Some blogs and online users claim that through this vulnerability it is not possible to make unauthorized payments. This is not true; in fact, if you use a real P.o.S., instead of a #FlipperZero-like device, Google Wallet makes a physical payment. Try it to believe.
@65Stoner Жыл бұрын
Fair play for exposing this
@arili-eo7vw Жыл бұрын
Hope you get some bounty for this 🎉 great work
@Howard_S Жыл бұрын
Just don't leave NFC on by default... As standard practice, I only ever activate it when I'm about to make a payment, and deactivate it afterwards... It's no more trouble than activating wallet... swipe down & tap the wallet shortcut, tap NFC shortcut...
@8yter801 Жыл бұрын
What? I'm unlocking my phone and that's it. Never did all the steps you described.
@davidrios2419 Жыл бұрын
Good job!
@Trekeyus Жыл бұрын
It's a good thing Google pay generates virtual cards
@ovios Жыл бұрын
What about the virtual account number that Google wallet uses as it says in the settings, it clearly states that Google wallet doesn't share the actual account number with the merchant but the virtual account number
@pierpaoloirmici7209 Жыл бұрын
that's right. During a payment transaction google wallet shares the token number, which is a fake PAN number, not the actual funding PAN of the card. You can't do anything with that
@mehere3013 Жыл бұрын
they would need to have your phone or be close to read it
@beduvas Жыл бұрын
Darth Vader shares his knowledge!
@yovtobe6 ай бұрын
Is this a virtual number or the actual card details?
@MartiniComedian Жыл бұрын
Where can I find that NFC toggle widget?
@_MrTiz Жыл бұрын
Forgive me, but I uninstalled it many months ago and can no longer remember which app it was. Unfortunately, I also have a habit of removing apps from the list of uninstalled apps found in the Play Store.
@MartinCaicedo Жыл бұрын
Google wallet Send a virtual account number not the real card number