Users of Google smartphone wallets were being warned on Friday that there is a way to crack pass codes intended to thwart thieves from going on illicit shopping sprees.
Zvelo Labs researcher Joshua Rubin was featured in a video on the company’s Web site demonstrating software that quickly figures out a Google Wallet personal identification number (PIN), provided the crook has the smartphone.
Rubin said that Google has been alerted to the vulnerability and is moving swiftly to fix it. He has not made his wallet “cracker” application public.
“Google Wallet allows only five invalid PIN entry attempts before locking the user out,” Rubin said in a blog post. “With this attack, the PIN can be revealed without even a single invalid attempt. This completely negates all of the security of this mobile phone payment system.”
Google declined a request for comment.
“Once attackers get your PIN, they have full access to any credit card information stored in the app and they can use your phone to make purchases,” McAfee security firm researcher Jimmy Shah said in a blog post.
“As a user of Google Wallet, the main security you see is the PIN,” McAfee added. “What makes Wallet easy for you to use now makes it easy for attackers to use; they can now spend your money and credit just as if your phone were an ATM card.”
Rubin dismissed the threat of hackers picking Google Wallets remotely, saying that physical access is needed to get priority access to controls in a process called “rooting.”
Security specialists advise Google Wallet users not to “root” smartphones, and to enable security features such as full-disk encryption and screen locks.
WASHINGTON’S INCENTIVES: The CHIPS Act set aside US$39 billion in direct grants to persuade the world’s top semiconductor companies to make chips on US soil The US plans to award more than US$6 billion to Samsung Electronics Co, helping the chipmaker expand beyond a project in Texas it has already announced, people familiar with the matter said. The money from the 2022 CHIPS and Science Act would be one of several major awards that the US Department of Commerce is expected to announce in the coming weeks, including a grant of more than US$5 billion to Samsung’s rival, Taiwan Semiconductor Manufacturing Co (TSMC, 台積電), people familiar with the plans said. The people spoke on condition of anonymity in advance of the official announcements. The federal funding for
HIGH DEMAND: The firm has strong capabilities of providing key components including liquid cooling technology needed for AI servers, chairman Young Liu said Hon Hai Precision Industry Co (鴻海精密) yesterday revised its revenue outlook for this year to “significant” growth from a “neutral” view forecast five months ago, due to strong demand for artificial intelligence (AI) servers from cloud service providers. Hon Hai, a major assembler of iPhones that is also known as Foxconn, expects AI server revenues to soar more than 40 percent annually this year, chairman Young Liu (劉揚偉) told investors. The robust growth would uplift revenue contribution from AI servers to 40 percent of the company’s overall server revenue this year, from 30 percent last year, Liu said. In the three-year period
LONG HAUL: Largan Energy Materials’ TNO-based lithium-ion batteries are expected to charge in five minutes and last about 20 years, far surpassing conventional technology Largan Precision Co (大立光) has formed a joint venture with the Industrial Technology Research Institute (ITRI, 工研院) to produce fast-charging, long-life lithium-ion batteries for electric vehicles, mobile electronics and electric storage units, the camera lens supplier for Apple Inc’s iPhones said yesterday. Largan Energy Materials Co (萬溢能源材料), established in January, is developing high-energy, fast-charging, long-life lithium-ion batteries using titanium niobium oxide (TNO) anodes, it said. TNO-based batteries can be fully charged in five minutes and have a lifespan of 20 years, a major advantage over the two to four hours of charging time needed for conventional graphite-anode-based batteries, Largan said in a
Taiwan is one of the first countries to benefit from the artificial intelligence (AI) boom, but because that is largely down to a single company it also represents a risk, former Google Taiwan managing director Chien Lee-feng (簡立峰) said at an AI forum in Taipei yesterday. Speaking at the forum on how generative AI can generate possibilities for all walks of life, Chien said Taiwan Semiconductor Manufacturing Co (TSMC, 台積電) — currently among the world’s 10 most-valuable companies due to continued optimism about AI — ensures Taiwan is one of the economies to benefit most from AI. “This is because AI is