Google Wallet NFC payment system can be exploited
Summary: An exploit for Google Wallet enables thieves to change a user's PIN and get at the stored funds - without needing to actually hack the device.
Earlier in the week, security firm Zvelo uncovered a way to compromise the Google Wallet NFC payment system, opening the door for criminals to use your phone and empty your virtual pockets. But it was only a problem if your phone was rooted and if you didn't have a lock screen passcode set. But now, blog TheSmartphoneChamp has figured out an exploit to do the same without the phone needing to be first rooted.
Uh-oh.
The worst part, as Gizmodo points out, is that the method is so simple that it requires essentially no technical expertise or skill at hacking. Just clear the data in the app settings, which prompts you for a new PIN. Put in that new PIN, tie a new Google pre-paid card into it, and all the previous funds are once again available. After that, whoever's holding your phone can wave it in front of any of the many participating retailers, enter the new PIN they just set, and spend your cash.
You know it's serious because Google is issuing the following statement:
We strongly encourage anyone who loses or wants to sell their phone to call Google Wallet support toll-free at 855-492-5538 to disable the prepaid card. We are currently working on an automated fix as well that will be available soon. We also advise all Wallet users to set up a screen lock as an additional layer of protection for their phone.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: Google Wallet NFC payment system can be exploited
RE: Google Wallet NFC payment system can be exploited
agreed
RE: Google Wallet NFC payment system can be exploited
rooting isn't something THEY would do...
...and the article even says that it's no longer required.
"But now, blog TheSmartphoneChamp has figured out an exploit to do the same without the phone needing to be first rooted"
...it's not that big a target at the moment, mainly because A) it's effort involved; and, B) you'll probably get more value from the phone itself instead of the google wallet; and, C) google wallet NFC isn't exactly common yet. (recall the article mentioning how it's only on Sprint and only the 1 phone model)
RE: Google Wallet NFC payment system can be exploited
Beta is always going to happen...
That said, there's been weaknesses in the INTERAC system, which weren't known/discovered at the time of creation. This is a similar situation where it needs to be fixed.
There should be no delay in fixing it, but updates might have issues with distribution, if not everyone updates to a fixed version, or whatnot.
RE: Google Wallet NFC payment system can be exploited
That's the key thing. It's not the probability, it's the credibility. Screw ups like this can be survived once a technology is off the ground, but this can set it back.