13 ms·
Offline card payments should be possible no later than 1 July 2026
- yangchang007 1y ago[dead]
- 0xWTF 11mo agoI just signed a credit card payment at a restaurant using a Toast device and it asked if they wanted to run in offline mode. So this is already solved at scale to some degree.
- Aurornis 1y ago> The online function shall apply to physical payment cards and accompanying PIN code when purchasing essential goods such as food, medicine and fuel. Is this a typo where they meant to say “the offline function”? If I’m reading this right, the goal is to allow food, fuel, and medicine purchases with card + PIN in offline mode. Seems like a reasonable goal. I wonder what the technical details will look like. Will there be a periodically updated list of cancelled cards/accounts distributed to endpoints? Even a hashed list of all cards cancelled before their expiration date within a country is a reasonable amount of data for modern storage systems. Or would they simply rely on the ability to track down account owners by their originally registered contact info in the event that someone gets an invalid transaction through during an offline period?
- objclxt 1y ago> I wonder what the technical details will look like It’s already a thing, the EMVCo standard predates ubiquitous internet connectivity. Mass transit systems typically use it, airlines used to for in-flight purchases before the advent of reliable WiFi. https://en.m.wikipedia.org/wiki/EMV#Offline_data_authentication_(ODA) https://en.m.wikipedia.org/wiki/EMV#Offline_data_authenticat... It is somewhat common to maintain a denylist of known fraudulent cards, but as you note the main mitigation is on the bank to track the card down. One of the key things you need to figure out with an offline payment system - and what I imagine is needed here - is a consensus on who has the liability for offline transactions and what the dollar limits are.
- tialaramex 1y agoI assume it's a typo or equivalent mistake. EMV (chip cards) can have a small amount of local smarts, so it is typical for example to insist on going online for a large transaction or if the card has performed too many offline transactions since last going online. The card maker decides these rules, so the bank gets to ensure the cards it issues to customers meet whatever requirements it has decided upon, balancing fraud risk against problems with loss of connectivity or services being down. So I doubt they'd bother doing some sort of ad hoc revocation technique.
- deleted 1y ago[deleted]
- londons_explore 1y agoThe card itself knows its balance and is authorised to approve transactions up to a limit fully offline. The UK already does this in some shops for low value items for NFC payments. You can tell the offline transactions because they immediately say 'approved' rather than taking a few seconds. If it turns out the card approved something 'wrongly', for example because you had previously reported the card lost to the bank, then the bank refunds the transaction and claims the value back from the merchant. That's why many merchants have their terminals set to require online payments.
- greenavocado 1y agoIt's incredible how the banks refuse to lose here; they will screw over the merchants before taking on any liability in this matter.
- xhoantran 1y agoWhen you set up the POS you can choose whether to allow offline auth or not. It makes transactions a little faster, but you’re the one who takes the hit if the card bounces later. Just comes down to whether you value speed over the extra risk.
- ErrantX 1y agoYour card doesn't know the balance, it doesn't work like that. Offline transactions mostly died off when the limit in the UK for contactless was raised to £100. At £20/30 (the original limits) issuers/merchants risk accept some payments not being valid (and the total limit before you had to chip and pin was fairly low top). And worth saying, the merchant has some control on the terminal but mostly the decision of offline/online is down to the issuer and configured on the card.
- mijoharas 1y agoOut of interest is this both debit and credit cards, or just debit?
- yieldcrv 1y agooffline key signing and broadcasting later should be a simple thing although heavily misunderstood, this is built into cryptocurrencies since day 1 (many critics have long thought crypto requires power and internet access, many proponents also don't know otherwise) with card networks learning from competition and functionally being public-only keys, this should be even simpler to implement
- dboreham 1y agoYes, but the merchant has to have a way to check for double-spending, or otherwise verify that the signed txn they have been given represents money that can be "taken to the bank". Checking the signature on some blob that says "this be money" is not enough.
- throw219080123 1y agoTrue. But if the system is implemented by a country this could be implemented using the law system and insurances. For example, when each transaction is done, both parties might keep a cryptographic proof which they are required to submit once they are online again. Failing to submit could result in a small fine (to encourage submission) and double spending which can then be detected could result in a large fine (or even a prison sentence), for example. There is, perhaps, a privacy issue, just like with blockchain. But it's not more of an issue than online transactions.
- mosdl 1y agoYou don't need a blockchain for that, see how old credit cards worked without network access.
- throw219080123 1y agoI didn't say you need a blockchain. I just said a cryptographic protocol (mostly offline and unrelated to blockchain) would help to automatically and quickly detect and proof fraud. The offline credit card system does not proof fraud but just has insurance.
- Etheryte 1y agoSome context might be useful here. I spent some time living Sweden not too long ago and Swedes practically don't use cash. It's usually not said out loud, but cash is often considered to be dirty and criminal, to the point that most don't have any at all. Digital payments are very convenient and deeply integrated, so long as you have a local ID which allows you use the local payment system Swish etc. This worked nicely until the tensions in Europe lead to more cyberattacks rolling in and suddenly you have people not being able to buy food, medicine, and so forth. Not too long after, there was a government advisory urging people to keep some cash reserves in case a larger cyberattack happens, but cultural habits at large are hard to change. This is of course a coarse simplification of the context, but might help understand this incentive a bit better.
- elictronic 1y agoPhysical attacks are also possible, this site focuses on software so much of the time, while acts occur in the physical world. Cyberattacks are grey areas, but based on some of the undersea cable cutting and factory fires Russia has been performing, physical attacks are very much on the table if you can obscure the source.
- timeon 1y agoPhysical attack is localized. Cash is more decentralized. Maybe this offline card-payment will help with that but I wold not bet on it.
- 1oooqooq 1y agothat's the excuse. it's really visa lobbying to destroy the (somehow worse than visa) easy credit new players. they give credit like candy because being online and low value only it's easier to avoid (or swallow) fraud. forcing their hand to accept offline sales mean they can't decide on the spot, and now those 5k credit lines which they only allow transactions for sub 100 purchases at a time will be wide open for offline fraud they can't detect, and which visa already know how to handle/sustain. this will probably be lobbied elsewhere soon. i predict Netherlands is next.
- 1y ago
- obblekk 1y ago1yr timeline is ambitious if it means fully deployed. Clearly the right thing for Sweden and others to do. Also worrying that even 3yrs into the Russian invasion, bordering countries are urgently increasing their preparedness for future conflicts.
- londons_explore 1y agoThe standards are already designed and widely implemented in Europe and a smallish percentage of transactions are already fully offline. I suspect this could be implemented with just policy and config changes, with no need to reissue cards or deploy new readers.
- hocuspocus 1y agoRight, basically all EMV cards are ready. You just need one that has some offline tolerance, as there are limits on both the amount and number of consecutive offline transactions. I believe these settings can be updated on the chip, i.e. your bank will tell you to go to an ATM perform any operation to make sure it's up to date. Payment terminals might be trickier as we've observed during outages that they currently don't fall back to offline transactions. But their software and business rules can obviously be updated.
- jcul 1y agoI believe most of those POS systems can operate in offline mode, in Europe at least. I have friends who work for large event organizers, and they have spoken about how if the system is offline the bars can continue to take payments, but there is a risk as a person's account may not have sufficient balance to make the charge when the system comes back online. Most people here pay by card and I would say the vast majority use debit cards. A lot of people don't even have credit cards, unlike the US. I'm no expert so may be wrong about some of this, and maybe huge events like these have these systems in place due to the risk of having to shut down bars etc. Many events are completely cash less these days.
- pndy 1y ago
- spullara 1y agoIt's a check, they have invented checks.
- Imustaskforhelp 1y agoatleast with cheques tho there was a way to safeguard the payments of a cheques by crossing of cheques and when I had learnt about cheques there were a lot of things that can be done via cheques like endorsing etc. But there was always a risk of cheques being unsafe so that's why there is bank drafts. It seems that this is more similar to bank drafts than cheques. If you really try to sum it up, I know I am going to do a grave misjustice but even a cash could be thought of a cheque from the govt. (well a cheque is meant to be unconditional but its based on the banking laws of a govt. and cash is a promissory note which is a promise made by the govt. so yeah....) As another HN commenter pointed out here,this decision might be partially due to swedish culture of how they view cash which you can find here.
- lostlogin 1y agoAre there people that like cheques? They are no longer a thing in New Zealand. It seems like something no-one would miss.
- reaperducer 1y agoAre there people that like cheques? For no good reason, I keep a list of why I use checks (in the U.S.): - Charitable donations because charities maximize every penny, and electronic contributions eat into that - Paying the accountant - Good accountants make every penny count, and aren't interested in paying credit card overhead. - Tipping the paperboy at Christmas - Tipping the doorman at Christmas - Business license renewal in certain cities - IRS payments without a fee - Gas bill. Gas company charges $5+ to pay by credit or debit card. - Rent. Building charges $50+ to pay by debit card, $200+ to pay by credit card. - Electric bill. Electric company charges $5+ to pay by credit or debit card. - Passport renewal fee (Though I believe this is finally possible with a credit card, I haven't had the opportunity to see yet.) - My company requires me to send it a check for the amount I receive from the government for jury duty. - My company allows me to buy computers and other equipment it no longer needs. Checks only. (And an M2 MacBook Pro for $200 woot!) - Fee to pay for a new car title. No credit cards accepted in my jurisdiction.
- andy99 1y agoThe idea of there being some "government approved" list of things people can buy with this is horrifying and exactly why cash should continue to exist.
- Animats 1y agoPeople should still be able to buy food and essentials even during cyberattacks from Russia. That's what Sweden is preparing for.
- andy99 1y agoAnd there's a solution to that that lets them value what they want appropriately and not have to choose it from a government list. I think unfortunately the temptation is too high for governments to also try and tell people what their priorities should be, which is why having an exchange medium that doesn't involve government control is important.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- Kwpolska 1y agoI don't think it's going to be a list of things, but rather a list of vendor types (grocery stores, pharmacies, gas stations) that have to accept offline payments, and that banks must accept offline payments from. You can live without a new iPhone if the terminal is down, but you can't live without food.
- mrtksn 1y agoIt's not about paying by cash but paying by card offline. How is this going to be implemented I wonder. On planes they often accept credit cards even when there's no internet. I assume this is a trust in-credit-based system because they don't accept debit cards, i.e. if you are worth being trusted with a card you can have your sandwich now and we will take care of the bank processing once we are on the ground. So maybe this will be like we trust you enough with basic goods that once we get a connection things will be sorted out situation?
- kosinus 1y agoDebit cards are most definitely accepted on planes.
- mrtksn 1y agoEven without internet connection? Edit: OK maybe there's different level of trust and some take a leap of faith :) In my experience debit didn't work but it appears that its not the same everywhere.
- whatevaa 1y agoYeah. They just accept some loss on bounced payments. Got a free meal (well it was a sandwich, nothing fancy) like that.
- ruszki 1y agoCan’t debit account go negative where you live? It’s definitely possible. Even when you don’t have an account credit, or what it’s called. Of course, this is possible only in strange circumstances, but still, I had a debit account with negative statement once. If I remember well, it was because similarly delayed offline transactions. It probably depends on country and/or bank.
- kosinus 1y agoI have no idea how the terminals operate, but I was on a flight two days ago and paid with a debit card. The flight otherwise required devices to be in airplane mode. Though there are flights that offer wifi, so there's a good chance the terminal can communicate with the ground, but they just don't allow anything else.
- motohagiography 1y agooffline mode has been the limiting factor in almost all electronic payments. there was a convention where the single use keys became limited use keys so that cards could make offline payments in low amounts that could be reconciled later. it created a risk and a vulnerability to be managed, and there was at least one exploit against it if I remember correctly. imo, the mandate creates an interesting technical constraint on any CBDC standard, where the offline mode limits the effectiveness of a "turn off" of someone's money, as there will always be some feature where they can use their money to buy food and fuel. For now I am interpreting this mandate as constructive to civil liberties.
- desireco42 1y agoThis is how it used to be before, they would slide your card through that machine thingy, it would copy it's digits and they would process this sometime in the future.
- greenavocado 1y agoLooks like summer 2026 is when the war will start
- empressplay 1y agoAh yes, that old Russian chestnut that any moves to make Western civil society more resilient are portrayed as an omen of military aggression against them. Sorry Boris, not everything is about you.
- DonHopkins 1y agoHow many days was your glorious war in Ukraine supposed to last, Boris? Maybe wrap that one up and breed some more cannon fodder before starting another.
- kkfx 1y agoPersonally, I dream of an open-hardware, FLOSS wallet, also usable on POS like a bank smart card, confirming crypto transactions like legacy/traditional ones on its own display. Internally, the signature part isolated like a smart-card, "embedded signature" hardware as a measure against double (multiple) spending, and reasonable limits on offline transactions with both parties offline (e.g., €10k/month). The "embedded signature" hardware part is a bit vague because technologically it's not clear how to do something like that in a "secure enough" way, but it's a necessary part and the limit somewhat lowers the risk. For use: mounted as a smartwatch or a pendant with a retractable lanyard, like ski-pass holders.
- catigula 1y agoKind of concerning when you see governments hardening themselves to massive AI cyber attacks.
- fpoling 1y agoExtracting keys from a modern SIM card is very difficult. The cost is way above 10K USD. So a payment card in offline mode is absolutely possible as long as one limits the payments to few hundreds USD. The bigger challenge is an offline terminal that can easy accumulate tenths of USD in case of a long outage. But then compared with cards the terminal may have better protection.
- mrtksn 1y agoWhat makes it over 10K USD?
- AAAAaccountAAAA 1y agoIn addition to the issue of microchips being inherently difficult to tamper with, smartcards have various hardware and software based anti-tampering measures, that are designed to destroy the chip, if someone attempts to extract the keys from the chip. That kind of security measures are never totally impermeable, but defeating them requires advanced equipment and skilled labour, and the R&D costs of the cracking devices need to be offset, too.
- 0xWTF 1y agoThere's a term I saw all over someone's Google calendar schedule, pre-pandemic "DNS without asking". Now I realize it means "Do not schedule without asking" but my mind thought "Domain Name Service without asking" ... how in the hell would you do that? I guess this is similar: how do you make trustworthy decisions that seem to inherently depend on the network, in the absence of a network? Before the internet, we had phonebooks instead of DNS, and we had cash instead of cards. Did the phonebook have every number? No. Was every piece of cash not counterfeit? No. But it's "good enough". Portable reference sources and tokens. The references are issued periodically and the tokens have evidence of exhaustion, their decay over time. A dog-eared dollar with a bunch of phone numbers on it, half-torn ... the merchant doesn't have to accept it. How do you do these things digitally? Periodic issue seems pretty straightforward ... if you have a network. Token issuance, similarly, needs at least occasional communication with other nodes in the network. So there's a local dwell capability. Is this part of the same reaction we saw with Denmark starting to have emergency stores within 50 km of every Dane? Is this motivated by a need to prepare for war?
- darig 1y ago[dead]
- pizzalife 1y ago>Is this motivated by a need to prepare for war? In short, yes. >The possibility to pay by card when the internet is not working – ‘so-called offline payments’ – is an area that ‘the Riksbank believes needs to be improved considerably, particularly in light of the geopolitical unease in the world,’ according to the announcement https://www.riksbank.se/en-gb/press-and-published/notices-and-press-releases/press-releases/2025/global-environment-puts-pressure-on-payments-system-resilience/ https://www.riksbank.se/en-gb/press-and-published/notices-an...
- lxgr 1y agoWe know exactly how to do these things digitally. Many European countries have had stored-value payment schemes in the 90s. Japan still does today. It's a completely solved problem, but it's a more complex (and as such more expensive) solution than just assuming ubiquitous connectivity and a backend that never goes down, which is how we got to where we are. > Is this motivated by a need to prepare for war? Preparing for cyberattacks seems like a prudent move, no matter the adversaries' motivation. But yes, the context here is pretty obvious in Europe.
- bilsbie 1y ago[flagged]
- recursive 1y agoIt is subject material of interest to hackers.
- Sohcahtoa82 1y agoHow is your account 3 years old with over 7,000 and you're still asking a question like this? Certainly you'd know by now that what's acceptable to be posted here is pretty broad?
- bilsbie 1y agoI’m not saying it’s not acceptable. I genuinely am trying to understand what I should be getting from this. It just sounds like a report on paying for things in Sweden.
- iammrpayments 1y agoOffline payments -> Online payments -> Tech startups -> website for tech startup called hacker news
- wcoenen 1y agoPedantically speaking, offline card payments are already possible _now_. E.g. see the Square documentation about that.[1] However, it requires that all the parties involved (issuer, acquirer, payment network, merchant) allow it, and there are certain limits. One of the linked documents[2] in the riksbank press release has more details about what they expect from these parties. [1] https://squareup.com/help/us/en/article/7777-process-card-payments-with-offline-mode https://squareup.com/help/us/en/article/7777-process-card-pa... [2] https://www.riksbank.se/globalassets/media/nyheter--pressmeddelanden/pressmeddelanden/2025/251003/memo---increased-possibilities-to-make-offline-card-payments-in-sweden.pdf https://www.riksbank.se/globalassets/media/nyheter--pressmed...
- loeg 1y agoFundamentally it's all extensions of credit, right? The question is who is taking on credit risk in these transactions and how is everything settled when the power comes back. Presumably, everything is somewhat reversible and there is some dispute resolution process.
- m11a 1y agoRight. IIRC, the acquiring bank would send an authorisation advice to the issuer when it comes back online. An auth advice is like notice that a payment happened, the issuer doesn’t really get a say in rejecting it (as it does for an authorisation). For the most part, anyway. If that transaction brings the customer into a negative balance, it’d be between the bank and customer to figure that out. Especially if the customer has no overdraft facility and isn’t supposed to be able to go negative, and isn’t able to easily recover the payment, or the customer is considered vulnerable, then the bank will often just swallow the loss.
- jfengel 1y agoIs this something they've been planning? Or is this a reaction to the saber rattling over in Russia?
- upcoming-sesame 1y agoHere in southern Europe on the other hand, cash is a crucial part of the tax evasion economy
- rkomorn 1y agoSomewhat tangential (sorry), but in my part of southern Europe, cash change machines seem to be getting close to ubiquitous. I wonder if that hinders tax evasion at all since there's presumably a pretty reliable paper trail of cash transactions.
- upcoming-sesame 1y agoYou mean ATMs ? It is still harder to prove where the cash you took out of the ATM went to in comparison to card payments, but yeah, if you take a big amount of cash out of the ATM then it would be easy to flag you
- rkomorn 1y agoNo, I mean the machines that now handle cash payments at many businesses, accepting cash and returning change. They're increasingly common here in Portugal, at least.
- upcoming-sesame 1y agoah got it. these are mostly mechanical I think and are offline / dumb device as far as I know
- DavidVoid 1y agoThat is partially why the banks/government in Sweden have been happy to phase it out. Companies also don't like dealing with cash because it requires extra accounting, security, and transportation. In the early 2000s there were about 50 cash transport robberies per year in Sweden, in 2018 there was 1.
- 1y ago
- wyager 1y agoThis sounds worse than cash in almost every dimension.
- chairmansteve 1y agoBack in the day, we used these machines to take a paper imprint of the card. You would get a copy and give it to the bank. There was a phone number you could ring to check if the card was valid. I never phoned the number. https://en.wikipedia.org/wiki/Credit_card_imprinter https://en.wikipedia.org/wiki/Credit_card_imprinter
- jeffrallen 1y agoKa-chunk. It's why the letters are raised on the cards!
- Findecanor 1y agoMy latest Swedish credit card doesn't have raised letters...
- jen729w 1y agoSimilarly in the UK we had the concept of a 'cheque guarantee card'. Present your Barclays plastic card along with a paper cheque up to some value (£50 rings a bell; I was too young, it was my mam doing the transacting) and that cheque is guaranteed by the bank. https://en.wikipedia.org/wiki/Cheque_guarantee_card https://en.wikipedia.org/wiki/Cheque_guarantee_card
- jaza 1y agoThis was before my time, but older folks have told me that in the early days of credit cards here in Australia (70s and 80s), for larger purchases at department stores (which were virtually the only merchants who accepted credit cards back then), it was common for the checkout person to phone your bank to get authorisation for the transaction, before you could walk out the door with the merchandise.
- freetime2 1y agoI'm not sure what they have in mind for supporting offline payments, but I think that Japan's FeliCa-based [1] electronic money systems (Suica, iD, etc) are pretty impressive. They are most typically used to pay for transportation, but also widely accepted at stores, vending machines, etc. Balances are stored on the card, and it's very fast to use and seems secure for the most part. Recently it's also available on any smartphone or smartwatch with NFC. Japan was pretty slow to adopt touch payment for credit cards, so for a while it was my favorite form of payment. Transit cards have a pretty low charge limit compared to credit cards - Suica balance is limited to ¥20,000 for example (although for cards that are backed by a credit card, I think the limit is higher). And now that Japan has fully embraced credit card touch payments, FeliCa-based systems are losing market share to Visa, Mastercard, etc. But it really shines for applications requiring speed (i.e. a turnstile in Tokyo station) or offline payments (a vending machine in a park somewhere). [1] https://en.wikipedia.org/wiki/FeliCa https://en.wikipedia.org/wiki/FeliCa
- twothreeone 1y agoIn Germany, there is the Electronic Cash (or newer versions called Girocard) which is similarly smartcard-based for the offline use case, but pairs with a regular debit card for online use [1]. Apparently, not that many people use the offline functionality.. it also has a somewhat low daily limit (though I think those are in place for some online transactions such as getting cash as well). [1] https://en.wikipedia.org/wiki/Electronic_cash https://en.wikipedia.org/wiki/Electronic_cash
- eric6071 1y agoHong Kong octopus is also great
- zdc1 1y agoTaiwan's EasyCard and iCash are their local equivalents. Seems to be common in that part of East Asia to have public transport cards that can also work for small expenses. I wish other governments would take note as its a nice way to avoid the Visa/MC/Amex fees for at least some expenses.
- EE84M3i 1y ago
- boramalper 1y agoThis reminds me of Mondex: > Mondex was a smart card electronic cash system, implemented as a stored-value card and owned by Mastercard. > Mondex allowed users to use its electronic card as they would with cash, enabling peer-to-peer offline transfers between cards, which did not need any authorization, via Mondex ATMs, computer card readers, personal 'wallets' and specialized telephones. This offline nature of the system and other unique features made Mondex stand out from leading competitors at the time, such as Visa Cash, which was a closed system and was much closer in concept to a traditional payment cards' transactional operation. https://en.wikipedia.org/wiki/Mondex https://en.wikipedia.org/wiki/Mondex
- phyzix5761 1y agoI guess if you have a card with no credit limit then this is possible but other than that how can you guarantee the funds, or credit, is there?
- t_mann 1y agoWould be interesting how they work technically. The linked pdf mentions an EMV chip, which I assume is some sort of TEE. Other than creating recipient-specific one-time vouchers online, I can't think of a way to do offline payments without a TEE.
- avianlyric 1y agoYes EMV chips and the EMV standard are secure elements that were spec’d and have been manufactured since the 80s. The EU has been using these thing pretty much universally since the late 90s. They’ve also supported offline transactions that entire time. Indeed offline transactions was the norm for a long time because internet connections were expensive. So payment terminals did offline transactions, then literally phoned home at the end of the day to upload all of the day’s transactions. The transactions themselves are just signed by the cards, and stored by the payment terminals. Interestingly using symmetric encryption, because asymmetric encryption was two expensive to put into debit/credit cards when the EMV spec was originally created. Card transactions being online by default in the EU is pretty recent phenomenon that only really happens in the past 5-10 years, as internet connections and cheap mobile data plans have become ubiquitous.
- lxgr 1y agoEMV has been using asymmetric cryptography for a long time now, even though it's strictly optional in the specs. Older cards indeed didn't have it for cost reasons, and online-only cards theoretically have no strict need for it even today, but practically, a symmetric-only card is a non-starter these days for several reasons. You won't be able to ride the Tube in London or Subway in NYC with a card that does not support it, for example.
- avianlyric 1y ago> You won't be able to ride the Tube in London or Subway in NYC with a card that does not support it, for example. Those systems all perform online auths at the gate, they don’t rely on offline transactions at all. Asymmetric encryption is used to prove the identity of the card itself, I.e. prove it’s a real card owned by a real issuer. But it’s not used to sign the transaction itself. Transaction cryptograms, the cryptographic blob that’s built using data like transaction amounts, method of customer authentication etc only use symmetric encryption. The produced cryptogram itself is then also signed using an asymmetric key, but the asymmetric and symmetric blobs are distinct entities and processes separately by the card network. Now this is the really important, and completely non-obvious part. Only the symmetrically encrypted transaction cryptogram is sent over the card network to the issuer. All of the asymmetric parts are only used locally by the terminal for validation, then thrown away. So the data produced by the card that is actually stored and eventually sent to the issuer can’t be used for cryptographic non-repudiation, because there’s no mechanism for the merchant to prove using only the transaction cryptogram, and public keys, that a specific transaction was signed by a specific card issued by a specific issuer. This may seem very strange from a technical perspective, but only because people think that the technical elements of card networks is what prevents fraud. In reality fraud, at least between network participants, is entirely prevented using legal contracts, escrow accounts, and the simple fact that the benefit of abusing the technical measures to commit fraud is simply not worth the consequences. Being a network participant requires you to put millions of dollars in escrow, and be a large enough company that you can realistically move millions of dollars in transactions everyday. Fraud between companies at that level is solved using very expensive lawyers, the technical measures only need to provide enough evidence of tampering to stand up in a court of law, where everyone is under oath, and at risk of personal repercussions for perjury. There is no need for them to be completely fool proof, it’s much easier to just depose the engineers who were ordered to circumvent the technical controls, under threat of prison time, than it is to get every network participant to adopt some complex cryptographic non-repudiation scheme to protect against scenarios that don’t actually occur in reality.
- jedberg 1y agoA lot of people don't realize that our entire financial system is eventually consistent. They think that when they go to an ATM and withdraw money, it's instantly gone from their account. The reality is that in most cases the convergence is so quick it looks like it's instantly gone, but it's not. For example, if the ATM is unable to get your current balance, it will still complete the transaction. That's why your card has a daily limit -- that's basically the risk tolerance of the bank on how much they are willing to lose if the transactions don't get converge quickly enough.
- chihuahua 1y agoIn a few places, you can see traces of this aspect of the system. For example, some gas pumps put a $150 "hold" on your card, and on your bank's web site, you may be able to see "pending" transactions that are in some not-quite-final state.
- kassner 1y agoThat’s a different thing: pre-authorization. It’s used for when you want to authorize some purchase before delivering the goods (that you later confirm once it’s delivered). The pre-auth is still done online for amounts above the card-offline limit. The nicer feature of preauth is that you can confirm a lower amount. So in the case of a gas pump, they first have to make sure you have the money, without knowing how much, because you haven’t pumped it yet. Once you finish, then they know the amount, and confirm the transaction at a lower amount.
- coldblues 1y agoEvery time I see posts like these related to fiat, my heart sinks. Despite pro privacy sentiments across the site, there is a concerning amount of people who have not only fallen to the trap of convenience, but even consider cash use suspicious or criminal (the morality of tax evasion is a whole different subject, the places where it's most popular often coincides with a corrupt, inefficient government). Soon, cash use will be made impractical due to digital currencies and growing government control, but cryptocurrency will take its place, it has already to a limited extent.
- cyberax 1y ago> but cryptocurrency will take its place, it has already to a limited extent. No. No, it won't. Although labeling regular electronic payments as "cryptocurrency" might become more popular.
- dudeWithAMood 1y agoHow are you going to make offline crypto payments?
- greenavocado 1y ago> Cryptocurrency will take its place. It won't. Look at China. Cash is impossible to use and crypto is banned.
- rjdj377dhabsn 1y agoHow do people pay for drugs, bribes, prostitutes, etc.? Do they just accept the risk the government can see every payment?
- boerseth 1y agoThese past couple of years I've gotten into plenty of trouble on multiple occasions, as a result of what I would describe as a cascade of misfortune initiated by a single unfortunate event (for which I will take some responsibility, but nevertheless...). These "cascades of misfortune" I've run into happen largely because of how we've placed certain institutions at the center of our lives and our society, or perhaps more precisely because of the "convenient" solutions of theirs that we've all been coralled into adopting. I'm thinking of social media networks, smartphone companies and their app stores, banks and their electronic payments, etc. Everyone's opted in, and we don't realise how much we've given up as a result, with all these "convenient" alternatives, now made mandatory to replace the old and inconvenient solution. We don't realize, that is, until you're standing at the bank teller in a city away from home, passport in hand but otherwise robbed of phone and wallet, hoping to withdraw some cash to keep you alive while you sort this mess out - only to learn that the bank is no longer able to do that for you. You can't just get your own money. You could withdraw at the ATM, but with a card of course, and that for a fee with a pretty low upper limit. But banks don't serve that purpose anymore. They're now software institutions that we are forced to have a relationship with and operate through in order to make monetary transactions. Suddenly society has shut down. You can't log into anything without your phone and 2FA, so you're stuck without access to your favorite online services until you get a new SIM card and a fresh device. But even then, there's no riding public transit, because you don't have access to the apps they all operate through. Not that you'd be able to pay in those apps anyway, after cancelling your payment cards. And besides, you don't have anywhere you'd like to go anyway, because, aside from having basically no money to spend on food or events, there's no way to learn what's happening in this city without access to Facebook and all the company pages and events published there. I forget now all the myriad ways that life grinds to a halt, but I do vividly remember feeling like nothing was possible. And that only because I lost one or two things which should be entirely optional in life! You shouldn't be required as a human, nor even as a member of society, to have a Facebook account, or a smartphone, or even a bank account (that last one is perhaps my most extreme take, but I stand by it).
- Reason077 1y agoEMV chip & pin cards have always been capable of offline payments. In the UK this has definitely worked in the past - I remember many years ago there being occasions when something was wrong with the network connection(?) at my local supermarket, but still being able to make a payment in offline mode. This works because the payment terminal authenticates the PIN directly with the chip on the card. They just can't check your balance is sufficient to pay for what you're purchasing. TfL also accepts your contactless card in offline mode: their buses operate in tunnels and other areas with a poor mobile data signal, but cards are still accepted at all times.
- nativeit 1y agoI don’t wanna freak anybody out, but we had offline card payments decades ago. Especially back before online payments existed.
- deleted 1y ago[deleted]
- BUFU 1y agoMake card payment available to local AI agents. How would this sound?
- bilsbie 1y agoAre they talking about something like this: https://en.m.wikipedia.org/wiki/Credit_card_imprinter https://en.m.wikipedia.org/wiki/Credit_card_imprinter Or is there some sort of technological breakthrough?
- daveoc64 1y agoThere's no technical breakthrough, but it might seem novel to people in countries like the USA where offline authorisation hasn't been widely allowed on credit and debit cards for some time. https://en.wikipedia.org/wiki/Online_authorisation https://en.wikipedia.org/wiki/Online_authorisation In many countries in Europe, offline authorisation is more common. Cards have had a chip as standard for over two decades in European countries, and a PIN is often used for cardholder verification. Combined, these make the risks of accepting a transaction for a small amount of money offline very low. The limit of what can be accepted offline is known as a "floor limit" in the UK.
- Phui3ferubus 1y agoThis is just reenabling existing technology. Card chip already has everything required to verify the card and PIN[0], the only thing internet access is required is checking if account is not empty/over limit. [0] That also means that after changing PIN on bank site, you have to visit ATM, so new PIN is actually stored on card - but that it only required for that offline mode.
- komali2 1y ago> “In Sweden, we pay digitally to a large degree and the use of cash is low. The general public being able to pay by card for example for food and medicines even in the event of a serious breakdown in data communication, that is offline, is a milestone in our intensified efforts to strengthen emergency preparedness”, says Governor Erik Thedéen. I understand that it's very normal to use a CC in Sweden (and many places), but it feels grim to me that the thought towards major telecommunications breakdown is, "oh no, how will we make sure that people can keep credit card companies and banks informed that they need food and medicine if the internet is down?" I feel like "reversion" to the solved problem of offline transactions - cash payments - would be a more reasonable default assumption, and in the case of catastrophic infrastructure breakdown, simple expropriation.
- sebra 1y agoRiksbanken have been pushing for cash payments too. Personally I think its too little too late. The culture in Sweden has already changed to purely digital https://www.riksbank.se/sv/press-och-publicerat/nyheter-och-pressmeddelanden/pressmeddelanden/2025/infor-kontantplikt-och-stark-bankernas-ansvar-for-kontanterna/ https://www.riksbank.se/sv/press-och-publicerat/nyheter-och-... Sweden has also done multiple pilots of a digital currency pressed by the state. This might be an interesting alternative to not give up control of our currency and privacy to banks and cc companies. Also supposed to work offline. https://www.riksbank.se/globalassets/media/rapporter/e-krona/2024/e-kronapiloten-etapp-4.pdf https://www.riksbank.se/globalassets/media/rapporter/e-krona...
- 7222aafdcf68cfe 1y agoCash would be a reasonable assumption, but not a practical one unfortunately. The only place really to get cash in Sweden is at an ATM, of which there are very few these days - most have been removed in the past years, and some might be very far away due to the large distances in Sweden. It should also be assumed that in the event of a critical infrastructure breakdown, the ATMs would not work either.
- kalmyk 1y agohuh how is that possible
- tflinton 1y agoCredit card companies have been doing stand-ins to support offline transactions for ages. Mainly the reason why you pay a high interest rate on your credit card.
- anonzzzies 1y agoAlmost no one has credit cards here. It is almost only debit.
- tiku 1y agoIn the Netherlands we had an extra chip on our cards a while back called "chipknip" for offline payments. Didn't work because you had to charge it separately. Chipknip (a portmanteau of chip card and knip, Dutch for purse) was a stored-value payment card system used in the Netherlands. Based on the Belgian Proton system, it was started by Interpay on 26 October 1995, as a pilot project in the city of Arnhem and a year later rolled out countrywide. Chipknip was taken over by Currence due to a restructuring on 17 May 2005, who managed it with their licensees until its discontinuation on 1 January 2015. The Chipknip was primarily used for small retail transactions, as the card could contain a maximum value of 500 euros. The money needed to be transferred from a card holders main bank account using a loading station which were generally located next to ATMs.
- kalleboo 1y agoSweden had a similar system in the late 90's-early 00's called the "cash card", also developed by Proton. It was a huge failure with basically zero uptake, there was no benefit over just using your debit card https://sv.wikipedia.org/wiki/Cash_%28betalsystem%29 https://sv.wikipedia.org/wiki/Cash_%28betalsystem%29
- Findecanor 1y agoAnd it was also before stores started not accepting cash.
- cess11 1y agoI'm not following this as closely as I probably should, but it seems to me to be more of a data collection and retention scheme than something that'd actually be useful to me and my neighbours in a crisis. In part because cash is common in my part of Sweden, which is likely annoying to the bureaucrats and oligarchs. Cash is nice because a transaction does not involve a measure of creditworthiness while only leaving an indirect trail, and this 'offline' thingie they're going for probably does and besides keeping personal data available 'offline' for performing such stratifications of people it also (theoretically) allows for a phasing out of cash also in crisis and armed conflict.
- Bunny121212111 1y ago[dead]
- iamflimflam1 1y agoCredit cards used to be used for offline payments - the cashier would take an imprint of the card and it would all be processed later. https://en.m.wikipedia.org/wiki/Credit_card_imprinter https://en.m.wikipedia.org/wiki/Credit_card_imprinter
- koliber 1y agoWe've come full circle. Credit cards were offline-only in the beginning. When have we lost this ability? See https://www.google.com/search?num=10&sca_esv=5e043526353aa70f&udm=2&fbs=AIIjpHxU7SXXniUZfeShr2fp4giZ1Y6MJ25_tmWITc7uy4KIegMOm3ItDJ-cT-Q5w0bTw0aWDUsQli3okTHBRSgORXy6CJUQc5sVHi-huEHnZn--lXeI5cOKb8xaiaZN98RZ8FshAoaS4PtnoCKohGCXSsG3bp_VbIK8PnkxyWVWwWqyBopz3rD3o3H-MSgFM3SfENhHrzq9&q=old+school+card+impression+machine https://www.google.com/search?num=10&sca_esv=5e043526353aa70...
- lxgr 1y agoWhen everybody in the industry decided the implementation was more trouble than it’s worth. (Offline-capable chips, that is; embossers were 80% solemnization ceremony and 20% data entry aid, just like signatures as "cardholder verification", and are a non-starter from a security perspective.) The mindset was one of ubiquitous Internet connectivity, which is cheaper than maintaining a complex stored-value or offline limit based solution. Of course, this assumption does not include some externalities in case of large scale outages, maybe due to cyberattacks…
- jdblair 1y agoOffline credit card transactions are still supported, and Square even supports it in the US. Europe use of debit cards instead of credit cards is much higher than the US.
- akmarinov 1y agoThat’s because credit card benefits suck in Europe and there’s no point to using them. If you need credit, there are credit options with much lower rates than what credit cards offer. And the reason credit card benefits suck is due to european interchange fee caps and regulation.
- forgotusername6 1y agoThey are still useful for buyer protection.
- 1y ago
- LelouBil 1y agoSpeaking about payment methods, I wonder what's the sentiment on HN about the new Digital Euro thing. I've seen people claim it's the worst thing to ever happen and that governments will lock money and things like that. But personally, after looking at their objectives (offline cash-like payments for example, where only the sender and the recipient know about the transaction) I'm pretty happy about this coming out (even though it still seems early in development)
- wartywhoa23 1y agoCash is the best offline card
- TXCSwe 1y agoThis is to put an end to Visa Electron and Mastercard's Maestro. This cards are often given to underage (< 20 year) customers, to prevent them to overspend.
- 1970-01-01 1y agoI read this as "new fraud mechanism should be possible no later than 1 July 2026"
- unnouinceput 1y agoA lot of people asking here in comments how the implementation would look like, given this is HN and the crowd here is technical inclined. No idea how they will do it but I can tell you how I did it in 2008. See, in 2008 one of my projects had a client that had a lot of venues around continental US and Mexico and those venues were having sparse internet connection (think sky resort venue, remote and internet delivered by antennas that weather could affect it). Meaning when internet was not available any card transaction was a no go. This was a problem to be solved so my client asked if there is a way to make offline credit payments. So here is my implementation: -read credit card details and deliver the goods -> store card details in a local database, encrypted -> check online connectivity -> when internet was a go try to charge the card. If it was good then all was done, details were erased from local storage, everybody happy. If it failed then retry, 5 times per day, for 5 different days. After 25 tries, blacklist the credit card. Forward the information to legal department and mark that credit card as not acceptable from now on. So if you screwed the client with a bad credit card, you screw it only for 5 days maximum. And you also had a legal department on your ass. Meaning you got a fake card, good for you, keep it up cause now you are also on Secret Service radar (most people don't know but Secret Service, not FBI, gets involved in this). In the years I got involved in this project, 8 years, the number of times this was an issue raised to legal department was like under 5. So most folks actually pay and the few that got retried had probably a temporary problem with their funds and eventually they got it back on track. For those under 5 I think all of them eventually cut a deal with legal without raising the issue further up. Sorry guys, no juicy story involving Secret Service here. Probably this worked because the goods were kinda under $50 as price. So maximum you'd screw the company I worked for like $500. And most likely this would not work with a big retailer like Amazon where you can purchase for thousand of $ in a single transaction. But it had the advantage that it worked with all credit cards, debit or otherwise, Visa/MasterCard or whatever. If I would be on the implementation side nowadays from the Sweden bank in this article, I would probably do it like somebody else already proposed here in comments. Get the card to also contain an electronic signature which means a lot more scrutiny to get it released, which means yeah!, your privacy is fucked to Alpha Centauri and back if you try anything shady.
- TacticalCoder 1y ago[dead]
- EasyMark 1y agoMaybe I'm being dense here, why does this matter? Eventually it has to sync up. So what is the advantage other than maybe being able to pay when networks are down? Same data eventually ends up in "the system" doesn't it?