男女羞羞视频在线观看,国产精品黄色免费,麻豆91在线视频,美女被羞羞免费软件下载,国产的一级片,亚洲熟色妇,天天操夜夜摸,一区二区三区在线电影
USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 大同市| 庆阳市| 浦县| 汉源县| 永善县| 外汇| 察雅县| 云梦县| 敖汉旗| 九龙城区| 黔南| 锡林郭勒盟| 沙田区| 东平县| 遂溪县| 哈巴河县| 肇源县| 肃南| 稷山县| 息烽县| 罗平县| 沂源县| 清河县| 博客| 大足县| 阿合奇县| 凯里市| 平凉市| 辽阳县| 泌阳县| 崇左市| 双桥区| 阿图什市| 海原县| 钟山县| 舒城县| 海林市| 建阳市| 广宁县| 滦平县| 崇仁县| 育儿| 泰兴市| 定边县| 哈密市| 舞钢市| 遂宁市| 惠东县| 盐津县| 皮山县| 澜沧| 佛山市| 丽水市| 西青区| 安龙县| 沐川县| 阳山县| 建瓯市| 灵台县| 阿鲁科尔沁旗| 永宁县| 长春市| 重庆市| 陕西省| 平遥县| 托克托县| 平遥县| 岫岩| 和顺县| 石柱| 越西县| 广汉市| 敖汉旗| 北辰区| 梅河口市| 涞源县| 洮南市| 钟祥市| 宜州市| 灌阳县| 绍兴县| 穆棱市|