Electronic Payment App analysis
Posted Pieces0310
tags:
篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了Electronic Payment App analysis相关的知识,希望对你有一定的参考价值。
Electronic Payment App is getting more and more popular now. People don\'t have to bring credit cards any more. All they need to do is using their smartphones and they could go shopping, check bills and dining in restaurants. It very convenient but some security issue occurs.
People like fancy interface Apps and they may not know how secure those Apps are. It\'s developers\' responsibility to keep credential data safe and sound. But guess what??? Boss don\'t want extra costs for developers writing more secure Apps. Fancy interface is more important than security. No need to waste time and efforts for security.
Let\'s take a look at some Electronic Payment App and see how secure it is.
Extract the package folder of allPay from a smartphone and take a look at shared preference files.
To my surprise that login accout is stored in share preference xml files. Poor lazy developers~ At least you should hash or encrypt those credential data such as account or phone numbers or e-mail.
Don\'t get me wrong. I\'m not trying to say this Electronic Payment App is not secure enough. Actually allPay is doing well on security such as Certificate Pinning and so on. We cannot emphasize too much the importance of secuirty.
以上是关于Electronic Payment App analysis的主要内容,如果未能解决你的问题,请参考以下文章
调用 Intent 加载 UPI Payment App 时出现异常:android.content.ActivityNotFoundException: No Activity found to h
解决Hbuilder打包的APP微信支付时无法唤起支付,且提示{“code“:-100,“message“:“[payment微信:-1]General errors“}的问题
mysql 数据库导入数据错误 #1064 - You have an error in your SQL syntax; check the manual