• jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    66
    ·
    2 years ago

    I thought Google wallet generated a unique card id for every transaction.

    This is a interesting bug, but I think fairly niche. Not many people use app pinning at all.

    • SuperIce
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 years ago

      If the PoS supports tokens, it’ll use unique tokens for each payment. If the PoS doesn’t support tokens, the phone has a virtual credit card number linked to the real one, so if it does get stolen, you can just remove the card from your Google Wallet to deactivate it. Your real card number is never exposed.

      Even then, credit card numbers on their own aren’t that useful anymore. Any online payment needs the CVC and PoS devices usually require chip or tap cards, which don’t use the number. On top of that, credit card companies have purchase price restrictions when using swipe because of the security risks vs chip (which is why most PoS devices don’t support swipe anymore).

        • Nemo Wuming
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          Which system do you have, with the NFC quick toggle?

          • newIdentity@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            1
            ·
            edit-2
            2 years ago

            Pixel 4a w. GrapheneOS, but I’m pretty sure I had that too on the stock ROM

            Edit: OK, WTF. Apparently I misremember it or I actually had a version with that toggle. Some say it has been removed and some say it never was there in the first place. I know that you can’t really rely on memory, but I could swear it was there on Android 10 or 11

      • Kaliax@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 years ago

        Many Samsung devices have a quick button for NFC toggling in their drop down menu, not sure about other phones though.

        • Pxtl@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          I have a Samsung Galaxy Watch, it has a button for that too. But also the Wallet app on the watch has to be manually opened to use it anyways, it’s not passive background app. I think I might just disable NFC on my phone and stick to using my watch for payments.

      • Arda
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        2 years ago

        You can diasble all sensors and make a quick button for it in dev settings, dont remember how exactly it is called tho

      • evident5051@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 years ago

        You can try using Tasker to create a task that turns on NFC and launches Google Wallet / Pay afterwards.

        After that, create another profile to turn off NFC when the screen is locked.

  • paper_clip@kbin.social
    link
    fedilink
    arrow-up
    7
    ·
    2 years ago

    The loophole seems to be having an app pinned to the screen (I’ve never done this, but it presumably keeps the phone from locking) while requiring you to have an unlocked phone to use NFC payments. This doesn’t seem to be a common scenario (I can imagine doing this in some sort of kiosk mode, or giving the phone to a kid and locking the app so he can’t wander around).

  • hotchocolateman6969
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    7
    ·
    2 years ago

    This is why Samsung pay is king, the NFC only turns on when you’re using Samsung pay otherwise it stays off