{"id":9826,"date":"2016-08-01T11:00:45","date_gmt":"2016-08-01T11:00:45","guid":{"rendered":"https:\/\/passkit.com\/blog\/?p=9826"},"modified":"2016-08-01T11:00:45","modified_gmt":"2016-08-01T11:00:45","slug":"how-secure-is-apple-pay","status":"publish","type":"post","link":"https:\/\/passkit.com\/blog\/how-secure-is-apple-pay\/","title":{"rendered":"How Secure is Apple Pay?"},"content":{"rendered":"<h3 style=\"text-align: left\">Very.<\/h3>\n<p>&nbsp;<br \/>\nWith the release of Apple Pay in Hong Kong last week you can\u2019t blame us for being over-excited little puppies and using it at every possible opportunity! We know not everyone is as crazy about it as us with 20.5% not trying Apple Pay due to security concerns, but we\u2019re hoping we can change your minds on that.<\/p>\n<h3><a href=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083711\/Screen-Shot-2016-07-26-at-10.22.10.png\" target=\"_blank\" rel=\"noopener\"><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-9828 size-full\" src=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083711\/Screen-Shot-2016-07-26-at-10.22.10.png\" alt=\"Screen Shot 2016-07-26 at 10.22.10\" width=\"969\" height=\"428\" title=\"\"><\/a><\/h3>\n<h3><b>The Basics<\/b><\/h3>\n<ul>\n<li>Apple Pay servers <span style=\"text-decoration: underline\">never<\/span> access your card information.<\/li>\n<li>Apple Pay stores a combination of part of your encrypted, unique Device Account Number, part of your card number, and some information about your card for you to better manage you mobile wallet.<\/li>\n<li>If you lose your phone and hence Apple Wallet, it is <em>near impossible<\/em> for someone to make purchases from Apple Pay unless they can replicate your fingerprint or wrist. Why? Because iPhone\/iPad use TouchID and Apple Watch uses Wrist Detect to make an in-store purchase.<\/li>\n<li>The only exception is if you don\u2019t use TouchID and simply enter a passcode to access your Apple Wallet, giving thieves the opportunity to watch you enter your passcode.<\/li>\n<li><strong>No payment can be sent without authentication!<\/strong><\/li>\n<li>Online purchase is also unheard of as Apple Pay only stores part of your card number, not the whole thing.<\/li>\n<li>You can also <span style=\"text-decoration: underline\">remove cards<\/span> from your Apple Wallet in 3 different ways; phone your bank, put the device into \u2018Lost Mode\u2019 via \u2018Find my iPhone\u2019, or wipe the device entirely through \u2018Find My iPhone\u2019.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083856\/Screen-Shot-2016-07-26-at-16.37.51.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-9829\" src=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083856\/Screen-Shot-2016-07-26-at-16.37.51.png\" alt=\"Screen Shot 2016-07-26 at 16.37.51\" width=\"362\" height=\"741\" title=\"\"><\/a><\/p>\n<h3><b>The Details<\/b><\/h3>\n<h4><b>Setting up Apple Pay<\/b><\/h4>\n<p><a href=\"https:\/\/passkit.com\/blog\/how-to-add-your-credit-card-to-apple-pay-apple-wallet-apple-watch\/\" target=\"_blank\" rel=\"noopener\">To set up Apple Pay<\/a>, you can either:<\/p>\n<ul>\n<li>Enter the relevant information from your credit or debit card manually.<\/li>\n<li>Or you can use your camera lens to capture this (picture is not saved or sent anywhere, the lens simply detects the information and inserts it into the correct fields).<\/li>\n<\/ul>\n<p>This data is then:<\/p>\n<ul>\n<li>Encrypted and sent to Apple servers.<\/li>\n<li>Data is decrypted so Apple can identify your network provider before it is re-encrypted with a key, that only your network provider or any other provider authorised by your card issuer has access to.<\/li>\n<li>Data is sent to your bank along with some background information is also sent along with this on your previous buying\u00a0 behaviour with iTunes and the App Store, your device information, as well as your location when you added the credit or debit card if location services are enabled.<\/li>\n<li>Once your bank receives all of this information, they approve or deny the addition of your credit or debit card to Apple Pay.<\/li>\n<\/ul>\n<p>Upon approval:<\/p>\n<ul>\n<li>You receive a device-specific, encrypted, Device Account Number that even Apple cannot decrypt.<\/li>\n<li>Device Account Number is added to your device\u2019s Secure Element. (The Secure Element is a certified chip that safely stores your payment information and is entirely separate from iOS and watchOS).<\/li>\n<li>Basically, your information is never stored on Apple Pay servers and is never backed up to iCloud.<\/li>\n<\/ul>\n<p>All of this means that <strong>Apple does not actually have access to your credit or debit card details<\/strong>. Apple Pay simply stores part of your card number and part of your Device Account Number, together with a description of your card, in order to differentiate your cards from one another and help you manage your mobile wallet. Should someone gain access to your Apple Wallet, they\u00a0 cannot actually access enough information to make a purchase, online or in-store.<\/p>\n<h4><a href=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083935\/Screen-Shot-2016-07-26-at-16.38.16.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-9830\" src=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26083935\/Screen-Shot-2016-07-26-at-16.38.16.png\" alt=\"Screen Shot 2016-07-26 at 16.38.16\" width=\"363\" height=\"742\" title=\"\"><\/a><\/h4>\n<h4><b>Using Apple Pay<\/b><\/h4>\n<p>In order to use <a href=\"https:\/\/www.youtube.com\/watch?v=d727IXIcbRw\" target=\"_blank\" rel=\"noopener\">Apple Pay from your iPhone<\/a> you must enter either a passcode or use the Touch ID that you have previously set up. For <a href=\"https:\/\/www.youtube.com\/watch?v=M-WhlhSLV0c\" target=\"_blank\" rel=\"noopener\">Apple Watch payments<\/a> you must be wearing the watch so Apple Pay can authenticate you through Wrist Detect.<br \/>\nWhen making the payment, neither Apple nor you device sends all of your credit or debit card information, they don\u2019t even send your card numbers. Instead, your unique and encrypted Device Account Number is sent.<br \/>\n<a href=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26084008\/Screen-Shot-2016-07-26-at-15.30.30.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9831\" src=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26084008\/Screen-Shot-2016-07-26-at-15.30.30.png\" alt=\"Screen Shot 2016-07-26 at 15.30.30\" width=\"560\" height=\"420\" title=\"\"><\/a><\/p>\n<h4><b>What if I lose my phone?<\/b><\/h4>\n<p>No need to worry, Apple have your back.<\/p>\n<ul>\n<li>You can use a more traditional method by phoning your bank and asking them to remove the card from your Apple Wallet.<\/li>\n<li>Otherwise, as long as you have \u2018Find My iPhone\u2019 enabled, you can either put the phone into \u2018Lost Mode\u2019 which will automatically remove your credit or debit cards from your Apple Wallet,<\/li>\n<li>Or you can wipe the phone entirely to remove all data you have stored on it, including anything within your mobile wallet.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26084041\/ios9-lost-mode-track-device.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9832\" src=\"https:\/\/dxjl3qy52c1o9.cloudfront.net\/wp-content\/uploads\/2016\/07\/26084041\/ios9-lost-mode-track-device.jpg\" alt=\"ios9-lost-mode-track-device\" width=\"1560\" height=\"1044\" title=\"\"><\/a><\/p>\n<h6 style=\"text-align: center\">Source: Apple Support, 2016 (<a href=\"https:\/\/support.apple.com\/en-us\/HT201472\" target=\"_blank\" rel=\"noopener\">https:\/\/support.apple.com\/en-us\/HT201472<\/a>)<\/h6>\n<p>&nbsp;<\/p>\n<h4>Compare all of this to a traditional wallet and a plastic card<\/h4>\n<ul>\n<li>Someone could either watch you enter your PIN number before they steal your card.<\/li>\n<li>Practice your signature on the back of the card until it looks similar once they have possession of your card (because let\u2019s be honest, how often do they actually check your signature?)<\/li>\n<li>Or shop online using all the details provided on the card itself on websites that don\u2019t ask for a password.<\/li>\n<\/ul>\n<p>So now that you trust Apple Pay, <a href=\"mailto:support@passkit.com?subject=Blog%20Post%20Security%20of%20Apple%20Pay%20Enquiry\" target=\"_blank\" rel=\"noopener\">get in touch with us<\/a> if you\u2019re looking for cool experiences using it with mobile wallet and leave your comments below!<\/p>\n<h6><a href=\"https:\/\/support.apple.com\/en-gb\/HT203027\" target=\"_blank\" rel=\"noopener\">https:\/\/support.apple.com\/en-gb\/HT203027<\/a><\/h6>\n","protected":false},"excerpt":{"rendered":"<p>Very. &nbsp; With the release of Apple Pay in Hong Kong last week you can\u2019t blame us for being over-excited little puppies and using it at every possible opportunity! We know not everyone is as crazy about it as us with 20.5% not trying Apple Pay due to security concerns, but we\u2019re hoping we can [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":9832,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,12,15,31],"tags":[],"class_list":["post-9826","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-pay","category-apple-wallet","category-blog","category-mobile-wallet-2"],"_links":{"self":[{"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/posts\/9826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/comments?post=9826"}],"version-history":[{"count":0,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/posts\/9826\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/media\/9832"}],"wp:attachment":[{"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/media?parent=9826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/categories?post=9826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/passkit.com\/blog\/wp-json\/wp\/v2\/tags?post=9826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}