• Home
  • Reviews
  • Featured
  • Archives
  • Videos
  • Devices
  • Tegra
  • Send Tips
  • Contact
  • AndroidCommunity on Twitter AndroidCommunity on Facebook AndroidCommunity on Google+ AndroidCommunity RSS Feed

Android Community

    • MUST READ

      STORIES

    • Intel-powered Galaxy Tab 3 leaked in benchmarks

      May 21, 2013

    • Samsung Galaxy Note 3 with Android 4.3 spotted in benchmark results

      May 21, 2013

    • Verizon HTC One running Android 4.2.2 could be coming soon

      May 21, 2013

  • Trending Topics
  • Jelly Bean
  • NVIDIA
  • Galaxy S 4
  • HTC One
  • Nexus 7
  • Sell Your Used Phone

Google Wallet now displays warnings for rooted phones

5
  • By Michael Crider
  • on 5 Mar, 2012

Google Wallet now displays warnings for rooted phones

Oh boy. After taking considerable heat from the privacy and security community over cracks in Google Wallet, the company updated the NFC payment app to close a security loophole. That apparently didn’t do anything to close the vulnerability for rooted devices, discovered in February. Instead of address the problem for rooted phones, Google seems to be sticking by its recommendation the rooted users not install Google Wallet. In a fit of expediency, they’re making sure that root users know their position: Google Wallet now displays an “unsupported device” warning message when run on a rooted phone.

Tap the link in the warning message, and you get a brief explanation of the root vulnerability and Google’s strong admonition that you avoid using the app on your phone. It’s pretty good advice, too: given a set of admittedly unlikely circumstances, it’s possible that a thief could gain access to all of the funds stored in your Google Wallet account. Granted, said thief would have to know that you had the app, understand the nature of rooted Android and then find and execute the exploit, but hey – better safe than sorry.

Some may take exception with Google’s approach, insisting that they have a responsibility to support all Android users. We respectfully disagree. When you root your Android phone or tablet, you’re taking control of the software away from Google, the manufacturer and the carrier – at that point, you take the responsibility as well. Though Android doesn’t come with any explicit or implicit warranty, and neither does Google Wallet, you can consider yourself warned at this point. If you don’t feel safe using Google Wallet, pull out your real one and pay the old-fashioned way.

Story Timeline

  • Google Wallet PIN can be compromised on rooted Android devices
  • Google responds to Wallet root vulnerability: don't use Google Wallet
  • Surprise: you don't need root to break into Google Wallet after all
  • Google has disabled use of your prepaid card via Google Wallet
  • Google pushes security fixes for Wallet, Google+, and Authenticator
[via Droid-Life]
Share
  • Student wins science fair with 30-second phone battery charger
  • Verizon HTC One reality returns as DROID DNA offer pops up
  • Hisense Sero 7 Pro with Tegra 3, Android 4.2 takes on Google's Nexus 7

Tags: GoogleGoogle Walletrootsecurity

  • http://www.facebook.com/sameersingh17 Sameer Singh

    At least they didn’t disable it for our rooted brethren.

    http://www.tech-thoughts.net/ 

  • Peter_redding

    rooted??? FUNNY SAYING  my last phone was rooted so i got a nexus

  • us1776

    Google needs to fix its security holes.  Not just say to rooted users, use at your own risk.

    Eventually someone is going to figure out how to exploit this security hole on non-rooted phones as well.

    Half of Nexus community is rooted phones.  Google needs to do a better job.

    • Sam Duke

      you should really go and read up on how google wallet works. by rooting your phone you are (potentially) undoing all the security that the operating system has built in. The secure element on your phone provides a trusted execution environment when making transactions, BUT there has to be some communication down from applications to this device to pass user authorization (e.g. pins). This is restricted firstly by an APK gaining the appropriate permission, AND by a ‘whitelist’ file of applications that are allowed to acquire this permission. On a rooted phone, a nefarious APK could come and change this whitelist file and so start to do evil things.

      Google’s main line of defence and what it should be (and is) working on, therefore, should be stopping the kind of loopholes that give applications Root without the user’s knowledge. Obviously most people who root use something like superuser, which allows people to grant/deny access to root. BUT google has no control over this, hence the warning in the wallet application.

  • http://www.facebook.com/kg4zxk Keith Ainsley

    It is disabled. I could not use it last night.

  • Search

  • REVIEWS

    • AT&T LG Optimus G Pro ReviewAT&T LG Optimus G Pro Review
    • Iron Man 3 game Review: what you need to knowIron Man 3 game Review: what you need to know
    • Samsung GALAXY S 4 ReviewSamsung GALAXY S 4 Review
    • Samsung Galaxy Note 8.0 ReviewSamsung Galaxy Note 8.0 Review
    • Pebble review: Two weeks with a smartwatchPebble review: Two weeks with a smartwatch
  • HANDS-ON & QUICK LOOKS

    • Opera for Android exits beta, we go hands onOpera for Android exits beta, we go hands on
    • NVIDIA Tegra 4i demos i500 LTE modem on Cat 4: 150Mbps of speedNVIDIA Tegra 4i demos i500 LTE modem on Cat 4: 150Mbps of speed
    • HP Slatebook x2 Tablet hands-onHP Slatebook x2 Tablet hands-on


  • T-Mobile G1 Accessories
  • RECENT COMMENTS

  • About
  • Contact
  • Terms of Use
  • Privacy Policy
  • Advertise

Copyright 2013 Android Community