Google Pay / GPay has always been quite insecure in my eyes; for being an app that boasts about using the “best security methods” it lacks a system to lock the app.
Banking apps and other payment or sensitive info related apps use PINs, passwords, and biometrics (fingerprint/retina/face scan). Google Pay only requires the user to have the NFC active and a lock screen on your phone (and some reviews even say that the lock screen doesn’t have to be unlocked to pay!). Not only that, but the app has an “on switch” for the NFC, but not an “off switch”!
Meaning that:
- as long as the phone is unlocked (or maybe not), it’s easy for crooks to get to your money: one only needs a capable NFC phone or scanner; contactless frauds are on the rise
- whenever you pay, you show everyone your unlocked phone
- having NFC active for other uses is a liability whenever Google Pay is on your device
Do compatible NFC payment alternatives exist? That requires the app to be actively open and possibly even contain additional security features?