日批在线视频_内射毛片内射国产夫妻_亚洲三级小视频_在线观看亚洲大片短视频_女性向h片资源在线观看_亚洲最大网

USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 国产成人在线视频播放 | 亚洲色图综合 | 亚洲日本天堂 | 另类中文字幕 | 国产精品视频网址 | 黄色大片在线免费观看 | 正在播放一区二区 | 久久久久久免费毛片精品 | 91亚洲国产成人精品一区二区三 | 午夜精品久久久久久久蜜桃 | 日本在线播放视频 | 欧日韩一区二区三区 | 久久久影视 | 亚洲精品在线视频 | 久久久久久高清 | 久久精品片 | 成年人免费网站视频 | 福利视频在线免费观看 | 国产精品第十页 | 日本精品视频在线播放 | 欧美日韩中文字幕视频 | 日韩少妇精品 | 在线观看日韩精品 | 男人在线观看视频 | 黑人巨大精品欧美一区二区 | 三级黄色短视频 | 伊人激情综合网 | 男女羞羞网站 | 中文字幕网站在线观看 | jzzijzzij亚洲成熟少妇 | 色咪咪网站 | 欧美成人免费在线 | 97久久久 | 久久精品国产77777蜜臀 | 四虎激情 | 国产极品美女在线 | 国产网址在线 | 天堂va| 深爱开心激情网 | 午夜成人影片 | 亚洲国产精品综合 |