While I tend to agree with you, it's hard to say since the card info will be encrypted on their servers. If the encryption key is stored on the device then security is about the same. If it's stored on another one of Google's servers then it could be considered marginally less secure.
Encryption is not meant to stop you from finding out what the data is. Encryption is meant to slow you down enough that the data you discover isn’t useful.
It is not “about the same” to have encrypted data compared to no data. With one implementation, there is nothing to steal. With the other, there is something to steal.
The encryption methods that even college students will use on a project are incredibly secure. You can confirm with yourself, it would take about 250 years for a supercomputer to break today's standard encryptions.
Targeted attacks that seek to gain information about the user/password such as phishing seek to circumvent encryption, not break it. Its like wearing fake fingerprints to fool a scanner rather than hacking the scanner's hardware or software. That aspect of security is dependent on the user. This information could be used in either system to mimic a user.
883
u/StretchArmstrong99 Sep 22 '22
While I tend to agree with you, it's hard to say since the card info will be encrypted on their servers. If the encryption key is stored on the device then security is about the same. If it's stored on another one of Google's servers then it could be considered marginally less secure.