/1 How do Apple Pay and Google Pay handle sensitive card info?
The diagram below shows the differences. Both approaches are very secure, but the implementations are different. To understand the difference, we break down the process into two flows.
514
9,625
615
39,748
/3 1๏ธโฃ The registration flow is represented by steps 1~3 for both cases.
๐๐ฉ๐ฉ๐ฅ๐ ๐๐๐ฒ: It doesnโt store any card info. It passes the card info to the bank. Bank returns a token called DAN (device account number). iPhone then stores DAN into a special hardware chip.
6
66
5
635
/5 2๏ธโฃ When you click the โPayโ button on your phone, the basic payment flow starts. Here are the differences:
๐๐ฉ๐ฉ๐ฅ๐ ๐๐๐ฒ: For iPhone, the e-commerce server passes the DAN to the bank.
Sep 21, 2022 ยท 3:53 PM UTC
4
29
376
/6 ๐๐จ๐จ๐ ๐ฅ๐ ๐๐๐ฒ: The e-commerce server passes the payment token to the Google server. Google server looks up the card info and passes it to the bank.
In the diagram, the red arrow means the credit card info is available on the public network, although it is encrypted.
7
46
5
420
/7 ๐ Over to you: Apple needs to discuss the DAN details with banks. It takes time and effort, but the benefit is that the credit card info is on the public network only once. If you are an architect and have to choose between security and cost, which solution do you prefer?
40
53
6
771
/8 I hope you've found this thread helpful.
Follow me @alexxubyte for more.
Like/Retweet the first tweet below if you can:
/1 How do Apple Pay and Google Pay handle sensitive card info?
The diagram below shows the differences. Both approaches are very secure, but the implementations are different. To understand the difference, we break down the process into two flows.
Show this thread
50
75
516