Hm, I thought I’d used Google Pay from my Pixel Watch without any service-is it possible Google Pay uses a secure element on supported hardware, and falls back to the token-based method on other hardware?
@jonaharagon
Жыл бұрын
How Google Pay CAN work offline despite being reliant on Google cloud servers #googlepay
@jonaharagon
Жыл бұрын
This is great feedback, thank you. No, but I did end up looking a lot further into this and I should've covered how offline payments *do* work in Google Pay. If you use a card which supports offline payments in Google Pay, Google will issue your device a handful of pre-authorized one-time use tokens which can be used at any time, allowing you to make a certain number of payments without an internet connection. This is still very different than the way that Apple Wallet works-which can generate payment tokens directly on-device-because you still need to connect to Google periodically to refresh your local cache of tokens. Definitely something I should've covered in the video, but ultimately it doesn't make a significant difference in the privacy or security of the product, it just means that your device will have to check in with Google at some arbitrary time in the future rather than exactly when the transaction is taking place. Hope that clears things up :)
@27370
Жыл бұрын
Incredibly informative and succinct. Great video.
@JayVera-j8k
11 ай бұрын
Hi Jonah! Great video! Question for you: do you know what exactly is provided to the merchant? I know it hides card numbers but if the cardholder name is provided to the merchant like a regular credit card do then it defeats the purpose. Also, what about any hardware identifiers? Does the NFC have any? One tip for others: if you remove and add the card on Apple Pay again you get assigned a different card number. I do this every month or so.
@marshahallinfosec
Жыл бұрын
Speaking of financial security, I recently moved most of my savings from an index fund with an online investment firm to a brick and mortar savings account, because I wasn’t confident in the security of the online firm. However, the interest rate of the savings account is obviously pretty low, so this doesn’t seem like a good permanent solution. Do you have any suggestions for online investment firms that take security seriously, or that are at least above average?
@jonaharagon
Жыл бұрын
Are there any investment firms that take security seriously? #finance #security #cybersecurity
Пікірлер: 9