Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

pokerfan

(27,677 posts)
Fri Feb 10, 2012, 12:43 AM Feb 2012

Google Wallet Hacked Again, Now You Should Panic

That's twice. In two days. Yesterday, security firm Zvelo discovered a potential exploit against rooted phones. Today, tech blog TheSmartphoneChamp discovered how to accomplish the same feat on non-rooted phones. This is not good.

What makes the new hack so dangerous is that it requires absolutely no hacking. While yesterday's exploit required you to crack encrypted files, today's requires you to simply clear the data in the app settings. Doing so forces Google Wallet to reset itself and prompt the user for a new PIN. Once that's done, the attacker ties in a Google PrePaid card to the account and presto—all previously available funds are once again accessible. The method has been tested by multiple sources and confirmed by Google itself—this is not a drill.

Google has issued a statement regarding the new method, We strongly encourage anyone who loses or wants to sell their phone to call Google Wallet support toll-free at 855-492-5538 to disable the prepaid card. We are currently working on an automated fix as well that will be available soon. We also advise all Wallet users to set up a screen lock as an additional layer of protection for their phone.

http://gizmodo.com/5883913/google-wallet-has-been-hacked-again-now-you-should-panic
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Google Wallet Hacked Again, Now You Should Panic (Original Post) pokerfan Feb 2012 OP
And yet more reasons I'm glad I have a "dumb" phone. Angleae Feb 2012 #1
Same here. hobbit709 Feb 2012 #2
Moi aussi! TygrBright Feb 2012 #3
Me too pokerfan Feb 2012 #5
Thank you for alerting people. One other thing that is so scary about all this: truedelphi Feb 2012 #4
I trust the cloud... discntnt_irny_srcsm Feb 2012 #6
Google Wallet security issue fixed; PIN codes still at risk? douglas9 Feb 2012 #7

pokerfan

(27,677 posts)
5. Me too
Sat Feb 11, 2012, 07:15 PM
Feb 2012

You can do a lot with a "dumb" phone provided you have sms. Text your query to 466453 (GOOGLE) and they'll text back your results. For example:

truedelphi

(32,324 posts)
4. Thank you for alerting people. One other thing that is so scary about all this:
Sat Feb 11, 2012, 06:10 PM
Feb 2012

Google stands with an entourage of companies that want us to put EVERYTHING into the Cloud.

The continual refrain these days is: "Cloud is good. Put your data on the cloud. It is good for you! And everyone will be doing it, so get a head start on them!"

If they cannot guarantee the simple accomplishment for something like total security for an app, Gawdess help us all ten years from now when EVERYTHING is in the cloud.

One thing I will guarantee - I will be the last computer user on Earth that uses the Cloud!

discntnt_irny_srcsm

(18,479 posts)
6. I trust the cloud...
Sun Feb 12, 2012, 01:50 PM
Feb 2012

...as long as I own the cloud. I have my own. I bought 2 NAS boxes and a built a WHS system. My home network is accessible from the internet via a dynamic dns.

douglas9

(4,358 posts)
7. Google Wallet security issue fixed; PIN codes still at risk?
Thu Feb 16, 2012, 06:13 AM
Feb 2012

On Saturday, Google announced that it was temporarily shutting down the use of prepaid credit cards for its Android-based Google Wallet payment service. At the time, Google said it had discovered a flaw in the system that would have allowed the "unauthorized use of an existing prepaid card balance if someone recovered a lost phone without a screen lock."

Late on Tuesday, Google announced that Google Wallet can once again use new prepaid credit cards thanks to the company fixing the security flaw. The post stated:

While we’re not aware of any abuse of prepaid cards or the Wallet PIN resulting from these recent reports, we took this step as a precaution to ensure the security of our Wallet customers.

Google had come under some fire from users after a research report from Zvelo claimed last week that Google Wallet's PIN codes could be cracked via brute force methods. However, both Zvelo and Google stated this method would work only on Android-based smartphones that had been rooted. Google has also stated publicly that it strongly discourages using Google Wallet on rooted Android phones.


http://www.neowin.net/news/google-wallet-security-issue-fixed-pin-numbers-still-at-risk

Latest Discussions»Help & Search»Computer Help and Support»Google Wallet Hacked Agai...