www射-国产免费一级-欧美福利-亚洲成人福利-成人一区在线观看-亚州成人

Banks under scrutiny over credit card data breach

Updated: 2015-10-15 07:32

By Kahon Chan in Hong Kong(HK Edition)

  Print Mail Large Medium  Small 分享按鈕 0

Banks under scrutiny over credit card data breach

A mobile phone reads the information of a credit card via mobile app "Banking Card Reader". Phones with near field communication (NFC) technology can instantly extract credit card information such as the card number, expiry date and transaction records. Roy Liu / China Daily

Some chips for contactless payment found to contain unsecured names of holders

Bank and personal data watchdogs in Hong Kong are investigating how names of contactless credit card holders could be read by unauthorized mobile devices. But experts said the isolated incident should not put the security of contactless payment platforms in doubt.

Near field communication technology (NFC) has become a regular feature on Android devices lately for its potential in data transfers and mobile payments.

Contactless payment pioneer Octopus has enabled payments via mobile phone for Taobao shopping. And Telecommunications giant, PCCW, earlier this year managed to enroll thousands of users onto its own payment platform Tap&Go through big shopping discounts at a local grocery chain.

The NFC chips on Android devices could also pick up numbers and expiry dates from credit cards containing contactless chips. Such exposure is considered safe - as names were essential for online transactions. A card number alone is also not considered to be personal data protected by local laws.

The Hong Kong Monetary Authority (HKMA) in 2012 instructed banks to not store cardholders' names on contactless chips. Three years later, however, a TV reporter managed to read the name from his colleague's Sogo Department Store credit card issued by Bank of China (Hong Kong) and ordered a pair of earphones from Amazon.

The same trick was also performed on a Compass Visa card issued by DBS. Both banks had reported the irregularity to the bank regulator before the report was aired on Monday. But the Bank of China (Hong Kong) only began recalling contactless cards on Wednesday afternoon.

The HKMA on Wednesday named all seven banks that breached the data rule in a move to get a response from banks. Apart from the two banks mentioned, the others were China CITIC Bank International, Bank of Communications (Hong Kong), ICBC (Asia), OCBC Wing Hang Bank and Dah Sing Bank.

Banks under scrutiny over credit card data breach

The Office of the Privacy Commissioner for Personal Data has also opened an investigation into the data breach. The office's information technology adviser Henry Chang noted that as not all banks using the payment platform were affected by the data breach, the flaw was likely to have occurred locally.

Cheng Lee-ming, a City University of Hong Kong expert in security encoding, suspected the names in the cards had not been encrypted properly. They could be easily decoded by mobile apps. He suspected the contactless chip supplier could be faulted for its failure to secure sensitive data stored on cards.

The incident could be a setback for public confidence in contactless payments. But Francis Fong Po-kiu, Hong Kong Information Technology Federation honorary president, said it might actually illustrate the superior security of payments by mobile devices over those by physical cards.

NFC functions on mobile devices, for instance, could be turned off by users. The Octopus app requires registration of specific cards, while the payment function of Tap&Go requires activation by password.

Henry Chang said there were persistent fears about data theft among customers new to contactless or mobile payments. But platforms widely adopted across the world like MasterCard's PayPass have been scrutinized extensively. They have been in use for years and had proved to be safe.

Secretary for Financial Services and the Treasury Ceajer Chan Ka-keung also assured the public the regulatory system could handle such problems. "Whenever there is a new technology, there is usually a process," he added.

kahon@chinadailyhk.com

(HK Edition 10/15/2015 page6)

主站蜘蛛池模板: 国产成人免费 | 日韩中文字幕在线亚洲一区 | 网禁呦萝资源网站在线观看 | 久久国产精品1区2区3区网页 | 综合亚洲欧美日韩一区二区 | 免费国产成人高清视频网站 | 日韩制服诱惑 | 在线观看精品国内福利视频 | 亚洲天天| 久久在线免费观看视频 | 日产国产精品久久久久久 | 外国成人网在线观看免费视频 | 日本一区二区三区四区无限 | 精品国产美女福到在线不卡f | 黄色三级视频 | 国产欧美日韩一区二区三区在线 | 亚洲一区二区三区首页 | 99精品在线免费观看 | 亚洲高清视频在线播放 | 亚洲高清二区 | 国产午夜伦伦伦午夜伦 | 久久影院在线观看 | 国内三级视频 | 欧美精品伊人久久 | 夜色福利久久久久久777777 | 99在线视频精品费观看视 | 男人亚洲天堂 | 日本一在线中文字幕天堂 | 久久综合久久精品 | 国产亚洲欧美视频 | 香港av三级 | 国产激情一区二区三区成人91 | 亚洲免费精品 | 亚洲欧美第一 | 美美女高清毛片视频黄的一免费 | 欧美中文字幕 | 国产在线精品一区二区中文 | 久久精品国产99久久 | 午夜三级毛片 | 国产三级网站 | 国内精品久久久久久中文字幕 |