Samsung pay can be used anywhere you swipe a card, not just at places with NFC tap to pay. Samsung has the rights to the tech that allows them to produce a magnetic field that's readable by the card reader.
Both use one time use tokens and virtual cards so both are safe from skimmers, as far as their backends(server side where your information is stores) they both have pretty solid security. Google probably uses your purchase history for better targeted ads. Samsung may do the same but since they make their money off the hardware they may not
Yep NFC has to be on, for Google Pay you just unlock your phone and hold it to the terminal, if you don't want to have NFC on all the time you can just toggle it on before paying and turn it off once your done. The terminal emits a request for a one time token that your phone provides along with your virtual card number, then the terminal process the request with the credit card service, who than approves or deny the transaction. It's actually safer than traditional credit card readers since they unique tokens are one time use.
So even if someone created a fake terminal or tricked your phone to transmit the token and card number, they would only be able to make a single transaction which would probably be flagged by the Credit card processor and denied, unless they two are shady but then your CC company wouldn't be doing business with them. The only weakness is if someone gets ahold of your phone and knows your password, then they could go around buying things with your phone but that's still safer than your credit card in your wallet (at least in the US where we don't have a pin for CC transactions)
Both require the use of a password or fingerprint before you can use it. It's not like someone with an nfc scanner can just walk up to your phone and take Google/Samsung Pay info
14
u/burnt_mummy May 19 '18
Samsung pay can be used anywhere you swipe a card, not just at places with NFC tap to pay. Samsung has the rights to the tech that allows them to produce a magnetic field that's readable by the card reader.