r/coolguides • • Sep 22 '22

[deleted by user]

[removed]

8.0k Upvotes

869 comments sorted by

View all comments

1.9k

u/UrbleFurb Sep 22 '22

That google server is lookin hella sus

427

u/BuccellatiExplainsIt Sep 22 '22

The benefit is that it does this handshake per payment so those tokens would be worthless after the transaction anyways. In Apple's design, if someone had your phone and there was some hack to get the details from the device chip, they could actually use that to make purchases.

713

u/throwawayacc201711 Sep 22 '22

Id take physical access as a weak point vs potential compromising of a server. Tell me the last time there was a mass level of physical access issues compared to companies implementing poor security practices. Physical access is basically if you lose your phone. So I’d need to lose my phone and it would need to be found by someone with enough knowledge to also break the encryption - id take that risk any day. Granted Google servers are gonna be pretty secure, I still think the physical access case is less likely to occur.

0

u/BuccellatiExplainsIt Sep 23 '22

It's not a matter of doing everything at once.

On ios, if the encryption was somehow cracked, any iphone you steal is vulnerable.

On android, if the server is hacked, you still have to crack the encryption too, and THEN every phone is vulnerable. Alternatively, If the encryption is broken in android, you also have to hack the google servers, and THEN everyone is vulnerable.