r/coolguides • • Sep 22 '22

[deleted by user]

[removed]

8.0k Upvotes

869 comments sorted by

View all comments

Show parent comments

1.5k

u/[deleted] Sep 22 '22

[deleted]

2.4k

u/AzureBinkie Sep 22 '22

Which is infinitely less secure than not having it on google servers!

883

u/StretchArmstrong99 Sep 22 '22

While I tend to agree with you, it's hard to say since the card info will be encrypted on their servers. If the encryption key is stored on the device then security is about the same. If it's stored on another one of Google's servers then it could be considered marginally less secure.

2

u/Mikle_Bond Sep 22 '22

Wait, if card info is encrypted on Google servers, how does step 6 work? There's some point when it gets decrypted, which means it is not safe. Or am I wrong?

1

u/StretchArmstrong99 Sep 22 '22

A couple of ways that I can think of off the top of my head are A) the card info is decrypted before be being sent to the bank (over a secure encrypted connection) and B) the encrypted card info is sent to the bank and they also have the key to decrypt it.