Blogger exposes major Google Wallet security flaw

If you took one look at Google Wallet and said to yourself, "There's no way that's completely secure," it turns out you were right.

The Smartphone Champ blog Thursday publicized a major security flaw within Google Wallet that can give hackers access to your Google Prepaid Card through the simple act of resetting your PIN. The blog discovered the flaw when it noticed that the Google Wallet Prepaid Card is not connected to a user's Google account, but rather, to the user's device.

GOOGLE REED-ER: More Google Wallet follies

ANALYSIS: Google Wallet -- 5 things you need to know

So let's say a hacker steals your phone and clears the data on your Google Wallet application. When the hacker then logs back into the application they'll be prompted to enter a new PIN and assign a Google account to the application. But instead of having to enter their own Google Prepaid Card onto the device, they'll have access to the card that the phone's original user had already placed on the phone.

"Google Prepaid account is not tied to your Google account, it's actually tied to your device, which is why if you change devices you actually have to call Money Network to have your balance moved over to the new device," noted Smartphone Champ blogger Hashim in his video demonstrating the flaw. "I don't know why Google set it this way but that's a pretty big security hole."

Google says that it is aware of the flaw and is currently working on "an automated fix that will be available soon." In an email to the Android and Me blog, the company also wrote that it recommended that "anyone who loses or wants to sell their phone to call Google Wallet support toll-free at 855-492-5538 to disable the prepaid card."

Google Wallet, announced in spring 2011, utilizes near-field communications technology to send very short-range signals to nearby NFC tags to complete payments -- or as Google tells it, you'll only have to tap your smartphone on a store's credit card processor and you're good to go. Google debuted the application on the Sprint network with the Nexus S 4G device and the company has said that the app should come to other Android-based devices on other wireless networks in the near future.

NFC payments have become a hot feature on smartphones ever since Google first enabled NFC technology on its Android operating system with the Android 2.3 ("Gingerbread") update last year. Online payment company PayPal has also developed an NFC-based mobile payment application that runs on the Google Nexus S smartphone.

Read more about anti-malware in Network World's Anti-malware section.

Show Comments