PaymentsJournal
SUBSCRIBE
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
  • Analysts Coverage
  • Truth In Data
  • Podcasts
  • Videos
  • Industry Opinions
  • News
  • Resources
No Result
View All Result
PaymentsJournal
No Result
View All Result

Google Wallet PIN Hack Still Works, But …

Mercator Advisory Group by Mercator Advisory Group
August 14, 2012
in Analysts Coverage
0
B2B Payments' Can Fintech Finally Connect Business Payments to the Digital Wave? - PaymentsJournal
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

The same white-hat hacker who broke the PIN handling of Google Wallet 1.0 has discovered that the same, or a very similar, hack works against the new and improved, cloud-oriented Google Wallet 2.0. This issue only occurs on rooted Android handsets, so it is easy to have some sympathy with Google’s stance that it cannot secure Wallet on a phone whose security has been compromised. But the issue does persist and it is possible for a phone to fall into someone else’s hands who, themselves, will root the device and be able to compromise the PIN code.

As with all electronic payment methods, the security of Google Wallet is still a work in progress. Google has much bigger challenges for Wallet. It needs Verizon Wireless, AT&T Mobility, and T-Mobile (the Isis triumvirate) to allow Google Wallet access to the secure element on the devices it controls. And that’s not likely for the time being.

While the PIN hack is a concern, it is not a fatal flaw by any means. Indeed, between its launch and the new version, Google Wallet has changed its card handling model in a way that may enhance security. If nothing else, this is not a security issue to get excited about. Just don’t root your phone.

From Security Watch:

“This new update changes Google Wallet from a way to store and pay directly with your payment cards to a NFC Google Checkout service,” wrote Intrepidus senior consultant Max Sobell in a blog post.

But with less data stored locally, the threat landscape is shrunk.

“I would say that one-off fraud is much safer because all payments now go through Google’s ‘virtual’ card, and then are passed off to your credit card within Google’s environment,” Intrepidus senior consultant Max Sobell told Security Watch. “In previous Wallet builds, your credit card details were going through the NFC interface unencrypted to the Point of Sale terminal.”

Click here to read more from Security Watch.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Analyst Coverage, Payments Data, and News Delivered Daily

    Sign up for the PaymentsJournal Newsletter to get exclusive insight and data from Mercator Advisory Group analysts and industry professionals.

    Must Reads

    faster payments

    Faster Payments Are Set to Revolutionize Modern Digital Payments

    January 26, 2023
    How AI can Help Manage Payments Risk in 2023

    How AI can Help Manage Payments Risk in 2023

    January 25, 2023
    cross-border payments

    How to Implement Effective and Innovative Cross-Border Payment Strategies

    January 24, 2023
    credit card experiences, digital payments, b2b payments

    Will Consumer-to-Business Payment Trends Drive B2B Global Growth in 2023?

    January 23, 2023
    Faster Payments Faster Identity Verification, connected car, payments

    2023 Predictions: Authentication, Digital Identity, and In-Car Payments

    January 20, 2023
    bank data

    Interconnectivity, Data Sharing, and Security Are Vital for Banks to Thrive

    January 19, 2023
    B2B Payments, cryptocurrency

    Crypto as a Practical Solution to B2B Payments

    January 18, 2023
    AR, accounts receivable

    Digitizing AR Would Address One of Executives’ Biggest Concerns About Economic Instability

    January 17, 2023

    • Advertise With Us
    • About Us
    • Terms of Use
    • Privacy Policy
    • Subscribe
    ADVERTISEMENT
    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Videos
    • Industry Opinions
    • News
    • Resources

    © 2022 PaymentsJournal.com

    • Analysts Coverage
    • Truth In Data
    • Podcasts
    • Industry Opinions
    • Faster Payments
    • News
    • Jobs
    • Events
    No Result
    View All Result

      Register to download the Brighterion eBook - The power of today’s market-ready AI to reduce transaction fraud