Holiday Gift Guide »

Video: If you root your Android device, your Google Wallet PIN code gets exposed

Categories: Android
By: , IntoMobile
Thursday, February 9th, 2012 at 5:10 AM

Google Wallet, the mobile payment service that uses near field communication (NFC) technology and hopes to one day replace the physical wallet that’s already in your pocket, apparently has a security flaw should you be one of the few people daring enough to have a rooted Android device. Now before you freak out and start questioning the security of Google Wallet, we’ll say this again in case you missed it the first time around: This security flaw only impacts owners of rooted Android phones. The guys from the research group “zvelo” discovered a flaw whereby they can see your Google Wallet PIN code with just a simple app. They say Google already knows about it and that only way to fix the issue is for Google to reengineer how Google Wallet works with regards to who is the authenticating party. Right now Google authenticates you, not your bank. All that being said, “zvelo” is confident that Google shouldn’t have too many difficulties making things right. They still however recommend that you use a password on your device and also turn on device encryption.

Compared to a credit card and cash, both of which can easily be stolen, anything that requires a PIN code is pretty much bulletproof. Still, expect to hear more stories like this as NFC takes off and mobile payments become a hot topic of discussion. Right now we’re in the very early days, but it’s only a matter of time until the next iPhone comes out, Windows Phone 8 devices hit the market, and America’s operators launch ISIS. Then there are going to be tens of millions of potential wallets to hack, and you bet lots of folks are going to try.

For the ultra paranoid, just make sure you use a credit card that has a pin chip. Those are damn near impossible to crack. We’d say use cash, but a mugger with a knife is all it takes to end up poor and sobbing on a street corner.

[Via: The Verge]

About The Author

Stefan Constantinescu

Stefan Constantinescu (@WhatTheBit on Twitter) has loved technology since as far back as he can remember. It started with computers, but in the past few years his passion has turned to mobile devices. As a mobile phone enthusiast who lives and breathes devices that connect to the internet, he knows he is not alone with this radical fascination of all things wireless. He is strongly opinionated and enjoys a good debate so leave comments in his posts and he’ll get back to you! Stefan began blogging as a hobby in the fall of 2006 and joined IntoMobile in the summer of 2007. Later he got a job at Nokia in March 2008, but as of June 2009 he has rejoined the IntoMobile team. He is currently based out of Helsinki, Finland.