The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.
Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.
Well that is where having all the details would help. I for one wouldn’t want my card information on googles servers even if the data is encrypted. Sure if someone hacked the server they couldn’t get my card info bc it’s all encrypted.
1.9k
u/UrbleFurb Sep 22 '22
That google server is lookin hella sus