Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is how Samsung Pay works, right? edit: And LoopPay which I guess Samsung acquired.


Yes.

And Samsung is really in a panic right now since the chip & pin rollout is going to effectively nullify their investment. Initially they can just strip the "require pin" flag from the magstripe, but eventually opt-out won't be supported.

So Samsung is investing massively into Samsung Pay adverts and promotions in order to get people using it, with the hope that once this functionality breaks that people will continue using it via NFC supported terminals.

I believe they give you $50-100 just to use Samsung Pay right now for one example.


Did they ever think chip & pin wouldn't roll out? I took the magstripe emulation as a bridge play, to be the first truly viable mobile payments option in order to take pole position in the coming mobile payments scuffle.


Samsung worked directly with the banks to deploy a tokenization scheme via the magnetic card swipe system so it would be EMV equivalent. It's not sending your actual card number, but a virtual card number provided by the bank that doesn't have the 'chip required' bit.


Samsung pay uses tokenization so is considered EMV. However you cannot tell a samsung pay transaction from magstripe relay.


Couldn't they have thought of a more creative name for their payment service than "s/Apple/Samsung"?


Same Idea, It was Samsung's effort at getting ahead of Apple Pay seen as it's compatible with non-nfc terminals.


Yup, however Samsung Pay/LoopPay keep the chip bit meaning you need to bring your cards with you when they require Chip, where MagSpoof can disable the bit, allowing you to leave your cards at home.


IIRC all these payment solutions work with NFC communications. I have a couple of NFC-compatible banking cards.


Samsung Pay's pitch is that it is (mostly) backwards compatible with existing card readers. When NFC fails, it does fallback to magnetic strip emulation.


[deleted]


It's pretty much the same as what's being described in the article. Samsung calls it Magnetic Secure Transmission (MST): http://www.samsung.com/us/support/answer/ANS00043865/9974103...


> Magnetic Secure Transmission They dare to call this secure...


It is because it uses a token not the PAN


Sounds like you didn't read the post.


By generating a magnetic field.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: