日韩精品久久一区二区三区_亚洲色图p_亚洲综合在线最大成人_国产中出在线观看_日韩免费_亚洲综合在线一区

USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 蜜桃视频在线观看免费视频网站www | www伊人 | 欧美精品久 | jizzzxxxxhd | 精品免费久久久久久成人影院 | 免费中日高清无专码有限公司 | 美女扒开内裤让男人桶 | 精品久久久久久久人人人人传媒 | 日韩免费视频播放 | 91在线视频 | 91看片在线看| 国产精品原创av片国产免费 | 日韩大片免费在线观看 | 91精选 | 国产免费福利网站 | 奇米在线影视 | 91免费国产精品 | 国产成人18黄网站免费 | 久久综合九色综合欧美9v777 | 日韩一区二区三区视频 | 高清不卡一区 | 2022国产成人精彩在线视频 | 国产野花视频天堂视频免费 | 日韩一级片播放 | 日本一区二区三区精品国产 | 性爽爽 | 中文字幕一区二区三区四区 | 26uuu在线| 久久久亚洲欧洲日产国码606 | 热99re久久精品2久久久 | 久久久久久久免费看 | 亚洲一区国产二区 | 久久久久国产精品免费免费搜索 | 欧美伊人| 久草新 | 狠狠综合久久av一区二区小说 | 日韩精品久久 | jdav视频在线观看免费 | 国产精品美女久久久久久 | 黄色尤物 | 久草草视频在线观看免费高清 |