So this happened this week and I have not stopped smirking about it: CurrentC, the mobile payment app that CVS and Rite Aid disabled their NFC terminals for so they could force you into it instead of Apple Pay, got hacked. Days after launching its pilot. Email addresses of testers got scooped up by "an unauthorized third party," which is corporate-speak for "somebody got in and we don't want to say how."
Let me back up for anyone who hasn't been following this mess.
Apple Pay came out on October 20th, and it's genuinely great, tap your phone, use Touch ID, done. No card out, no signature, no fumbling with a chip reader that beeps at you like you did something wrong. Then last weekend CVS and Rite Aid quietly switched off their NFC readers entirely. Not just for Apple Pay, for Google Wallet too, everything that used the same tap-to-pay hardware they'd had installed for years. Why? Because both chains are part of a retailer consortium called MCX that's been building its own payment app, CurrentC, and apparently they've got exclusivity agreements that say they can't support competing systems while they're rolling their thing out.
I tried to pay with Apple Pay at a CVS on Tuesday out of morbid curiosity, more or less to see it fail in person. The reader just sat there dark. The cashier didn't even blink, I think she's had this conversation forty times already this week.
And CurrentC itself isn't even out yet. It's still in a limited pilot with a handful of companies, you have to use a QR code instead of NFC (which, come on, it's 2014, scanning a black and white square feels like a step backward when the phone in your hand can already do a tap), and it links straight to your bank account rather than a card, presumably so the retailers can skip interchange fees. That's really what this is about, if you ask me. It was never about security or "openness," it's about a dozen big chains not wanting to pay Visa and Mastercard their cut.
So the hack timing is almost too good. MCX put out a statement Thursday saying the breach only affected people in the CurrentC test group and that actual account or payment information "was not at risk" because that data lives somewhere else. Maybe that's true! But it's a rough way to introduce yourself to the public, especially when your entire pitch is "trust us more than the guy with the fingerprint sensor."
I don't think this kills CurrentC on its own. Big companies have weathered worse first weeks. But it's a bad look layered on top of an already bad look, and it's the kind of story that makes the whole "we blocked a working payment system to protect our new unproven one" decision look even dumber in hindsight. My CVS receipt is still two feet long and printed in six point font, by the way, unrelated complaint, but if we're rebuilding retail tech from scratch can somebody fix that too.
I keep going back and forth on whether Apple Pay actually changes anything long term or if it's a nice-to-have that dies out once the novelty wears off, the way I felt about Passbook boarding passes for the first year (still haven't used one, still have the app). But at minimum it works right now, today, at the terminal, without a QR code or a new bank linkup. That's not nothing. When the alternative announces a breach in week one, "it works" starts to look like the whole ballgame.
Anyway. I'll keep testing Apple Pay wherever I go until I run out of stores that support it, which at this rate might be sooner than I'd like. If you've had it actually reject a valid card at checkout I want to hear about it, mine's worked everywhere except, well, you know.