Hacker News new | past | comments | ask | show | jobs | submit login

It notes that it’s supported iPhone XS or later - what feature was added to the XS that is not in the X? When Apple names the “pro” model like this does it mean that the XR from the same generation is not supported?



8 Global/7 JP and later has FeliCa secure element; checkm8 exploit works up to X. It’s a fine thinking to not accept secure transaction originating a potentially jailbroken device; perhaps that’s why?


I was wondering about that too. I wonder how much SecureROM extraction pays nowadays? It used to be $200k circa 2015: https://ramtin-amin.fr/#nvmedma

(Interim while the above URL currently doesn't work: https://web.archive.org/web/20200217151824/http://ramtin-ami...)


There are publicly available SecureROM dumps online, see http://securerom.fun

The author(s) maintain the site out of personal interest.


Oooh, TIL. That's really cool.

It's very amusing that as you get to the bottom the "Vulnerable to" starts to disappear :) and yet you can download the bootrom anyway~ hmmmmm :D


I too would be extremely interested to know this. The sibling comment referring to NFC looks interesting, but I can't help but think there's an extra dimension or two.

I thought most bank cards used RFID per se as opposed to full NFC.

Plus (and much more significantly) there's the fact that the phone is doing the magic voodoo sekret handshake thing that has been the stomping ground of credit card terminals for only the past two decades or so.

My understanding was that Apple Pay stuck Apple in the middle as an intermediary to the payment, which was internally settled via backend servers. I *think*. I don't think the phones behave as credit cards in the strictest sense - my (pulled out of thin air) guesstimate is that it emulates a credit card to the extent that it make the payment terminal happy, but in such a way that the actual payment settlement is done out of band. Or... something.

Hmmmm, maybe something similar is going on here, where the phone talks the protocol but not strictly exactly the way a payment terminal would, such that Apple ultimately intermediates the final settlement of the transaction.

I feel super dumb here, mostly because this whole world is (sigh very understandably) clandestine. I would be very interested to learn about any high-level "oh okay!" type info on the subject that might be out there!





Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: