Security hounds over at zvelo have discovered a vulnerability in Google Wallet that means your precious PIN can be “easily revealed.” Digging through the app’s code and using Google’s open resources to reveal its contents, they uncovered a piratical treasure trove of data: unique user IDs, Google account information, and the PIN stored as a SHA256 hex-encoded string. Since this string is known to carry four digits, it only takes a “trivial” brute-force attack involving a maximum of 10,000 calculations to decode it. To prove their point, the researchers made a Wallet Cracker app — demoed after the break — that does the job quicker than you can say “unexpected overdraft.”
Google has been receptive to these findings, but its attempts at a fix have so far been hampered by the need to coordinate with the banks, since changing the way the PIN is stored could also change which agency is responsible for its security. In the meantime, zvelo advises that there are some measures users can take themselves, aside from putting a protective hand over their pockets: refrain from rooting your phone, enable your lock screen, disable USB debugging, enable Full Disk Encryption and keep your handset up-to-date.
Related posts:















April 8, 2012: Nokia’s free color 710 covers are amazing every day, during April at least
April 8, 2012: Nokia takes over Times Square for Lumia 900 launch event
April 8, 2012: Origin PC EON15-S and EON17-S gaming laptops available now, priced from $1,525
April 8, 2012: Max Payne to rampage on iOS April 12th, Android April 26th
April 8, 2012: Legal Loophole May Pave Way For Private Ownership Of Outer Space
April 8, 2012: Brand Name Goes Generic: Apple’s ‘iPad’ Is The Only Tablet People Know
April 8, 2012: Biswamohan Pani, Ex-Intel Employee Pleads Guilty To Theft Charges
April 8, 2012: Sheryl Sandberg: ‘There’s No Such Thing As Work-Life Balance’
April 8, 2012: AT&T Workers: Contracts Expire Tonight For 40,000 Employees, Strike Could Follow
April 8, 2012: Utah Medicaid Cyberattack Affected 25,000 Social Security Numbers
April 7, 2012: RIM confirms departures of two top BlackBerry, BBM execs
April 7, 2012: Samsung’s Galaxy Tab 2 (10.1-inch) priced at $399, still unavailable for purchase
April 7, 2012: Comcast confirms full HBO Go access on Xbox 360 coming next week
April 7, 2012: IMDb updates Android app, now lets you watch 720p trailers
April 7, 2012: ‘Leaked’ Nokia Lumia PureView concept images brandish bright colors, chunky profile
April 7, 2012: Instagram for Android update adds support for tablets, WiFi handsets and SD card installs
April 7, 2012: Google updates Gmail’s ‘people widget,’ now includes previous images
April 7, 2012: TextSpresso machine brews caffeinated goodness via text messaging
Recent Comments