'Host Card Emulation' Vs 'Secure Element': Which Is More Secure?

Although Apple is using a Secure Element to safeguard Apple Pay credit card transactions, competitors such as Google and Microsoft have decided on Host Card Emulation (HCE) as an easier way to bring secure mobile payments to whole ranges of devices. Although HCE is easier to implement, it may not have been the best choice in terms of security.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • badvok66
    While Secure Element does hide the user and provide privacy this is a double-edged sword since that same privacy allows ANY credit card, stolen or cloned, to be used with no trace. Thus criminals no longer need to clone the physical card onto another card, they just need to store the stolen details in a device using a Secure Element.

    With HCE there is likely to be some traceability, at the expense of privacy.
    Reply
  • ericburnby
    While Secure Element does hide the user and provide privacy this is a double-edged sword since that same privacy allows ANY credit card, stolen or cloned, to be used with no trace. Thus criminals no longer need to clone the physical card onto another card, they just need to store the stolen details in a device using a Secure Element.

    With HCE there is likely to be some traceability, at the expense of privacy.

    Not true. If a criminal has your credit card data AND enough personal information to get through the screening/activation, then they can add a stolen card to either system just as easily.

    Secure element/tokens don't make the transactions 100% anonymous (or leave "no trace" as you implied). They're only anonymous to the merchants. The bank will have a detailed record of activity exactly as if the person used an actual card.
    Reply