الأحد، 12 فبراير 2012

A security problem with Google Wallet

From an article posted at Technorati.  If someone gets hold of your phone, all they have to do is reset the app:
Once Google Wallet is restarted, it will ask for a new PIN. The thief types in whatever PIN they want, and viola — instant financial disaster.

The reason this is possible, is Google Wallet attaches access to your funds to the device itself. This is to ensure you as the legitimate user can get to your funds easily. Using Near Field Communications technology, simply move your Google Wallet-enabled smartphone near a special reader, type in your PIN, and you're on your way. Unfortunately, this concept makes it easy to anyone else who has your phone, due to the ease creating a new PIN...

The forum user that discovered this new flaw states they informed Google of their find, and that Google has a fix for those banks that choose to implement it. Are you secure? If you're a Google Wallet user, you might want to contact your bank and ask...
More at the link, including an illustrative video.

ليست هناك تعليقات:

إرسال تعليق