Google Defends Google Wallet After Security Scare

Google has been stung into action and defended its mobile payment service, Google Wallet, and said it is safer than using credit cards to pay for goods.

Google Wallet is a mobile payment app that communicates with smartphones equipped with near-field communication (NFC), a short-distance wireless technology. The app runs on Sprint Nexus S 4G smartphones, which users may tap against a cash register to pay for goods at some 20 retailers and restaurants.

The app, designed to let shoppers leave the wallets, cash and credit cards at home, is protected by a PIN code and the phone’s lock screen.

Is It Safe?

“People are asking if Google Wallet is safe enough for mobile phone payments,” wrote Osama Bedier, vice president of Google Wallet and payments, in a corporate blog post. “The simple answer to this question is yes.”

However, two separate security researchers last week cracked the PIN code used to secure Google Wallet.

On 9 February, Web security provider Zvelo found a way to execute a brute-force attack on the Google Wallet PIN code. Zvelo engineer Joshua Rubin said the Wallet-bearing smartphone needs to be rooted by the user or someone who has physical access to the device to divine the PIN code.

Google said it “strongly discourages” users from disabling the PIN code in order to gain root access to their phone because the product is not supported on rooted phones.

“That’s why, in most cases, rooting your phone will cause your Google Wallet data to be automatically wiped from the device,” Bedier wrote.

In the other attack, the SmartphoneChamp blog 10 February detailed how a user who finds a lost Wallet-enabled smartphone that is not protected by a screen lock can clear the data associated with Wallet from the phone’s application settings menu.

What this does is prompt Google Wallet to reset itself and ask the user for a new PIN the next time it is launched. A user can simply create a new PIN and associate a Google PrePaid card to the app to access all previously available funds.

Permanent Fix

Bedier acknowledged this issue, saying Google temporarily disabled provisioning of prepaid cards as a precaution until Google issues a permanent fix.

He added that, as with credit cards, users who lose their phone or fear someone used them to make unauthorized payments can call Google’s toll-free assistance hotline at 855-492-5538.

“In the meantime, you can be confident that the digital wallet you carry provides defences that plastic and leather simply don’t,” Bedier added.

This is an allusion to the notion that the more wallets stay at home, the fewer will get lost and pose security issues related to lose credit cards.

However, if researchers keep poking holes in Wallet, whether they use tricks to unlock PINs or not, the less credible Wallet’s security will seem. This will be problematic at a time when Google is fighting to expand the service and help it proliferate in commercial markets worldwide.

In general, NFC-based mobile payments are expected to boom over the next five years.

Clint Boulton eWEEK USA 2012. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

2 days ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

3 days ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

3 days ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

3 days ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

3 days ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

3 days ago