北京时间4月16日晚,中国国家质检总局发布一项风险警示,称在近期的一项对智能手机的检测中,40批次的手机样品中,有18批次样品存在质量安全隐患,13批次样品后端信息系统存在信息安全漏洞,这些问题可能导致用户隐私数据泄漏甚至智能手机被恶意控制。
On the 16th April evening Beijin time,AQSIQ(General Administration of Quality Supervision, Inspection and Quarantine the People’s Republic of China) issued a risk warning reporting that there were 18 batches of sample having quality and safety risk,13 batches of sample existing Information security vulnerabilities among 40 batches of sample in a recent testing of smart phone.These problems may lead to users’ privacy data leakage even malicious phones’ control.
智能手机与我们的生活越来越紧密,目前中国手机网民已将近7亿,但智能手机的信息安全问题不容忽视。
Since Chinese smart phone netizens raises to nearly 700 million,mobiles are getting more and more relevant to our lives.However,we cannot ignore the information security.
中国国家质检总局在通报中表明,18批次存在质量安全隐患的样品中,13批次样品后端信息系统存在信息安全漏洞,包括未限制用户密码复杂度、未限制非法登陆次数、未限制短信验证码错误使用次数、重置密码的短信验证码由本地生成、未对数据包重要访问控制参数进行校验导致可被越权操作;9批次样品中的预置应用软件未向用户明示且未经用户同意,擅自收集用户数据;1批次样品未实现对用户数据的操作权限控制功能;1批次样品操作系统的更新未向用户明示且未经用户同意,擅自自动升级。
AQSIQ indicated in the bulletin, among 18 batches of sample having quality and safety risk,13 batches of sample existing Information security vulnerabilities,have the problems including following :Unlimited users password complexity;Unlimited times of illegal landing;Unlimited usage of SMS verification code;reset password SMS verification code generated by the local; No significant access control parameters of the packet can be checked for unauthorized operation;Pre-configured App collect users’ information without authorization among 9 batches of sample.One batch of sample fails to control the personal data of users.One batch of sample upgrade its operating system without agreement of users.
(中国网作者 杨云寒 综合报道 陈萍萍/译)
来源: 中国网综合 | 作者:杨云寒 | 责编:杨云寒 审核:张渊
新闻投稿:184042016@qq.com 新闻热线:13157110107
版权所有 中国互联网新闻中心
电话: 057187567897 京ICP证 040089号