Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

that's seems like an obvious security vulnerability. if the phone has no power then how does it authenticate the payment request?


It only works with approved transit providers and you have to explicitly enable it so the exposure is fairly limited.

https://www.apple.com/uk/apple-pay/transport/


If you think about it, it's still more secure than a physical card – that also doesn't have any authentication method at transit terminals, but unlike the "Express Transit" option on iOS, you can't turn that functionality off at all.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: