Tuesday, March 10, 2015

Apple Pay: a new frontier for scammers


Criminals in the US are using the new Apple Pay mobile payment system to buy high-value goods – often from Apple Stores – with stolen identities and credit card details.
Banks have been caught by surprise by the level of fraud, and the Guardian understands that some are scrambling to ensure that better verification and checking systems are put in place to prevent the problem running out of control, with around two million Americans already using the system.
The crooks have not broken the secure encryption around Apple Pay’s fingerprint-activated wireless payment mechanism. Instead, they are setting up new iPhones with stolen personal information, and then calling banks to “provision” the victim’s card on the phone to use it to buy goods.
Criminals with the stolen IDs are understood to have targeted Apple Stores in particular because they both accept Apple Pay and offer high-value items, which can then be sold on for cash.
A credit or debit card can only be added to Apple Pay when its issuing bank beams over an encrypted version of the card details to store on the phone – which it should only do when certain the real owner is using it.
However, fraud using stolen IDs is understood to be far higher than expected, with total losses already running into millions, according to industry sources. That compares with an expected value of about $5bn for smartphone-based retail payments in the US this year.
Apple’s support pages for the service says: “When you add a credit or debit card to Apple Pay… Apple sends the encrypted data, along with other information about your iTunes account activity and device (such as the name of your device, its current location, or if you have a long history of transactions within iTunes) to your bank. Using this information, your bank will determine whether to approve adding your card to Apple Pay.”
US banks are using a “green path” for cards they approve straight away on such data, and a “yellow path” for cards requiring more checks. But some banks have made the task too simple by asking callers to verify their identity with the last four digits of their social security number (SSN).
A worker demonstrates Apple Pay inside a mobile kiosk.
Though meant to be secret, SSNs are commonly stolen in identity theft, and on average 11.5 million Americans are victims of identity fraud annually, according to US data, with the average incident costing $4,930. In 2013 total losses from ID fraud in the US totalled $24.7bn. Nearly two-thirds of cases involve credit card details.
“At this point, every issuer [bank] in Apple Pay has seen significant ongoing provisioning fraud via customer account takeover,” said Cherian Abraham, a mobile-payments specialist who is a consultant to US finance groups, on his blog.
He said organised gangs are behind the scams: “In some cases, fraudsters are calling the [bank’s] call centre themselves to ‘alert them to a trip out of town’ so that fraud rules looking for transaction anomalies (such as a customer living in California and transacting in Miami) do not trip up [as] fraudulent transactions.”
Apple Pay, introduced in October 2014 and only available on the iPhone 6 and 6 Plus phones released last year, lets users pay by holding their phone near an NFC-equipped payment terminal and then confirm their identity with the iPhone’s built-in fingerprint reader.
On Wednesday, JP Morgan Chase said on an investor call that more than one million customers had added debit and credit cards to Apple’s service, while Bank of America has previously said 800,000 people had added 1.1m cards by the end of 2014 – almost certainly making it the predominant mobile payment method in the US, displacing Google Wallet, which launched in 2011. Despite being available first, Wallet has had very low transaction volumes due to the lack of NFC terminals and a more complex interface, retail experts say. Google has not provided any data on how many users it has for Google Wallet.
A spokesman for Apple reiterated that the secure mechanism for paying with card details stored on the phone had not been breached.
“Apple Pay is designed to be extremely secure and protect a user’s personal information,” the spokesman said. “During setup Apple Pay requires banks to verify each and every card and the bank then determines and approves whether a card can be added to Apple Pay. Banks are always reviewing and improving their approval process, which varies by bank.”
None of the US banks that offer Apple Pay contacted by the Guardian would discuss levels of fraud.
But it is understood that US banks are seeking more robust methods to verify peoples’ identities before adding cards to the service. Abraham warns: “Fraud scales – call centres don’t. There has to be an automated process that is invisible but secure. In hindsight the only thing Apple could have done better was to anticipate the problem, made it mandatory [to call] and helped build a better ‘yellow path’.”
Tim Sloane, vice president of payments innovation at the Massachusetts-based financial consultancy Mercator Group, said: “These are probably just some teething problems. If the banks can nail down the authentication, they should see less fraud on Apple Pay,” and added: “Battle plans always look great until you meet the enemy.”
Dave Birch, a UK-based mobile payments expert, told the Guardian: “in the UK there probably won’t be a ‘yellow path’” – meaning that people won’t have to call their bank to add any card to Apple Pay once it is introduced here because the banks have alternative, stronger authentication techniques.
The US lags behind much of the world in its adoption of secure retail payment systems and mobile payments. “Chip and Pin” systems, used throughout Europe for years, will only become compulsory in the US later this year. As retailers replace old magnetic stripe systems, which were vulnerable to widespread fraud, with new ones, they are also adding NFC capabilities, already used in the UK for Oyster cards and in many shops.
Abraham says: “Fraud in Apple Pay… came as a surprise to all”, adding that too much trust had been put in the on-device security: “The soft underbelly proved to be [the] provisioning of cards”.
    This article was updated 6 March 2015 to more accurately reflect Dave Birch’s views of how UK banks will implement Apple Pay.

Thursday, February 5, 2015

Apple to Xiaomi: being number one is easy to say, more difficult to do

After becoming the third largest smartphone manufacturer in the world, China’s Xiaomi is bullish about taking the top spot from Apple in five to 10 years.
Top Apple and Xiaomi executives traded blows under the veil of light-hearted barbs at China’s World Internet Conference in Wuzhen, where Xiaomi’s chief executive and founder Lei Jun described the company as a “small miracle” and said that it was setting its sights on world smartphone domination.
Xiaomi's Lei Jun holding a smartphone
“I believe that no one thought the Xiaomi from three years ago, which just made its first phone, would later rank as the third largest player,” Lei said speaking for three minutes after arriving two hours late for a panel that was scheduled for two hours. “India is becoming our largest overseas market. Within five or 10 years, we have the opportunity to become the number one smartphone company in the world.”
‘A small miracle like Xiaomi’
Xiaomi was founded in 2010 and made its first smartphone in 2011 in China. It quickly became the number one smartphone manufacturer in China, rising to have 70 million users and becoming the world’s third largest smartphone manufacturer in the third quarter of this year.
Lei said that the company is forecast to almost triple its user base in the next year to 200 million users and targets the number-one spot globally currently held by Samsung powered by Xiaomi’s expansion into new markets.
“It is easy to say, it is more difficult to do,” Bruce Sewell, Apple’s general counsel and senior vice president of legal and government affairs, told the conference when asked about Lei’s bold claims which would require Xiaomi to displace Apple in second place, adding that there were “many good competitive phones in China”.
“In this magic land, we produced not only a company like Alibaba, but a small miracle like Xiaomi,” Lei said.

Xiaomi may be number one in China, where Apple languishes in sixth place, but on a global scale with 6% of the smartphone shipments in the third quarter, it is far behind Samsung’s 25% and Apple’s 12%.
Xiaomi’s smartphones use Google’s Android software with designs which some say mimic Apple’s iPhone. They compete with both Apple and Samsung smartphones with similar functionality, but at prices significantly lower than the cost of an iPhone 6 or Galaxy S5.
Moving from outside of China and select developing markets in south-east Asia and India may also be difficult for Xiaomi, potentially facing legal challenges from Apple. Jony Ive, Apple’s chief designer, recently hit out at designs that could be seen as copying Apple.
“I’ll stand a little bit harsh, I don’t see it as flattery,” said Ive when asked about Chinese smartphone manufacturer Xiaomi, described as “the Apple of China” in an interview with Vanity Fair. “When you’re doing something for the first time, you don’t know it’s gonna work. You spend seven or eight years working on something, and then it’s copied. I think it is really straightforward. It is theft and it is lazy. I don’t think it is OK at all.”
Xiaomi has made efforts to be more appealing to the west, hiring key executives from Google, including the outspoken Brazilian vice president of Android Hugo Barra, who became Xiaomi’s head of international sales and spoke out about copycat claims.
“Our designers, our engineers, are inspired by great products and by great design out there. And frankly who in today’s world isn’t?” Barra said at the WSJD Live conference in Laguna Beach, California.

Saturday, January 10, 2015

Job ad error confirms European launch of Apple Pay

Apple CEO Tim Cook introduces Apple Pay.
Apple has inadvertently confirmed that its mobile wallet and online payment system, Apple Pay, is coming to Europe by posting a job advertisement on its website.
The advert, which has now been taken down, said that the company was seeking a London-based intern to “drive out the roll-out” of Apple Pay across Europe, the Middle East, India and Africa.
“Apple Pay is a new and exciting area in Apple that is set to expand across Europe, Middle East, India and Africa,” read the advert. “Apple Pay will change the way consumers pay with breakthrough contactless payment technology and unique security features built right into their iPhone 6 or Apple Watch to pay in an easy, secure, and private way.”
Apple Pay comprises two related services that both require close links between Apple and existing banks. The first is an in-app payment tool, which developers can implement to allow customers to make purchases without entering credit card details. In apps such as Uber, users will instead be able to pay by simply tapping the touch ID sensor of an iPhone 6, iPad Air 2 or iPad mini 3.
Contactless technology
The second service allows users to buy items in stores using their NFC-enabled iPhone 6, or their Apple Watch - which is yet to go on sale.
In the US, Apple Pay has taken considerable preparation because of the need to ensure retailers have compatible hardware. However, existing technology in many European shops should make the task easier on this side of the Atlantic.
The technology works with the same terminals as contactless payments, so retailers that already accept those cards should be able to use Apple Pay with the flick of a switch.
On top of the promise of increased ease of use, Apple is touting the security benefits of its service. Unlike paying with a card online, or a swipe-card in stores (still common in the US) that reveals all the information on the card to the merchant, Apple Pay sends a one-use token.
That means in the case of a hack such as the widespread data theft from US retailers Target and Home Depot earlier this year, the stolen information cannot be used to authorise further transactions.
Further, the company promises that users are doubly secured if they lose their device. Not only does the system need a fingerprint to initiate a transaction, it can also be remotely disabled.