LC://_LucaCarbone
    Back to blog
    Shopping
    May 10, 20265 min read

    Why paying with your phone is more secure than paying with a card

    Your card number never leaves the phone. In its place travels a disposable token. Securer than plastic.

    Why paying with your phone is more secure than paying with a card

    A friend told me last week: "I don't pay with my phone. I don't trust it." I asked him if he trusted the card he keeps in his wallet instead. "Of course, that's safe." I smiled. Because the truth is exactly the opposite. Let me explain something that banks know very well but that no one tells you in simple terms. When you pay with a physical card, the plastic one you tap on the shop's reader, the terminal reads your card number. That number travels through the payment network. If someone intercepts it, they have your data. With the old magnetic stripe, it was even worse: a hidden device on the reader was enough to clone everything. When you pay with your phone, something completely different happens. Your card number never leaves the phone. Never. In its place, the phone generates a disposable code called a token. This token is valid for a single transaction. It lasts a few seconds. Then it expires and becomes useless. If a malicious actor managed to intercept it, they would be holding an expired code, as good as yesterday's train ticket. Think of it like a key that changes shape every time you use it. Every payment has its own key. Once used, it no longer opens anything. Your card number stays locked inside the phone, protected by a secure area of the processor that not even the phone's own applications can read. But there's more. To pay with your phone, you must first prove it's you. Apple Pay asks for your fingerprint or facial recognition. Google Pay does the same. Samsung Pay too. This means that even if someone stole your phone, they couldn't pay without your finger or your face. Try doing the same with a plastic card. Under 80 francs, anyone who finds it can tap it on the reader and pay. No questions asked, no checks. Let me give you a concrete example. You are at the Lugano market. You buy vegetables, you pay 35 francs. With the card, the terminal reads your number and transmits it. With the phone, you place your finger on the sensor, bring the phone close to the reader, and the terminal receives a temporary code that contains none of your card information. The merchant does not see your number. The network does not transmit it. No one knows it. Another example. Your card is cloned. It happens more often than you think: a tampered reader at an ATM, a dishonest waiter at a restaurant, a compromised website. With a cloned card, the scammer makes purchases until the bank blocks everything. With a phone, there is nothing to clone. The token changes with every payment. There is no "fixed number" to copy. Three practical tips for those who want to start paying by phone. First: add your card to your phone's digital wallet. On iPhone, it's called Apple Wallet. On Android, it's called Google Wallet. Open the application, frame the card with the camera, enter the confirmation code that the bank sends you via SMS. You're done in five minutes. Most Swiss banks support these systems: PostFinance, UBS, Raiffeisen, the cantonal banks. Second: keep biometric recognition active. Fingerprint or face. It is your protection. Every payment requires your physical confirmation. No one pays in your place. Third: if you lose your phone, lock it remotely. On iPhone, just go to iCloud.com and activate lost mode. On Android, use Google's "Find My Device." Payments are deactivated immediately. With a lost physical card, however, you have to call the bank, wait on the line, and hope that no one has used it in the meantime. One last thing I'm often asked: "But what if the phone dies?" Fair point. If the battery is at zero, you can't pay. That's why it makes sense to keep a card in your wallet too, as a plan B. But for daily use, the phone protects you better. Much better. The next time someone tells you that paying with your phone is risky, tell them the story of the token. That code that changes every time, that doesn't contain your data, that expires in a few seconds. And then ask them: explain to me why your plastic card, with the number printed right there in plain sight, is supposed to be safer?

    Share this article
    WhatsApp