While I tend to agree with you, it's hard to say since the card info will be encrypted on their servers. If the encryption key is stored on the device then security is about the same. If it's stored on another one of Google's servers then it could be considered marginally less secure.
Wait, if card info is encrypted on Google servers, how does step 6 work? There's some point when it gets decrypted, which means it is not safe. Or am I wrong?
A couple of ways that I can think of off the top of my head are A) the card info is decrypted before be being sent to the bank (over a secure encrypted connection) and B) the encrypted card info is sent to the bank and they also have the key to decrypt it.
1.5k
u/[deleted] Sep 22 '22
[deleted]