Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Why not? :)

We use credit cards every day with little or no security (at least, in the US).

The watch is already more secure than that, because it requires a PIN to authorize it each time we put it on. That's logically the same as requiring a PIN each time it's used. If someone steals it off our wrist, it's de-activated for payment.

--

That said..

The watch could either act as a dumb communications intermediary, or handle the NFC transaction locally.

If it just passes info back and forth from the phone, then it needs no Secure Element.

However, the watch very likely handles things locally, simply because entire tap transactions have time limits as low as 150ms, and we wouldn't want things to get screwed up waiting to talk to the mother phone. So it would have a copy of our info... or more likely, a time-limited copy.

If it does handle it all locally, then it'll need a Secure Element not so much for the info itself, which should be pretty safe from sandboxed third party apps (unless someone figures out a way to jailbreak the watch), but more so that it can run its own local copy of each of the card scheme specific payment apps.

Which brings up again the whole topic of who provisions the MC/ Visa/ Amex/ etc apps in the SEs. Normally this is done via a link of backend providers and trusted service managers like First Data. Doesn't the watch have WiFi? Maybe it can access updates on its own?

You're right that Apple Pay is more secure than a credit card, but from what I understand of it, a big part of that security comes from using the secure element on your phone. So if the watch doesn't have a secure element, and can be used for Apple Pay without being paired to a phone, then it better have its own secure element.

For non-Apple Pay transactions I use the Google Wallet card, which is also more secure than a credit card and has its own secure element, albeit in the cloud.

As long as the watch has a secure element I will have no problems using it for Apple Pay.
 
You're right that Apple Pay is more secure than a credit card, but from what I understand of it, a big part of that security comes from using the secure element on your phone. So if the watch doesn't have a secure element, and can be used for Apple Pay without being paired to a phone, then it better have its own secure element.

For non-Apple Pay transactions I use the Google Wallet card, which is also more secure than a credit card and has its own secure element, albeit in the cloud.

As long as the watch has a secure element I will have no problems using it for Apple Pay.
No CC info is stored on your iPhone or aWatch. It is simply an random based token that has no meaning to anyone except your CC holder after decoding. There is nothing on you aWatch to be considered un-secure when using for Apple Pay. As soon as you remove the aWatch Apple Pay becomes inactive and can't be used until you reauthorize the aWatch by a PIN or iPhone paring.
 
that would make a lot of sense, ID'd once and good to go.

Any source?

----------



Doubt it.

Apple said you could pay with the watch, but a combination of watch & phone. Thats just not what apple does, maybe for the 5s since it doesnt have NFC but 6 users will not have to take their phones out.

I believe they mentioned it during the announcement keynote. If your phone is authenticated while your watch is on your wrist, your watch will stay authenticated until it loses contact with your skin.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.