Electronic Payment App analysis

本文探讨了当前流行的电子支付应用的安全问题。虽然这类应用极大地方便了人们的日常生活,但其安全性却常常被忽视。文章通过分析某款电子支付应用如何在手机上存储登录账号等敏感信息,揭示了开发者在追求美观界面的同时可能牺牲安全性的现状。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Electronic Payment App is getting more and more popular now. People don't have to bring credit cards any more. All they need to do is using their smartphones and they could go shopping, check bills and dining in restaurants. It very convenient but some security issue occurs.

 

People like fancy interface Apps and they may not know how secure those Apps are. It's developers' responsibility to keep credential data safe and sound. But guess what??? Boss don't want extra costs for developers writing more secure Apps. Fancy interface is more important than security. No need to waste time and efforts for security.

 

Let's take a look at some Electronic Payment App and see how secure it is.

 

Extract the package folder of allPay from a smartphone and take a look at shared preference files.

 

To my surprise that login accout is stored in share preference xml files. Poor lazy developers~ At least you should hash or encrypt those credential data such as account or phone numbers or e-mail.

 

Don't get me wrong. I'm not trying to say this Electronic Payment App is not secure enough. Actually allPay is doing well on security such as Certificate Pinning and so on. We cannot emphasize too much the importance of secuirty.

 

转载于:https://www.cnblogs.com/pieces0310/p/5927251.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值