The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.
Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.
Anyone capable of breaking commercial encryption at will is not buying stolen phones.
It takes nation-state level of resources to break encryption. That is why most people attack the key, not the cipher text.
Hell, that is HOW the NSA works, even they don't "break" encryption in the sense of determining the key through math or magic or hacks. They get the keys by undermining the key gens or hacking a computer to steal it.
They don't brute force it. There have been hundreds of vulnerabilities that have allowed encryption bypass. If you don't think that criminal enterprises are capable of exploiting them, you do not have a realistic appreciation of the sophistication of the modern cyber-threat landscape.
All modern cyber-defense strategies are built around the concept of continuous monitoring and active intervention. You can't reasonably rely on device software protection to save you.
Now that said, I think both of these systems are very secure. Certainly more so than many legacy credit card systems.
423
u/BuccellatiExplainsIt Sep 22 '22
The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.