0

Google Wallet PIN Exploit: How-To Protect Yourself, Rooted Phones At Risk

Posted on 10 February 2012 by pinoytutorial

A recent report from viaForensics has pointed out a certain security issue with regards to Google Wallet. According to their statement, users’ PIN can be easily made known due to personal information and payment profile that remains unencrypted. Exploring through the application’s code and utilizing open resources provided by Google itself to determine the contents, it was revealed that there was a very important set of data, including user IDs, information on one’s Google account, as well as the user’s PIN that had been stored in the form of a SHA256 hex-encoded string.

google wallet hack 1 Google Wallet PIN Exploit: How To Protect Yourself, Rooted Phones At Risk

Because such string has been recognized to include four digits, it can take a few to 10,000 computations in order to decode such numbers. A Wallet Cracker app was even developed to demonstrate how a user’s PIN in Google Wallet can be easily worked out. Google has stated that the most affected users are the ones who are using rooted devices; therefore, it has been encouraged that people should not install Google Wallet on a rooted device for increased security.

See how the Wallet Cracker app works:

Such reports have reached Google and while the company has made its attempts to reduce such vulnerability, their efforts have been slowed down due to the need to work together with the banks. Altering the way with which the users’ PIN is stored will also bring about change with which security is provided, hence the need for coordination with banks. Nevertheless, according to Zvelo, users can still maintain security for their Google Wallet by enabling their lock screen, disabling USB debugging, allowing Full Disk Encryption, and using an up-to-date handset.


Share

You might also like

Galaxy Nexus: Google Wallet ‘Blocked’ By Verizon In The Name Of Security, For Now
Why You Shouldn’t Use Google Wallet: Will iPhone 5 Adopt?
Google Wallet Review and Release Date — How To Use It?
Samsung Nexus S 4G: Android 2.3.7 (GWK74) OTA Update — Download For Google Wallet
Galaxy Nexus Google Wallet Hack: No-Root Guide and Download
 

Story by

Tags: , , , ,

Sensible comments/suggestions are always appreciated.

Pinoytutorial Links


Or, subscribe to us via email:


Delivered by FeedBurner