Banks under scrutiny over credit card data breach

    Updated: 2015-10-15 07:32

    By Kahon Chan in Hong Kong(HK Edition)

      Print Mail Large Medium  Small 分享按鈕 0

    Banks under scrutiny over credit card data breach

    A mobile phone reads the information of a credit card via mobile app "Banking Card Reader". Phones with near field communication (NFC) technology can instantly extract credit card information such as the card number, expiry date and transaction records. Roy Liu / China Daily

    Some chips for contactless payment found to contain unsecured names of holders

    Bank and personal data watchdogs in Hong Kong are investigating how names of contactless credit card holders could be read by unauthorized mobile devices. But experts said the isolated incident should not put the security of contactless payment platforms in doubt.

    Near field communication technology (NFC) has become a regular feature on Android devices lately for its potential in data transfers and mobile payments.

    Contactless payment pioneer Octopus has enabled payments via mobile phone for Taobao shopping. And Telecommunications giant, PCCW, earlier this year managed to enroll thousands of users onto its own payment platform Tap&Go through big shopping discounts at a local grocery chain.

    The NFC chips on Android devices could also pick up numbers and expiry dates from credit cards containing contactless chips. Such exposure is considered safe - as names were essential for online transactions. A card number alone is also not considered to be personal data protected by local laws.

    The Hong Kong Monetary Authority (HKMA) in 2012 instructed banks to not store cardholders' names on contactless chips. Three years later, however, a TV reporter managed to read the name from his colleague's Sogo Department Store credit card issued by Bank of China (Hong Kong) and ordered a pair of earphones from Amazon.

    The same trick was also performed on a Compass Visa card issued by DBS. Both banks had reported the irregularity to the bank regulator before the report was aired on Monday. But the Bank of China (Hong Kong) only began recalling contactless cards on Wednesday afternoon.

    The HKMA on Wednesday named all seven banks that breached the data rule in a move to get a response from banks. Apart from the two banks mentioned, the others were China CITIC Bank International, Bank of Communications (Hong Kong), ICBC (Asia), OCBC Wing Hang Bank and Dah Sing Bank.

    Banks under scrutiny over credit card data breach

    The Office of the Privacy Commissioner for Personal Data has also opened an investigation into the data breach. The office's information technology adviser Henry Chang noted that as not all banks using the payment platform were affected by the data breach, the flaw was likely to have occurred locally.

    Cheng Lee-ming, a City University of Hong Kong expert in security encoding, suspected the names in the cards had not been encrypted properly. They could be easily decoded by mobile apps. He suspected the contactless chip supplier could be faulted for its failure to secure sensitive data stored on cards.

    The incident could be a setback for public confidence in contactless payments. But Francis Fong Po-kiu, Hong Kong Information Technology Federation honorary president, said it might actually illustrate the superior security of payments by mobile devices over those by physical cards.

    NFC functions on mobile devices, for instance, could be turned off by users. The Octopus app requires registration of specific cards, while the payment function of Tap&Go requires activation by password.

    Henry Chang said there were persistent fears about data theft among customers new to contactless or mobile payments. But platforms widely adopted across the world like MasterCard's PayPass have been scrutinized extensively. They have been in use for years and had proved to be safe.

    Secretary for Financial Services and the Treasury Ceajer Chan Ka-keung also assured the public the regulatory system could handle such problems. "Whenever there is a new technology, there is usually a process," he added.

    kahon@chinadailyhk.com

    (HK Edition 10/15/2015 page6)

    中文字幕日本精品一区二区三区| 久久亚洲av无码精品浪潮| 国产办公室秘书无码精品99| 日韩精品中文字幕无码一区| 久久水蜜桃亚洲av无码精品麻豆| 亚洲精品中文字幕无码蜜桃| 国99精品无码一区二区三区| 日韩a级无码免费视频| 亚洲色中文字幕无码AV| 久久久久亚洲精品无码网址 | 曰韩精品无码一区二区三区| 中文字幕VA一区二区三区| 99久久人妻无码精品系列蜜桃| 一本加勒比HEZYO无码人妻| 中文字幕手机在线视频| 中文无码喷潮在线播放| 国产精品午夜无码AV天美传媒| 无码无遮挡又大又爽又黄的视频 | 精品久久久无码人妻中文字幕豆芽| 久久久久亚洲AV无码永不| 老子午夜精品无码| 色综合天天综合中文网| 亚洲午夜福利精品无码| 免费一区二区无码视频在线播放 | 中文字幕无码人妻AAA片| 日本精品自产拍在线观看中文 | 中文字幕亚洲欧美日韩在线不卡| 国产成人精品无码播放| 日韩丰满少妇无码内射| 无码专区AAAAAA免费视频| 伊人久久精品无码av一区| 久久亚洲精品无码VA大香大香| AV色欲无码人妻中文字幕| 亚洲欧美在线一区中文字幕| 最近免费最新高清中文字幕韩国| 国产乱码精品一区二区三区中文 | 欧美日韩中文字幕在线看| 日韩国产中文字幕| 久久精品99无色码中文字幕| 亚洲欧洲中文日韩av乱码| 无码人妻丝袜在线视频|