Subpages

Find us on

Archived News

Recent News

Poll

User: Password: Forget Password? | Register
 
Experts unveil two vulnerabilities on Google Wallet
 

Windows X's Live recommends:
Before and after making any changes to your system: Check Windows for registry errors
and make sure to run a free scan to check check for windows errors causing speed loss

The security editor zveloLABS published a note showing some flaws in the Google Wallet payment service (available in the U.S. and using the NFC). He explained that the service stores the hash of unencrypted passwords used to secure a transaction. According to the engineer Joshua Rubin, it is then possible to find this code.

Indeed, with a 4 digits PIN there is only 10,000 possible combinations of numbers. Rubin explains that a brute force attack could quickly find the security code. An attacker could then, if in possession of the smartphone, try to access the victim's wallet account. zveloLABS states that the division of Google Security Agency is aware of the fault.

Meanwhile a security update, a second vulnerability was published by The Smartphone Champ. The site explains that no protection exists if a user wishes to erase all application data. A new PIN is provided and is used to connect to the service again to make further payments.

A hacker with the smartphone could easily get the code to make further payments. For its part, Google said it had temporarily disabled the account provisioning. The company will soon release a security patch.