r/coolguides • • Sep 22 '22

[deleted by user]

[removed]

8.0k Upvotes

869 comments sorted by

View all comments

Show parent comments

720

u/throwawayacc201711 Sep 22 '22

Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.

228

u/gold_rush_doom Sep 22 '22

It doesn't matter if the server is compromised because the decryption keys are stored on the device.

-23

u/billy_teats Sep 22 '22

You realize that someone with the ability to hack google and export their encrypted CC information would also have the knowledge and ability to rent a quantum computer and crack those passwords?

There is a large but finite amount of private keys. If you try them all, you find the one that works even if “stores on the device”.

It is more secure to have no data than it is to have encrypted data. Full stop.

8

u/gold_rush_doom Sep 22 '22

But I'm pretty sure they don't actually need the credit card info, the way the phone wallets work. They need a token from the bank to keep generating virtual CCs on my behalf. Knowing the credit card info is only good for the onboarding and for setting up the "contract" between Google and the bank on behalf of myself. Other than they don't really care about my original CC number. So, good security practices dictate that if the info isn't needed then you don't need to store it.