Google users warned of threat to smartphone wallets

Feb 10, 2012
Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.

Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.

Zvelo Labs researcher Joshua Rubin was featured in a video at the company's website demonstrating software that quickly figures out a Google (PIN), provided the crook has the .

Rubin said that Google has been alerted to the vulnerability and is moving swiftly to fix it. He has not made his wallet "Cracker" application public.

This video is not supported by your browser at this time.

"Google Wallet allows only five invalid PIN entry attempts before locking the user out," Rubin said in a blog post.

"With this attack, the PIN can be revealed without even a single invalid attempt," he continued. "This completely negates all of the security of this mobile phone payment system."

Google declined an AFP request for comment.

"Once attackers get your PIN, they have full access to any stored in the app and they can use your phone to make purchases," McAfee researcher Jimmy Shah said in a blog post.

"As a user of Google Wallet, the main security you see is the PIN," McAfee added.

"What makes Wallet easy for you to use now makes it easy for attackers to use; they can now spend your money and credit just as if your phone were an ATM card."

Rubin dismissed the threat of hackers picking Google Wallets remotely, explaining that physical access is needed to get priority access to controls in a process called "rooting."

Security specialists advise Google Wallet users not to "root" smartphones, and to enable such as full-disk encryption and screen locks.

Google Wallet is available only on Nexus S and Galaxy Nexus smartphones. Google said it planned to expand the feature to more Android phones.

Google Wallet uses a near field communication (NFC) chip embedded in a phone to allow a user to "tap-and-pay" for purchases at a checkout register equipped with the PayPass system from CitiMasterCard.

Customers can also use a Google Prepaid card to pay for purchases, topping up the Google card with any payment card, and take advantage of Google Offers, the Mountain View, California-based company's online discount coupon program.

In addition to allowing for mobile payments, Wallet allows consumers to pay using gift cards and to redeem promotions such as discounts or coupons.

Explore further: Dove 'Sketches' most-watched online ad: Unilever

add to favorites email to friend print save as pdf

Related Stories

PayPal letting Google phones swap cash

Jul 13, 2011

Online financial transactions giant PayPal on Wednesday showed off a mini-program that lets people exchange money by touching together a pair of Google smartphones.

Recommended for you

Internet in 'coma' as Iran election looms

May 19, 2013

Iran is tightening control of the Internet ahead of next month's presidential election, mindful of violent street protests that social networkers inspired last time around over claims of fraud, users and ...

Bernanke forecasts gains from computer technology

May 18, 2013

(AP)—Federal Reserve Chairman Ben Bernanke says pessimists who are forecasting that the economy will not reap sizable benefits from the computer revolution are likely to be proven wrong.

Yahoo Japan suspects 22 million IDs stolen

May 18, 2013

Yahoo Japan Corp. has said it suspects up to 22 million user IDs may have been stolen during an unauthorised attempt to access the administrative system of its Yahoo! Japan portal.

US seizes Bitcoin operator accounts

May 18, 2013

US authorities seized the accounts of a Bitcoin digital currency exchange operator, claiming it was functioning as an "unlicensed money service business," court documents showed Friday.

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

chromosome2
not rated yet Feb 12, 2012
The only phones that have Google Wallet have operating systems that the carriers haven't had an opportunity to screw up, so, I don't see why one would root them. I rooted my HTC Incredible because my first phone was the Droid and I couldn't stand sense, and gosh darnit, if I'm going to buy a $700 pocket computer, it's going to do what *I* want it to do. The Nexus phones already do that.

More news stories

Philippines approves three new wind farms

The Philippines has approved three wind farm projects that will generate 208 megawatts, enough to power more than 40,000 middle-class homes, an energy official said on Monday.

Protein study suggests drug side effects are inevitable

A new study of both computer-created and natural proteins suggests that the number of unique pockets – sites where small molecule pharmaceutical compounds can bind to proteins – is surprisingly small, meaning drug side ...

Do salamanders hold the solution to regeneration?

Salamanders' immune systems are key to their remarkable ability to regrow limbs, and could also underpin their ability to regenerate spinal cords, brain tissue and even parts of their hearts, scientists have ...