Lemmy.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
ijeff@lemdro.idM to Android@lemdro.idEnglish · 2 years ago

Android loophole exposes credit card details via NFC

9to5google.com

external-link
message-square
26
link
fedilink
  • cross-posted to:
  • [email protected]
176
external-link

Android loophole exposes credit card details via NFC

9to5google.com

ijeff@lemdro.idM to Android@lemdro.idEnglish · 2 years ago
message-square
26
link
fedilink
  • cross-posted to:
  • [email protected]
Android loophole allows Google Wallet to leak credit card details via NFC, fix coming
9to5google.com
external-link
A loophole in Android allows a niche scenario to leak credit card details via an NFC reader even when the phone is locked.

GitHub: https://github.com/MrTiz/CVE-2023-35671

  • thisbenzingring@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    2
    ·
    2 years ago

    Turn off NFC unless you are using it at that moment.

    • Potatos_are_not_friends@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 years ago

      Woah, first I learned of this. https://www.lifewire.com/turn-off-nfc-to-secure-your-android-smartphone-2532822

      Kinda sucks that there’s no quick button for that. I can turn off Bluetooth, wireless, auto-rotate, etc in a single setting but not NFC?

      • newIdentity@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        23
        arrow-down
        1
        ·
        2 years ago

        Screenshot_20230914-163449~2

        • Potatos_are_not_friends@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 years ago

          I’m so envious of you. I don’t have that.

          • dan1101@lemm.ee
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 years ago

            I don’t have NFC at all. Ultimate safety.

          • newIdentity@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            Sad

        • Nemo Wuming@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          Which system do you have, with the NFC quick toggle?

          • newIdentity@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            1
            ·
            edit-2
            2 years ago

            Pixel 4a w. GrapheneOS, but I’m pretty sure I had that too on the stock ROM

            Edit: OK, WTF. Apparently I misremember it or I actually had a version with that toggle. Some say it has been removed and some say it never was there in the first place. I know that you can’t really rely on memory, but I could swear it was there on Android 10 or 11

            • Nemo Wuming@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 years ago

              I have a pixel 7 with android 13 and the NFC toggle is not on the quick buttons

              • newIdentity@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 years ago

                Apparently they removed it or it never was there in the first place on AOSP

            • DeltaTangoLima@reddrefuge.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 years ago

              P7P with Android 13, I don’t have it. Wonder why it was removed…

              • scottywh@lemmy.world
                link
                fedilink
                English
                arrow-up
                3
                ·
                2 years ago

                I have it on Android 13 on my Motorola.

            • Nemo Wuming@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 years ago

              I can confirm it’s there on Galaxy S7 with Android 8

      • Kaliax@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 years ago

        Many Samsung devices have a quick button for NFC toggling in their drop down menu, not sure about other phones though.

        • Pxtl
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          I have a Samsung Galaxy Watch, it has a button for that too. But also the Wallet app on the watch has to be manually opened to use it anyways, it’s not passive background app. I think I might just disable NFC on my phone and stick to using my watch for payments.

      • evident5051@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 years ago

        You can try using Tasker to create a task that turns on NFC and launches Google Wallet / Pay afterwards.

        After that, create another profile to turn off NFC when the screen is locked.

      • Arda@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 years ago

        You can diasble all sensors and make a quick button for it in dev settings, dont remember how exactly it is called tho

      • newIdentity@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        2 years ago

        deleted by creator

Android@lemdro.id

android@lemdro.id

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: [email protected]


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it’s in violation of the rules.


Support, technical, or app related questions belong in: [email protected]

For fresh communities, lemmy apps, and instance updates: [email protected]

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to [email protected].

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to [email protected].

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it’s not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website’s name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don’t post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
Lemmy App List
  • See thread
Chat and More
  • Android Chat
  • Lemdro.id Chat
  • Mods Chat
  • Lemdro.id Admin Chat
  • Reddit

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 168 users / day
  • 1.17K users / week
  • 2.88K users / month
  • 6.78K users / 6 months
  • 459 local subscribers
  • 19.2K subscribers
  • 3.33K Posts
  • 38.4K Comments
  • Modlog
  • mods:
  • ijeff@lemdro.id
  • ladfrombrad 🇬🇧@lemdro.id
  • multimoon@lemdro.id
  • Paradox@lemdro.id
  • Mike Stevens 🇦🇺 S23U@lemdro.id
  • Devgard@lemmy.world
  • limerod@reddthat.com
  • Netrunner@lemdro.id
  • UI: 0.19.11
  • BE: 0.19.11-n.1
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org