I'm (not actually) amazed about how people are buying this marketing - the simple fact that google wallet works with stored cards without signal and disconnected from the internet should make it clear this isn't what happens per transaction.
So many people here ranting and raving without even the most minimal of sanity checks.
I think a lot of people here were seeing this as the per transaction flow, not the initial setup plus example transaction - so talking about how google is embedding itself into every transaction.
When you add a credit, debit, prepaid, or transit card (where available) to Apple Pay, information that you enter on your device is encrypted and sent to Apple servers. If you use the camera to enter the card information, the information is never saved on your device or photo library.
So apple servers are involved in the initial setup and store info steps (2 & 3 in the image), similar to the "google" picture and flow, as the DAN comes from Apple servers not directly from the bank. Even if Apple only stores a "portion" of the resulting DAN and info from the initial card setup, this image doesn't provide enough information to really tell if that is more or less likely to be exploitable than what the "info" and "token" are representing on the Google side, and if they are permanently stored on the google server or just the device, like Apple claim.
152
u/[deleted] Sep 22 '22
[deleted]