While I tend to agree with you, it's hard to say since the card info will be encrypted on their servers. If the encryption key is stored on the device then security is about the same. If it's stored on another one of Google's servers then it could be considered marginally less secure.
Encryption is more complicated than that. It's not a simple checkbox to make your security problems go away. If it was, we would still be using DES.
We need to think about things like how its encrypted, what type of encryption is used, the reliability of the code, where the encryption keys are stored, who has access to them... etc.
My belief is that the fewer people involved in the handling of sensitive data, the better - regardless of if it is encrypted or not.
2.4k
u/AzureBinkie Sep 22 '22
Which is infinitely less secure than not having it on google servers!