A few weeks ago, Network World ran a couple of articles about using smartphones as devices to transact credit and debit payments. One article said this would be “possibly dangerous.” I completely disagree with that assumption. In fact, I say using your smartphone as your credit card is much more secure than using your regular old plastic credit card. Read on to learn why this is true.
A few weeks ago, Network World ran a couple of articles about using smartphones as devices to transact credit and debit payments. (See Smartphones as credit cards: Possibly dangerous, definitely inevitable and AT&T, Verizon Want to Replace Your Credit Cards). I think these articles may have left the impression with readers that (1) using a smartphone as a payment device is inherently insecure, and (2) the credit card companies such as American Express, VISA and MasterCard will lose relevance if people no longer use their plastic credit cards as payment devices. Nothing could be further from the truth.
7 keys to the ultimate smartphone
My business has taken me into the mobile payments space, and I feel compelled to respond to these two articles to set the record straight. To help me with the facts, I consulted with Dom Morea, senior vice president and division manager of Mobile Commerce Solutions, and Bengt Horsma, vice president of Mobile Communications, both with First Data Corporation. First Data is a leading provider of payments processing and serves as a Trusted Service Management (TSM) company in the mobile payments market.
Let’s start with the premise that using a smartphone as a “credit card” could be dangerous. The truth is, using a smartphone as a payment device — the payment could actually be credit, debit or a gift card — is much more secure than using a regular plastic credit card with a magnetic stripe (magstripe) on the back, according to Morea. The technology enabled by the smartphone is far more advanced than the technology that reads the account data on a magstripe payment card.
Magstripe payment cards have been around for about 30 years, and they have served us well, but the technology behind them is showing its age. That black stripe on your card holds very sensitive information: your primary account number, your name, the card’s expiration date and some other discretionary information. The data embedded on the magnetic stripe is static — it never changes. What’s more, it’s not too difficult for a thief with a skimming device to read the data on your card and replicate it on another plastic card. Voila! A counterfeit and quite usable card with your account information is born. The thief can use this card over and over until you discover the unauthorized purchases. (The payments industry actually uses very sophisticated measures to mitigate losses from this kind of fraud, but those measures take place in the back-end processing of the transaction, not in the magnetic stripe.)
Smartphones, on the other hand, have morphed in recent years to become very sophisticated computer-like devices with powerful operating systems. For a smartphone to function as a payment device, it must have specialized hardware and software. The software is a mobile wallet application with additional security layers or features that are protected by a user ID and password. Someone who steals your phone could not even open the wallet application without your credentials.
The specialized hardware is a separate tamperproof microprocessor chip that securely carries your encrypted account information. According to Bengt, this payment account data is not stored in the traditional phone chip (SIM) or in the phone memory. Rather, it is stored in a separate microprocessor chip which communicates using Near Field Communication (NFC) or radio frequency (RF) protocols — not RFID — and the chip’s architecture is based on strict payment specification standards developed by the payment industry. (RFID is based upon radio frequency standards for transmitting ID data for supply and inventory purposes. These implementations are based on memory chips, which are not secure and not applicable for payments.) Therefore the payment industry is using a microprocessor chip, which actually encrypts, creates and/or processes data within its own operating system, as well as stores files and applications, which makes them very secure because one can only “open” or communicate with the chip using a specific “key” (software).
The specialized payments chip has a huge security advantage over a magnetic stripe on a plastic card: the data on the chip can be dynamic. That is, the account data can change for every single transaction you make. Therefore, if your device or account is somehow compromised — though this is quite unlikely — a thief could only use it one time before the data changes and it cannot be used a second time.
Bengt, who helped develop the PayPass contactless application deployed by MasterCard, says the keys to securing account data and for using the mobile wallet as the tool for the consumer to manage which account data to use, are the security features on both the hardware (chip) and software (wallet), which will interact in order to execute a payment transaction. The chip has a secure element (file storage), which holds the account data and can only be opened by using specific processes and a “unique key” based upon payment industry standards and specifications.
The smartphone-as-mobile-payment system can have many layers of safeguards. For instance, the user could assign a password to his phone, and the password must be entered correctly to unlock the phone and its applications. Or, the phone could use a biometric reader that looks for the user’s fingerprint to unlock the phone. In addition, the mobile wallet application has the option to be protected by a user ID and password, and the payment transaction also has the option to be protected by a chip and PIN. The account data stored on the phone is encrypted, and the transaction data is one-time use. In short, this is far more secure than presenting a plastic card with a magnetic stripe that contains easily-read static data.
Now let’s tackle the notion that American credit card companies “will be scrambling for relevance” once the mobile wallet becomes commonplace. Um, no. Just the opposite, in fact. Using a phone to initiate a mobile payment doesn’t eliminate the need for the card companies, which own and operate extensive payment networks. The phone is simply a device — a different form factor, if you will — that is comparable to a chip-enabled plastic card or a contactless fob. AT&T, Verizon and T-Mobile will not be processing your mobile payments; VISA, MasterCard, Discover, and American Express will — just as they do today.
Rather than become irrelevant, these companies stand to increase their business as more and more phone users discover the convenience of tapping their phone to make a payment. Moreover, by utilizing the TSM services from providers such as First Data, the card companies would be able to securely provision or transmit card or account data to the phone in real-time, on-the-go; for example, in the case where the consumer is being upgraded from Gold to Platinum status or to a rewards program. The consumer will not have to wait for a new plastic and the bank would not need to produce or ship it out.
Should you use your smartphone to make mobile payments? Absolutely! Your transactions will be much more secure than if you use a magstripe card, and it will probably be more convenient as well.
By the way, the U.S. market is years behind other countries in using smartphones as payment devices. This technology has been a common reality for millions of people in Europe and Japan for years. It’s good news to see that mobile wallets are beginning to get a foothold in the United States as well.




