Blogger exposes major Google Wallet security flaw

If you took one look at Google Wallet and said to yourself, "There's no way that's completely secure," it turns out you were right.

The Smartphone Champ blog Thursday publicized a major security flaw within Google Wallet that can give hackers access to your Google Prepaid Card through the simple act of resetting your PIN. The blog discovered the flaw when it noticed that the Google Wallet Prepaid Card is not connected to a user's Google account, but rather, to the user's device.

GOOGLE REED-ER: More Google Wallet follies

ANALYSIS: Google Wallet -- 5 things you need to know

So let's say a hacker steals your phone and clears the data on your Google Wallet application. When the hacker then logs back into the application they'll be prompted to enter a new PIN and assign a Google account to the application. But instead of having to enter their own Google Prepaid Card onto the device, they'll have access to the card that the phone's original user had already placed on the phone.

"Google Prepaid account is not tied to your Google account, it's actually tied to your device, which is why if you change devices you actually have to call Money Network to have your balance moved over to the new device," noted Smartphone Champ blogger Hashim in his video demonstrating the flaw. "I don't know why Google set it this way but that's a pretty big security hole."

Google says that it is aware of the flaw and is currently working on "an automated fix that will be available soon." In an email to the Android and Me blog, the company also wrote that it recommended that "anyone who loses or wants to sell their phone to call Google Wallet support toll-free at 855-492-5538 to disable the prepaid card."

Google Wallet, announced in spring 2011, utilizes near-field communications technology to send very short-range signals to nearby NFC tags to complete payments -- or as Google tells it, you'll only have to tap your smartphone on a store's credit card processor and you're good to go. Google debuted the application on the Sprint network with the Nexus S 4G device and the company has said that the app should come to other Android-based devices on other wireless networks in the near future.

NFC payments have become a hot feature on smartphones ever since Google first enabled NFC technology on its Android operating system with the Android 2.3 ("Gingerbread") update last year. Online payment company PayPal has also developed an NFC-based mobile payment application that runs on the Google Nexus S smartphone.

Read more about anti-malware in Network World's Anti-malware section.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Follow our new CSO Australia LinkedIn
Follow our new social and we'll keep you in the loop for exclusive events and all things security!
Have an opinion on security? Want to have your articles published on CSO? Please contact CSO Content Manager for our guidelines.

More about GoogleNFCPayPalSprint

Show Comments

Featured Whitepapers

Editor's Recommendations

Brand Page

Stories by Brad Reed

Latest Videos

More videos

Blog Posts