成人小说亚洲一区二区三区,亚洲国产精品一区二区三区,国产精品成人精品久久久,久久综合一区二区三区,精品无码av一区二区,国产一级a毛一级a看免费视频,欧洲uv免费在线区一二区,亚洲国产欧美中日韩成人综合视频,国产熟女一区二区三区五月婷小说,亚洲一区波多野结衣在线

立即打開
研究稱中國三款熱門瀏覽器有安全隱患

研究稱中國三款熱門瀏覽器有安全隱患

David Meyer 2016年04月04日
不安全的數(shù)據(jù)傳輸方式意味著路徑內的任何行為方(比如,用戶的網(wǎng)絡服務提供商、咖啡店的WiFi網(wǎng)絡,或者通過其中任何一種接入點進入網(wǎng)絡的惡意行為方)都能通過收集信息流,通過一些手段解密后就能獲取各種個人信息。

如果你正在使用中國的最熱門瀏覽器,那要小心了,因為這很可能不太保險。多倫多大學公民實驗室的研究人員曾抨擊UC瀏覽器和百度瀏覽器不安全,最近又指出廣泛使用的Windows版和安卓版QQ瀏覽器也存在重大安全問題。

安全研究人員指出,QQ瀏覽器將用戶個人信息傳回騰訊服務器時,要么根本不加防護,要么使用很容易破解的加密方式。

他們推斷,這可能是專門留下的后門,旨在擴大行政部門的監(jiān)控范圍。

Windows版和安卓版QQ瀏覽器都會返回瀏覽網(wǎng)頁的地址,以及上網(wǎng)所用手機或電腦的識別信息。安卓版QQ瀏覽器還會返回用戶在搜索框里輸入的關鍵詞,采取的防護手段同樣脆弱不堪。

此外,這些研究人員稱,兩種版本的QQ瀏覽器在軟件升級機制上都存在漏洞,別人可以利用漏洞在用戶的設備上安裝惡意軟件。

這些問題為什么重要?首先,幾乎一半的中國手機用戶都在使用安卓版QQ瀏覽器。研究人員指出:

不安全的數(shù)據(jù)傳輸方式意味著路徑內的任何行為方(比如,用戶的網(wǎng)絡服務提供商、咖啡店的WiFi網(wǎng)絡,或者通過其中任何一種接入點進入網(wǎng)絡的惡意行為方)都能通過收集信息流,通過一些手段解密后就能獲取各種個人信息。

中國這幾家瀏覽器的用戶要擔心的還不僅是偶然的攻擊。此前,愛德華?斯諾登泄露的信息顯示,情報部門很清楚UC瀏覽器(在中國和印度有5億多用戶)存在的類似漏洞,并且在利用漏洞監(jiān)控公眾。關于這一點,公民實驗室2015年5月也已經(jīng)證實。

QQ瀏覽器、UC瀏覽器和百度瀏覽器上相似的安全漏洞引起了研究人員的懷疑,他們曾向騰訊詢問是否存在深層次的原因,但騰訊一直未答復。不過,在被指出問題后,騰訊確實改進了QQ瀏覽器的部分安全機制,但在研究人員看來安全性仍然不夠。

研究人員在報告中指出,出現(xiàn)種種安全漏洞可能是因為行業(yè)潛規(guī)則,也或許是行政壓力。畢竟,中國的科技公司受制于諸多監(jiān)管條例,不得不協(xié)助政府工作。

他們寫道:“公司高層之所以設置大范圍數(shù)據(jù)收集功能,有可能是應安全部門的要求,也有可能是為了取悅安全部門。要驗證假設,還需要更進一步研究?!保ㄘ敻恢形木W(wǎng))

譯者:Charlie

審校:夏林

It’s probably not a great idea to use China’s top web browsers. After slamming the security of the UC and Baidu mobile browsers, researchers from Citizen Lab at the University of Toronto have now identified serious problems with both the Windows and Android versions of Tencent’s widely-used QQ Browser.

According to the security researchers, Tencent’s browsers transmitted personal user information back to the company’s servers with either no protection at all, or poorly implemented encryption that could easily be broken.

The researchers theorized these could be deliberate backdoors, aimed at expanding state surveillance.

Both versions sent back the addresses of visited pages, along with identifying data about the phones or computers being used for the surfing. The Android version of the QQ Browser also sent back search terms that the user typed into the address bar, again with poor security protection.

What’s more, the researchers said, there were holes in the software-update mechanisms for both browsers, making it possible for someone to send malware to the user’s device.

Why does all this matter? Firstly, the Android version of the QQ Browser is used by almost half of all Chinese mobile users. Here’s what the researchers said:

This insecure data transmission means that any in-path actor (such as a user’s ISP, a coffee shop WiFi network, or a malicious actor with network visibility across any of these type of access points) would be able to acquire this personal data by collecting traffic and performing any necessary decryption.

It’s not just random attackers that users of these Chinese browsers need to be concerned about. As Citizen Lab demonstrated last May, Edward Snowden’s leaks showed that similar vulnerabilities in the UC Browser (used by over half a billion people in China and India) were known to intelligence services, and used to spy on people.

Suspicious of the similarities between the security holes in the QQ, UC and Baidu browsers, the researchers said they asked Tencent whether there was a underlying reason. They received no answer, but Tencent did strengthen some of the browsers’ security mechanisms after being notified of them — though not to the satisfaction of the researchers.

In their paper, the researchers suggested the flaws could result from poor industry norms and/or pressure from the authorities, who want to be able to easily spy on citizens. After all, China has numerous regulations on tech firms, demanding that they aid authorities.

“It is reasonable to hypothesize that company officers put in place wide-reaching data gathering functionalities either at the request of, or to appease the preferences of, China’s security services,” they wrote. “More research is needed to evaluate this hypothesis.”

掃碼打開財富Plus App
精品亚洲麻豆1区2区3区| 重口SM一区二区三区视频| 国产mv动漫精品一区二区三区| 亚洲九九视频欧美插逼视频| 国产性色福利在线视频| 2021国自拍产精品视频| 国产一区二区三区不卡| 精品国产aⅴ无码一区二区| 久久久久人妻精品一区三寸| 亚洲人成人无码网WWW国| 国产揄拍国内精品对白| 懂色av,亚洲综合精品第一页| 台湾无码中文娱乐网| 国产在线午夜不卡精品影| 午夜无码片在线观看影院y| AV无码人妻一区二区三区在线| 色欲国产精品无码一区二区在| 成人精品怡红院在线观看| 99久热RE在线精品99 6热视频| 久久精品久久久久观看99水蜜桃| 超碰高清熟女一区二区| d91精品国产综合久久不| 亚洲欧美日韩中文字幕在线国产成人高清亚洲亚洲日本人成网站| 国产精品久久久久久一区二区| 三年片在线观看免费观看大全| 亚洲天堂丁香五月| 97高清国产国语精品自产拍| 亚洲av无码一区东京热不卡| 激情国产精品视频一区二区| 伊人久久综合精品无码AV专区| 丰满人妻一区二区三区视频53| 国产丝袜无码一区二区视频| 免费午夜无码片在线观看影院| 欧美精品九九久久久久久久久| 国产女同疯狂作爱系列| 国产乱婬AV片免费| 亚洲国产精品尤物yw在线观看| 漂亮人妻被中出中文字幕| 一本色道久久88—综合亚洲精品| 69天堂人成无码免费视频网站| 国产免费午夜福利蜜芽无码|