日批在线视频_内射毛片内射国产夫妻_亚洲三级小视频_在线观看亚洲大片短视频_女性向h片资源在线观看_亚洲最大网

USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 久久久久久中文字幕 | 人人插插 | 特黄特色大片免费播放器使用方法 | 最新国产在线视频 | 日韩激情网址 | 欧美精品aaa| 久久综合影视 | 麻豆av免费 | 久久国产高清视频 | 日本在线一级片 | 欧美日韩视频在线 | www日本视频| 成人午夜小视频 | 岛国精品在线播放 | 中文字幕视频免费 | 日本国产在线视频 | 欧美三级一区 | 亚洲成人免费看 | 国产中文字幕视频 | 中文字幕在线视频免费观看 | 一区二区三区免费在线视频 | 欧美日韩精品久久久 | 欧美顶级毛片在线播放 | 中文字幕视频免费 | 手机看片国产日韩 | jizz日本在线 | 久久婷婷网 | 日本黄色免费在线观看 | 韩国舌吻呻吟激吻原声 | 四虎永久免费网站 | 亚洲美女视频在线 | 欧美精品免费一区二区三区 | 亚洲天堂午夜 | 99精品欧美一区二区三区综合在线 | 自拍偷拍第八页 | 免费在线观看av的网站 | 国产在线中文字幕 | 久久草网站 | 成人国产精品一区二区 | 国产a精品| 看av在线|