USEUROPEAFRICAASIA 中文雙語Fran?ais
China
Home / China / Society

CUHK researchers discover major loophole in mobile payment systems

Xinhua | Updated: 2017-09-28 17:10
HONG KONG - A major loophole in mobile payment systems was discovered by researchers from the Chinese University of Hong Kong (CUHK), which made the finding public on Thursday.

The discovery was made by the System Security Lab led by Professor Kehuan Zhang from the Department of Computer Science and Engineering at CUHK, which has analyzed various major mobile payment systems for their security vulnerabilities.

In mobile payment transactions, the key to communications between the mobile payer and payee is a payment token that is issued by the payment service provider to verify the payment.

Some of the most widely adopted forms of transmitting these tokens include Near-Field Communication (NFC), Quick Response Code (QR code) scans and Magnetic Secure Transmission (MST).

According to Zhang, whose team has spent two years in conducting an in-depth study into these payment systems, apart from NFC, the remaining formats support one-way communications only.

In other words, if the transaction fails, the payee's device is unable to notify the payer and cancel or reclaim the token already issued, a loophole that an active adversary can exploit.

In regard to QR Code scanning, a popular format of token verification, the study has revealed that a malicious device is able to sniff the token from the payee's screen from afar and spend it on a different transaction.

As for MST function uniquely used by Samsung Pay, payers are required to place their handsets within a 7.5 cm distance of the payees' POS (Point of sale) for identification.

But after a series of tests, the team discovered that the magnetic signals can be picked up from 2 meters away. A rogue in a supermarket queue can seize the opportunity to attack and steal the token.

The team has notified relevant third party payment platforms and Zhang reminded mobile payment users to stay alert and avoid downloading mobile apps from unknown sources.

Editor's picks
Copyright 1995 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US
 
主站蜘蛛池模板: 伊人大杳焦在线| 老少交欧美另类| 老师好长好大坐不下去| 激情综合网五月| 日韩免费高清专区| 废柴视频网最新fcww78| 国产精品视频全国免费观看| 国产人成午夜电影| 免费看a级毛片| 亚州**色毛片免费观看| 中文japanese在线播放| 18美女私密尿口视频| 色一情一乱一伦色一情一乱一伦| 波多野结衣伦理片| 日韩不卡免费视频| 在线播放第一页| 国产乱码一区二区三区爽爽爽| 亚洲精品无码专区在线在线播放 | 日本丰满岳乱妇在线观看| 夜夜春宵伴娇全文阅读| 国产后入又长又硬| 亚洲精品中文字幕乱码三区| 久久丫精品国产亚洲AV不卡| 91国高清视频| 美女把尿口扒开让男人添| 欧洲美熟女乱又伦免费视频| 妖精视频免费网站| 国产在线无码视频一区二区三区| 亚洲视频国产视频| 中文字幕在线播放第一页| 日本高清在线免费| 波霸女的湮欲生活mp4| 成人欧美在线视频| 国产女同疯狂摩擦系列1| 亚洲男女一区二区三区| 一本大道香蕉大无线视频| 韩国伦理s级在线| 欧美亚洲国产精品久久高清| 女人张腿让男人捅| 国产一区曰韩二区欧美三区| 亚洲一区二区三区精品视频|