Do you HAVE to use a card to buy paid applications?

As long as you are connected via https

Then you are quite safe, there is no human interaction so unless employees of google are crooked (and who is to say they aren't), then you are even safer again.

There are other ways to make yourself even safer still, like use a virtual kb to type in your answers (thus preventing direct keystrokes), if you wish to. Or use the virtual kb to type onto a text file, then use copy & paste to put the info into the https site.

It's not normally the end user that abuses your info, but the unscrupulous types inbetween you & the end user, so keep yourself as safe as you can between you & the recipient (ensuring they are always https) and you will be as secure as you can be.
