Do not store Visa cards on iPhone

Apr 16, 2026 Last reply: 3 months ago 5 Replies

They are suspect to man in the middle attacks as the NFC communication between the card and the reader is amazingly not encrypted.



YouTube: How Secure Is Tap To Pay - Veritasium ?

formatting link
I've just disabled "Express Travel Settings". However, eventually someone will figure out an exploit for other tap uses. Change to MasterCard (or Android....) if you must tap.



This exploit came out a few years ago and Visa has done nothing?


ChatGPT defends VISA:

Me: If mastercard can avoid a know design weakness then why don't visa implement the same restrictions?

ChatGPT: Good question—and the answer is less about “Visa being careless” and more about different design trade-offs and legacy decisions.

Me: If Mastercard can avoid a known design weakness in card security using Near Field technology then why don't Visa implement the same solutions?

GPT-mini 5: Because card security designs, certification rules, and vendor ecosystems differ across payment networks, there are several practical reasons Visa might not adopt the exact same NFC-based mitigation Mastercard uses:

Different threat assessments and priorities: Networks evaluate risks differently. Mastercard may have judged a specific NFC-based mitigation worth the cost and user impact; Visa may accept the residual risk or prefer other mitigations (e.g., tokenization, terminal controls, issuer-level monitoring).

Backwards compatibility and deployment complexity: Any change to card-side NFC behavior must remain compatible with millions of existing terminals, mobile wallets, and issuer systems. Rolling out a card-side change across issuers, form-factors (chip, mobile, wearable), and global terminals is complex and costly.

Standards and certification constraints: Payment schemes follow EMV standards and their own scheme rules. A solution Mastercard can implement unilaterally for its cards may require changes to EMV specifications, terminal certification profiles, or Visa’s scheme rules before Visa-branded cards or terminals can adopt it.

Issuer and vendor coordination: Card issuers, chip vendors, card manufacturers, and terminal providers must implement and certify changes. Mastercard may have coordinated with its ecosystem partners to deploy a solution; Visa would need similar coordination with its large, global partner base.

Alternative mitigations already in use: Visa and issuing banks commonly use other defenses (dynamic CVV/CVC, tokenization for mobile payments, issuer risk scoring, contactless transaction limits, and terminal-based restrictions) that may reduce the practical need for the exact same NFC tweak.

Business and product trade-offs: Some mitigations affect user experience (authentication prompts, slower transactions), cost, or ancillary services. Visa may prioritize different balances of security, cost, and UX.

If you want specifics about the particular NFC mitigation Mastercard deployed (technical details, how it works, compatibility impact) and whether Visa has equivalent or alternative measures, tell me which Mastercard change you mean and I’ll summarize technical differences and likely reasons Visa hasn’t matched it.

Ask me one on sport.

Adrian Caspersz snipped-for-privacy@here.invalid wrote

Doesn't need to be given that you can't reuse the token

Completely bogus, you never get that approved screen with a real apple pay transaction

There is no exploit

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required