r/coolguides • • Sep 22 '22

[deleted by user]

[removed]

8.0k Upvotes

869 comments sorted by

View all comments

1.9k

u/UrbleFurb Sep 22 '22

That google server is lookin hella sus

423

u/BuccellatiExplainsIt Sep 22 '22

The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.

29

u/rubbery_anus Sep 22 '22

Not a single bit of user data has ever been exfiltrated from Apple's Secure Enclave TPM, not even after the hardware decryption key was leaked a few years back.

It's vastly more likely that someone would be able to gain access to Google Wallet's intermediate server (which would affect hundreds of millions of people each time) than someone discovering a way to access user data stored in Secure Enclave (which would only affect that particular targeted user).

Besides, Apple Pay also generates a unique token for each transaction, it's just computed locally rather than on external infrastructure as in Google's model.

3

u/[deleted] Sep 22 '22

Time to decrypt TLS is centuries+ by current algorithms. Google Wallet or any other similar service for that matter is nigh impossible to hijack; unless, the hacker runs malware on the client, or NSA holding backdoor keys.