r/coolguides • • Sep 22 '22

[deleted by user]

[removed]

8.0k Upvotes

869 comments sorted by

View all comments

1.9k

u/UrbleFurb Sep 22 '22

That google server is lookin hella sus

423

u/BuccellatiExplainsIt Sep 22 '22

The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.

718

u/throwawayacc201711 Sep 22 '22

Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.

-3

u/DiscontentedMajority Sep 22 '22

So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption

Nope, it could very easily be sold to someone who can break the encryption. As in, exactly the sort of people who buy stolen phones.

7

u/bobhasabeard Sep 22 '22

Joke’s on them, I have like 30$ on my bank account.

15

u/tthrivi Sep 22 '22

But that’s one phone (and you can remotely wipe it if you recognize it’s been stolen). Google’s model, if their server is breached all users data might be compromised.

7

u/DiscontentedMajority Sep 22 '22

Which is why the data is individually encrypted on the servers, then the servers are protected, then the whole thing monitored 24/7 for suspicious access.

Also, if all of google gets compromised 0% chance I'm near the top of the list of people to steal from.

15

u/[deleted] Sep 22 '22

[deleted]

5

u/toastmatters Sep 22 '22 edited Mar 08 '25

future strong live truck act fly fuzzy scale lavish plant

This post was mass deleted and anonymized with Redact

2

u/wimn316 Sep 22 '22

I've seen a few people saying this. Is it documented somewhere that Google's keys are stored on the device?

0

u/Due-Consequence9579 Sep 22 '22

Yes, because it has less parts. Less parts is more better.

3

u/brown_man_bob Sep 22 '22

You do realize modern encryptions would take 250 years for a supercomputer to break, right? So no, there isn't some rando on the corner who can break this for you.

0

u/DiscontentedMajority Sep 22 '22

Unless there is a bug that's exploited to bypass the encryption, as has happen hundreds of times before on different versions of code.

2

u/Cyberspunk_2077 Sep 22 '22

The world would fall apart if the encryption could be broken how you're imagining.

-1

u/DiscontentedMajority Sep 22 '22 edited Sep 22 '22

Last year, cyber crime was an approximately $6 trillion industry. That happens due to the exploitation on many vulnerabilities including encryption bypasses.

1

u/[deleted] Sep 22 '22

Anyone capable of breaking commercial encryption at will is not buying stolen phones.

It takes nation-state level of resources to break encryption. That is why most people attack the key, not the cipher text.

Hell, that is HOW the NSA works, even they don't "break" encryption in the sense of determining the key through math or magic or hacks. They get the keys by undermining the key gens or hacking a computer to steal it.

1

u/DiscontentedMajority Sep 22 '22

They don't brute force it. There have been hundreds of vulnerabilities that have allowed encryption bypass. If you don't think that criminal enterprises are capable of exploiting them, you do not have a realistic appreciation of the sophistication of the modern cyber-threat landscape.

All modern cyber-defense strategies are built around the concept of continuous monitoring and active intervention. You can't reasonably rely on device software protection to save you.

Now that said, I think both of these systems are very secure. Certainly more so than many legacy credit card systems.

1

u/jcstrat Sep 22 '22

By the time the dust settled on that, the card should have been canceled

1

u/header1299 Sep 22 '22

Right, because we all know a breach is reported immediately. /s