Suica App 3D Secure authorization for all non-Apple Pay in-app purchases

More fallout from the VISA JP Apple Pay agreement: JR East announced they will implement 3D Secure in iOS Suica App, requiring authorization for all non-Apple Pay in-app purchases.

Suica App is convenient because it works hand in glove with Apple Pay and app registered Japanese issue credit cards, giving users the widest possible card coverage. Since 2016, Suica App was the only work around solution for using VISA JP cards for Apple Pay Suica recharge.

With the VISA JP Apple Pay deal however, we are seeing a bunch of credit card backend changes, like merchant code changes that eliminate Suica recharge 3x travel points for Chase Sapphire Reserve VISA holders. JR East is changing how Suica App works, 3D Secure authorization for all non-Apple Pay in-app purchases is part of that. For users this means doing Suica recharge and commute plan renewal in Wallet instead of Suica App to avoid 3D Secure login hassles. Wallet is the hands down easiest way to recharge Suica and renew commute plans.

We’ll see a Suica App v3.0.4 update when 3D Secure is in place, likely after the new Eki-Net launches June 26. PASMO App already uses 3D Secure for registering cards but not for in-app purchases.

With direct Wallet addition of Suica cards starting with iOS 13 coupled with last year’s migration of Shinkansen eTicket functionality to Eki-Net, and the addition of VISA JP Apple Pay in-app support, Suica App is less essential than ever. The only reason for using it now is new commute plan purchases, Auto-Charge setup (which remains the 3D Secure free way to recharge) and receiving Suica Pocket recharge rewards.

There are some VISA JP cards that still don’t support Apple Pay in-app, MUFG holders still have to recharge the old Suica App way. Whatever the reason, the across the board change will be likely be very unpopular with iOS Suica App and Android Mobile Suica users.

UPDATE July 20, 2021
3D Secure is now required for registering credit cards in Suica App. So far there are no reports of 3D Secure confirmation required for Suica App in-app recharge or Green Car Seat upgrades. This matches my own limited testing. I’ll update this post if anything changes.

Any purchase in Suica App can be made with Apple Pay instead of the app registered card that bypasses 3D Secure, Suica App registered CC on the left, Apple Pay on the right

UWB Touchless Express Transit and Apple Pay for iOS 15?

A recent sudden surge of hits from Hong Kong accessing my December 2019 UWB Touchless Mobile FeliCa post seemed odd. I dug around and it appears that Hong Kong MTR, like JR East, is making noises about incorporating UWB technology in next generation transit gates.

iOS 14.5 added a new PassKit call for Bluetooth and the U1 chip integration since iPhone 11 and Apple Watch 6, coupled with global FeliCa support certainly puts Apple ahead of the game. I have no idea what WWDC21 will deliver but more UWB integration is a given.

Apple only mentioned UWB Touchless at WWDC20 in connection with digital car key without showing anything because the Car Connectivity Consortium Digital Key 3.0 spec was a work in progress. Now that the spec is in-place with BMW said to deliver car models incorporating UWB Touchless this year, will Apple show it in action? I think it’s highly likely, but since Car Key is a ‘Wallet Card’, and Wallet app Express Cards come is 3 types: Transit, Student ID, and Car Key, the more interesting question is…will Apple also show Touchless Transit and Student ID Express Cards? And what about Apple Pay?

People think Touchless is a completely new thing for ‘keep smartphone in pocket’ transactions, and they worry about security. You can’t blame them because marketers are selling the in-pocket payment experience. However, Touchless is simply long distance NFC without NFC. All UWB Touchless does is describe the frequency to use Bluetooth instead of NFC. The background stuff, secure element and so on, is exactly the same. This means user interaction is the same. For walking through transit gates and security doors, or unlocking your car, the convenience of Touchless is easy to understand: no more NFC tapping, just keep moving.

What about Express Card payments? The current Apple Pay Suica payment checkout experience: the user taps Suica on a touchscreen, or tells the clerk “Suica” then holds the device to the reader. The user has to give consent before the transaction is activated by checkout staff or the self checkout reader. For Apple Pay EMV transactions users have the extra step of confirming a transaction by Face ID/Touch ID to complete it.

Realistically however, in what situations does Touchless make store checkout more convenient and faster? Drive thru certainly, supermarkets…maybe, but most stores will probably not want to invest in Touchless without a good reason when the NFC readers they already have installed get the job done. There is one more interesting role that Apple has planned for UWB however, one that promises to improve the entire Apple Pay and Wallet experience: communicating with the reader before transaction to select the right Wallet card for the job, at a distance, for a truly smart Wallet app. With national ID cards, passports and more coming to Wallet at some point, UWB could be the Wallet reboot we really need.

And then there is EMVCo. The problems with UWB Touchless for EMVCo are that: (1) Touchless only works with devices with batteries, á la AirTag, and doesn’t work with the current plastic card model, (2) UWB + Bluetooth level the digital playing field with FeliCa and MIFARE, no more ‘real’ vs ‘who cares’ NFC hardware flavors to split hairs over. The plastic card NFC limitation is probably a bitter pill for everybody but especially for EMVCo members and issuers as plastic card issue is big business, and many customers are more comfortable with plastic cards. For those reasons I think EMVCo will be the last to support UWB Touchless, if they do at all. On the plus side Touchless does give digital wallet platforms an edge to create smart aware wallets, digital does NFC and Touchless, plastic only does NFC. We’ll find out about Apple’s UWB Touchless roadmap at WWDC21.

Is it possible to move Suica to a different iCloud account?

asking for a friend but is there a way to remove a PASMO from one iCloud account, and move it over to a different iCloud account? My friend is a bit of an idiot and noob with iPhones.

This is a tricky question and even if possible, why bother? Most people would just add a new Suica•PASMO to iPhone which is very easy to do. Up until the big Mobile Suica reset on March 21 it wasn’t possible to migrate the Suica card anywhere else except a different device with same iCloud account. However, it is now possible to move the same Mobile Suica card between Android and iOS. PASMO doesn’t allow this yet because Mobile PASMO hasn’t received the same backend upgrade. If we were assigning version numbers Mobile Suica would be v2.0, Mobile PASMO would be v1.5. In Mobile Suica 2.0 the card ID, the Mobile Suica account email used for system ID, is independent of Apple Pay and Google Pay systems. Let’s take a look at how it might work.

Here is the Mobile Suica transfer path going from iOS to Android.

  • Requirements: Mobile Suica account, ID registered email and PW, latest versions of Suica App (iOS) and Mobile Suica App (Android) installed on both devices.
  • Step 1: remove Suica from Wallet on iPhone (this parks the Suica card on the Mobile Suica cloud server)
  • Step 2: on the Android device launch Mobile Suica and sign in with the same ID and PW
  • Step 3: follow the screen prompts to add the Suica card from the server to the device

One of the interesting points about Android is that the receiving device must have a valid SIM inserted, otherwise Suica will not transfer. In theory here is how the process might work going between different iCloud account devices:

  • Requirements: Mobile Suica account, ID registered email and PW, Suica App 3.0.3 or later (iOS) installed on both devices.
  • Step 1: remove Suica from Wallet on iCloud A device, sign out of Suica App or delete the app, restart device
  • Step 2: on the iCloud B device launch launch Suica App, tap [機種変更] (Transfer from Android) and sign in with the same ID and PW
  • Step 3: Tap [+], and (if the theory is correct), you should see the Suica card with balance on the server, add to Wallet

Remember this may not work as it is not officially supported by JR East, for security reasons, and I have no way to test confirm if this works or not. Even in the worst case that is does not work you still have the Suica card attached to the iCloud account. And remember, it’s very easy to add Suica and PASMO to any iPhone 8 and later or Apple Watch Series 3 and later.

JR East eliminating 70% of ticket offices by 2025 in ticketless push

In the run-up to the June 27 Eki-Net reboot next month JR East released a nice looking PR release with the first 2 pages promoting a ticketless future. On page 3 they dropped a bomb: JR EAST will eliminate ‘up to’ 70% of their ticket offices by 2025, just 140 stations or so on the entire JR East rail network will have the honor of having a ticket office manned by real people:

JR East has been planning this for years and report that in 2019 only 30% of JR East ticketing was purchased at a JR East Ticket Window (Midori-guchi). In 2020 that number declined to 20%. Could it be people were so tired of waiting in long slow ticket office lines they bought tickets elsewhere? Let’s be real though, the COVID pandemic has hit transit so hard all expenses that can be cut will be cut. You will going ticketless whether you like it or not.

So yes, we have Mobile Suica and Eki-Net Ticketless for regular express trains, Touch and Go Shinkansen, Mobile Suica and Shinkansen eTickets. By 2025 I suspect QR tickets will have replaced mag strip tickets. The Cloud Suica system coming in 2023 is said to power QR ticketing as well. All is good, I guess. Except for when you need help at the transit gate for some weird ticket problem, a smartphone that died before you got to the last station because you were too wrapped up playing games on it. What do you do? Press a button for an online station agent:

JR East says real station agents will be available to offer real assistance for disabled customers and such. We shall see. If JRE wants people to use Suica as much as possible they need to get Suica disability discount fares in order and working on mobile. Right now they are only working in the 2 in 1 totra Suica region. They need to work everywhere.

The VISA JP Apple Pay announcement and digital banking wars

MacRumors: Customers with Visa cards…will be able to add their card to their Wallet on iPhone and Apple Watch.

Me: I like MacRumors but the writer here has no idea what the story is or that users have been using these cards in Apple Pay all along for store purchases.

MacRumors: Hey! Could you elaborate on what you mean? Visa cards issued by those banks now have Apple Pay, correct?

Sure Sami, here’s the elaborate story. Do you know FeliCa? It’s the Sony created NFC standard that has been around a long time, long before EMV grafted NFC into contactless credit cards. When mobile payments launched in Japan back in 2004, Mobile FeliCa was the only technology that worked. So mobile payments for all major credit cards and Suica were built on Mobile FeliCa, the contactless payments infrastructure in Japan grew from that.

Fast forward to 2016. Phil Schiller announced FeliCa for iPhone 7 at the keynote and the launch of Apple Pay in Japan. VISA Japan didn’t sign an agreement with Apple but it didn’t matter much because VISA JP cards were available for Apple Pay thanks to previous Mobile FeliCa agreements covering the iD and QUICPay networks for store payments. The other card companies (Mastercard JP, JCB, American Express JP) signed with Apple.

It was a big success. But the Mobile FeliCa agreements only covered store purchases, they didn’t cover things like in-app purchases. Even though many Japanese users added their VISA cards to Apple Pay they couldn’t use them to recharge Suica cards because in app purchases were not supported.

Fast forward to 2020. VISA JP is a major sponsor of the Tokyo Olympics showering sponsorship money to promote ‘VISA Touch’ EMV contactless cards. They want customers to use VISA Touch at stores, not iD and QUICPay because the margins are nicer and EMV contactless is a world standard except for places like Japan (FeliCa) and China (PBOC). Most of the POS equipment in Japanese stores is multi-protocol ready so the customer NFC flavor is a moot point. For whatever reason, let’s say marketshare, VISA JP finally signed on with Apple Pay.

What changed for all those VISA JP cards already working in Apple Pay Wallet these past few years? A VISA logo, in-app payments, dual mode NFC and Payment card Express Transit:

Did you get that Sami? Hello, anybody there?

Digital Banking Wars
Seriously though, it’s sad when tech writers don’t understand the technology in the stories they write. All major Apple sites ran the same wrong story. It should have been: Visa JP Cards now fully support Apple Pay. I think journalists do everybody a great service when explaining complex stories and connecting the dots in easy to understand ways. Nobody cares, which is a shame because there were other major things going on behind the VISA JP Apple Pay announcement that even the Japanese tech media missed: the very same day, NTT Docomo and MUFG announced a joint digital banking venture.

Let’s take a closer look at that VISA JP Apple Pay announcement, specifically the issuer launch list: APLUS, Cedyna (SMBC Financial), SMBC, Docomo, MICARD, Saison, JACCS, Rakuten. Do you see MUFG? Nope. MUFG brand VISA cards will join at some point, probably, but VISA has put all their eggs in the SMBC basket, the companies are not on the friendliest of terms.

NTT Docomo and SMBC/VISA group feuded for years and called a stalemate. It was only a matter of time before NTT Docomo kicked SMBC to the curb, which they did yesterday with the MUFG joint announcement. Docomo and MUFG are going to leverage dPoint into an economic zone to rival Rakuten and SMBC/VISA V Point. It’s as simple as that. And here you thought that VISA JP announcement was only about Apple Pay. Think again, the economic zone mobile digital banking wars are just getting started.

One last bit: if you want to know the reason why it took so long for VISA JP to sign with Apple go to the SMBC V Point App page and look at the Apple Pay • Google Pay section. ApplePay is dual mode, Google Pay is EMV only. It was the power play we suspected all along: VISA wanted to kill FeliCa, Apple stuck to its NFC switching dual mode guns. For a detailed list of VISA JP cards and supported features go here.