Google Pay -- is it safe?

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
When I go to pay for something online by credit card, Google Chrome wants to fill in my credit card details for me, leaving blank only the CVV number. This is called Gpay, or Google pay.
Is it safe? If not, how do I get rid of it? I could tell Chrome not to fill it in, but it still knows the info, even after I deleted autofill memory. It seems to be pulling the info straight from my Google account, rather than storing it in browser memory.
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Go to Redirecting... then go to payment methods and remove your card.
But I am not convinced there is a significant security risk involved with Gpay, because as far as I can tell, the data is not stored in the user's browser, it is only in the Google servers which are maintained with high security standards.
 

Threadripper

Level 9
Verified
Well-known
Feb 24, 2019
408
Apple Pay works by using generated info stored in The Secure Enclave on your device so you can pay in stores and on the web in a way where the info payment processors receive is useless should they be be breached. Minus the hardware security part, doesn't Google Pay work like this?
It is only in the Google servers which are maintained with high security standards.
Google stored some passwords in plain text for fourteen years
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Apple Pay works by using generated info stored in The Secure Enclave on your device so you can pay in stores and on the web in a way where the info payment processors receive is useless should they be be breached. Minus the hardware security part, doesn't Google Pay work like this?

Google stored some passwords in plain text for fourteen years
That password issue was not the same as Gpay, but I must admit that I don't quite know how Gpay works, or even if Google is willing to divulge the info. I assume that the data is not stored in the browser or locally because it survives even after wiping all local data and browser data.
 

Threadripper

Level 9
Verified
Well-known
Feb 24, 2019
408
That password issue was not the same as Gpay, but I must admit that I don't quite know how Gpay works, or even if Google is willing to divulge the info. I assume that the data is not stored in the browser or locally because it survives even after wiping all local data and browser data.
I was just saying that Google's "high security standards" aren't as high as you may think, and that issue was only resolved this year after 14 years. Is this not where you need to go to disable it? Very interesting that you didn't explicitly allow this, did you just save your card details in Chrome?
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I was just saying that Google's "high security standards" aren't as high as you may think
Good point.
Is this not where you need to go to disable it? Very interesting that you didn't explicitly allow this, did you just save your card details in Chrome?
For some reason, that link just takes me to a page with a history of my Gpay payments.

I am the manager of a certain Google Drive account with 100GB, it holds an audio library of a certain speaker, and I pay for it monthly, automatically. Once Google got those credit card credentials from me, I started seeing Gpay pop up whenever I pay online by credit card, since the browser is signed in to my Google account. This is a default setting in Chrome, but can be disabled. I never ever saved my credit card credentials in Chrome itself, all I did was set up a monthly payment plan for Google Drive.
 

Threadripper

Level 9
Verified
Well-known
Feb 24, 2019
408
Good point.

For some reason, that link just takes me to a page with a history of my Gpay payments.

I am the manager of a certain Google Drive account with 100GB, it holds an audio library of a certain speaker, and I pay for it monthly, automatically. Once Google got those credit card credentials from me, I started seeing Gpay pop up whenever I pay online by credit card, since the browser is signed in to my Google account. This is a default setting in Chrome, but can be disabled. I never ever saved my credit card credentials in Chrome itself, all I did was set up a monthly payment plan for Google Drive.
That's shady, like really shady... That'd make me run away from Google like my ass was on fire. But I already did that two years ago.
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
That's shady, like really shady... That'd make me run away from Google like my ass was on fire. But I already did that two years ago.
They seem to think that they own their users. Truth is, I am sure that the vast majority of people only see the pure convenience in it. It is an awesome convenience. My password manager never seems to fill in the credit card details right, but Gpay gets it right every time. I kind of doubt that most people see much more in it than that.
 
Last edited:

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Turn it off in Chrome
chrome://settings/payments

You can also remove Payments from Play Store or from Google Pay website
https://play.google.com/store/paymentmethods
https://pay.google.com/payments/u/0/home#paymentMethods

Yes, both links are safe.

Edit: I think it would be obvious that signing up to Google One / Drive storage would automatically allow Google to store your payment / billing details for an future payments.
 
Last edited:

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I think it would be obvious that signing up to Google One / Drive storage would automatically allow Google to store your payment / billing details for an future payments.
True. It doesn't bother me that they stored my payment details, as there is no other way they could charge me monthly. I was just a bit surprised when I saw my credit card credentials being leveraged for purchases having nothing at all to do with my Google account.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top