications. For contactless payment (the consumer side), there are apps that implement the EMV NFC standards and also interface with the tokenization services that are run by the card issuers.

In this case, it's a different sort of application that provides the merchant side of the EMV transaction, provisioned as part of the PCI SPoC standard (https://www.pcisecuritystandards.org/assessors_and_solutions...).

SPoC relaxes some of the physical security requirements while enhancing online monitoring (of the application and security of keys etc) and approval of an end-to-end implementation.

So the SPoC standard will allow merchant side payment processing without needing specific PA-DSS compliant readers etc, because the end-to-end between the secure PIN reader (SCR-P standard) and the SPoC monitoring replaces that.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: