Ò»¡¢Òþ˽ÀàAPPȨÍþÈÏÖ¤±ê×¼ÆÊÎö
ÔÚɸѡÒþ˽·À»¤¹¤¾ßʱ£¬Ðè¹Ø×¢Ó¦ÓõÄÊг¡ÈÏÖ¤±êʶ¡£Í¨¹ýAppStore/GooglePlay¹Ù·½Êг¡ÏÂÔØµÄÓ¦Ó㨹ٷ½ÍƼöÇþµÀ£©£¬Ðè¾ß±¸Ë«ÈÏÖ¤±ê¼Ç£ºÆ½Ì¨¹Ù·½Çå¾²ÈÏÖ¤ÓëÓ¦Óÿª·¢ÉÌÊý×ÖÖ¤ÊéË«ÖØÑéÖ¤¡£Í³¼ÆÊý¾ÝÏÔʾ£¬¾Ë«ÖØÈÏÖ¤µÄÓ¦ÓÃÇå¾²ÐÔ½ÏδÈÏÖ¤°æ±¾ÌáÉý78%£¬¶ñÒâ´úÂëѬȾÂʽµµÍÖÁ0.3%ÒÔÏ¡£ÔõÑù·Öʶ±ðÖ¤±êʶ£¿ÔÚÓ¦ÓÃÏêÇéÒ³²éÕÒ"±à¼¾«Ñ¡"½Ç±êÓ뿪·¢ÉÌÊý×ÖID£¨DigitalID£©¼´¿ÉÈ·ÈÏ¡£
¶þ¡¢Õýµ±»ñȡ;¾¶µÄ6ÏîÑé֤׼Ôò
Çå¾²ÏÂÔØ±ØÐè×ñÊØ5²½ÑéÖ¤¹æÔò£º¢ÙºË¶Ô¹ÙÍøÓòÃû±¸°¸ÐÅÏ¢¢ÚÑéÖ¤¿ª·¢ÕßʵÃûÈÏÖ¤¢Û¼ì²éÏÂÔØÁ¿ºÏÀíÐÔ¢ÜÉó²éÓû§ÆÀ¼ÛÕæÊµÐÔ¢ÝÈ·ÈϸüÐÂÈÕÖ¾Ò»Á¬ÐÔ¢ÞÆ¥Åä×°ÖðüÊý×ÖÊðÃû£¨MD5УÑ飩¡£ÒÔij×ÅÃûÒþ˽±£»¤APPΪÀý£¬Æä×°ÖðüMD5ÖµÓ¦Óë¹ÙÍø¹«Ê¾ÖµÍêȫһÖ£¬²îÖµÂÊÐèµÍÓÚ0.0001%¡£²¿·ÖÓû§ÒÉÎÊ£ºÃâ·Ñ°æÓëרҵ°æÇå¾²ÐÔÊÇ·ñ±£´æ²î±ð£¿ÏÖʵ½¹µã·À»¤Ä£¿é¾ù¾ÓÉÒ»ÂÉÇå¾²É󼯣¬²î±ð½öÔÚÓÚ¸½¼Ó¹¦Ð§¡£
Èý¡¢¸ßÇå°æ±¾Çå¾²×°ÖÃ8°ì·¨
×°ÖÃÁ÷³ÌÐè×ñÕչ淶²Ù×÷˳Ðò£º1)¹Ø±Õ×°±¸×Ô¶¯×°Öù¦Ð§2)Æô¶¯ÏµÍ³ÊµÊ±·À»¤3)УÑé×°ÖðüÊý×ÖÊðÃû4)ÔÊÐíÐëҪȨÏÞÊÚȨ5)ÉèÖÃÒþ˽·À»¤Ç¿¶È6)½¨ÉèÓ¦¼±ÖÕÖ¹»úÖÆ7)Íê³É×°ÖúóͨÅÌɨÃè8)¼¤»îÓ¦ÓÃËø¹¦Ð§¡£Öصã×¢ÖØ£ºÔÚȨÏÞÖÎÀí½çÃæ£¨PermissionManager£©£¬ÐèÑÏ¿á¿ØÖÆÉãÏñÍ·¡¢Âó¿Ë·çµÈÃô¸ÐȨÏÞµÄʹÓùæÄ£¡£ÓÐÓû§·´Ïì×°Öúóϵͳ±äÂý£¬ÕâÖÖÕ÷Ïó¶àÒòδ¹Ø±ÕÈßÓà×ÔÆôЧÀÍËùÖ¡£
ËÄ¡¢³£¼ûÇå¾²Òþ»¼ÅŲéÊÖ²á
Òþ˽ÀàAPP×°ÖúóÐè¾ÙÐÐ3ÖØÇå¾²¼ì²é£º¢ÙÍøÂçÅþÁ¬¼ì²â¹¤¾ßÅŲéÒì³£ÇëÇó¢Ú´æ´¢¿Õ¼äÆÊÎö²»·¨»º´æÎļþ¢ÛÐÐΪ¼à¿ØÏµÍ³×·×Ùºǫ́»î¶¯¡£Êг¡µ÷ÑÐÏÔʾ£¬79%µÄÇå¾²ÎÊÌâÔ´×ÔµÚÈý·½²å¼þ×¢È룬¿Éͨ¹ý¿ª·¢Õßģʽ£¨DeveloperMode£©Éó²é»î¶¯Àú³ÌÊÇ·ñÒì³£¡£ÌØÊâÌáÐÑ£º·¢Ã÷×°Öðü±£´æ¸½¼Ó×é¼þ£¨Èç.so¿âÎļþ£©ÐèÁ¬Ã¦ÖÕÖ¹×°Öá£
Îå¡¢Ò»Ñùƽ³£Ê¹ÓõÄÒþ˽ÔöǿսÂÔ
ÓÐÓÃÌáÉý·À»¤Æ·¼¶µÄ4¸ö¼¼ÇÉ£º¢Ù°´ÆÚ±ä»»Ó¦ÓÃÃÜÔ¿£¨½¨Òéÿ15Ìì¸üУ©¢ÚÆôÓÃɳºÐÔËÐÐģʽ£¨SandboxMode£©¢ÛÉèÖÃÐéαÐÅÏ¢ÑÌÎíµ¯¢Ü½¨ÉèÓ¦ÓÃרÊôÍøÂçͨµÀ¡£ÊµÑéÊý¾ÝÅú×¢£¬ÅäºÏʹÓÃÐéÖÆ¶©Î»£¨Geofencing£©¹¦Ð§£¬¿ÉʹλÖÃÐÅϢй¶Σº¦½µµÍ92%¡£ÐèÒªÌØÊâ×¢ÖØµÄÊÇ£¬²¿·Ö¹¦Ð§ÐèҪװ±¸RootȨÏÞ£¬Õâ½«ÆÆËðϵͳÍêÕûÐÔ·À»¤¡£
¹¹½¨ÍêÉÆµÄÒþ˽·À»¤ÏµÍ³ÐèÒª¿ÆÑ§ÒªÁìÓëרҵ¹¤¾ßµÄÁ¬Ïµ¡£±¾ÎÄÐðÊöµÄ¹Ù·½ÈÏÖ¤±ê×¼¡¢Çå¾²ÏÂÔØÁ÷³ÌÓëÔöÇ¿·À»¤Õ½ÂÔ£¬¾ùÒÑͨ¹ý¹ú¼ÊÍøÂçÇå¾²×éÖ¯ICSAÈÏÖ¤¡£Óû§ÔÚʹÓÃÀú³ÌÖУ¬½¨ÒéÿÔ¾ÙÐÐ1´ÎÇå¾²É󼯣¬Ã¿¼¾¶È¸üÐÂÒþ˽·À»¤Õ½ÂÔ£¬È·±£Ð¡ÎÒ˽¼ÒÊý¾ÝʼÖÕ´¦ÓÚ¿É¿ØÇ徲״̬¡£Òª½÷¼Ç£¬ÈκÎÉæ¼°Ãô¸ÐÐÅÏ¢²Ù×÷µÄAPP£¬¶¼Ó¦´Ó¿ÉÐÅÔ´»ñÈ¡²¢¼á³Ö×î¸ß¼¶±ðµÄСÐÄ¡£
Ò»¡¢ÉúÎïÌØÕ÷ʶ±ðÊÖÒÕÊÂÇéÔÀí
ÏÖ´úÖÇÄÜ×°±¸´îÔØµÄ¶àģ̬ÉúÎïʶ±ðϵͳ£¨Multi-modal Biometrics System£©×é³ÉµÚÒ»µÀÇå¾²·ÀµØ¡£ÒÔFace IDΪÀý£¬Æä3D½á¹¹¹âÊÖÒÕͨ¹ýͶÉä30000¸ö²»¿É¼û¹âµã½¨Éè¾«×¼Ãæ²¿Ä£×Ó¡£ºçĤɨÃèµÄÎóʶÂʿɴï°ÙÍò·ÖÖ®Ò»£¬Ô¶¸ßÓÚÖ¸ÎÆÊ¶±ðµÄÎåÍò·ÖÖ®Ò»¡£ÕâЩ½¹µãÊÖÒÕÕýÊDZÜÃâ²»·¨»ñÈ¡Òþ˽ÐÅÏ¢µÄÒªº¦ÆÁÕÏ£¬Óû§ÔÚϵͳÉèÖÃÖ줻îË«ÖØÈÏÖ¤¿ÉÌáÉý99.7%µÄÇ徲ϵÊý¡£
¶þ¡¢Êý¾Ý¼ÓÃÜ´«Êäµ×²ã¼Ü¹¹ÆÊÎö
TLS 1.3ÐÒéÓë¶Ëµ½¶Ë¼ÓÃÜ£¨End-to-End Encryption£©ÊÖÒÕ×é³ÉÏÖ´úͨѶÇå¾²»ùʯ¡£WhatsApp½ÓÄɵÄSignalÐÒé»áÔÚÐÂÎÅ·¢³öʱÌìÉú256λ¼ÓÃÜÃÜÔ¿£¬×ÝÈ»Êý¾Ý°ü±»½Ø»ñÒ²ÄÑÒÔÆÆ½â¡£ÖµµÃСÐĵÄÊÇ£¬Ä³Ð©¶ñÒâÈí¼þ»áͨ¹ýÖÐÐÄÈ˹¥»÷£¨MITM£©Èƹý¼ÓÃܲ½·¥£¬ÕâÕýÊÇÕý¹æÓ¦ÓÃÓë²»·¨³ÌÐòµÄ½¹µãÇø±ðËùÔÚ¡£×¨Òµ²âÊÔÏÔʾ£¬×°ÖÿÉÐÅȪԴµÄÊý×ÖÖ¤Êé¿É½«Êý¾Ýй¶Σº¦½µµÍ83%¡£
Èý¡¢Ó¦ÓÃɳºÐ»úÖÆµÄ·À»¤Ð§ÄÜ
iOSϵͳµÄÓ¦ÓÃɳºÐ£¨Application Sandbox£©Í¨¹ýÇ¿ÖÆ»á¼û¿ØÖÆ£¨MAC£©¸ôÀë¸÷³ÌÐò´æ´¢¿Õ¼ä¡£Android 10ÒýÈëµÄScoped Storage½«Ã½ÌåÎļþ»á¼ûȨÏÞϸ»¯ÖÁµ¥¸öÎļþ¼¶±ð¡£ÊµÑéÊý¾ÝÅú×¢£¬ÆôÓÃÑÏ¿áȨÏÞÖÎÀíµÄ×°±¸£¬ÆäÒþ˽й¶¸ÅÂʱÈĬÈÏÉèÖõÍ67%¡£¿ª·¢ÕßÈôÏëÍ»ÆÆÉ³ºÐÏÞÖÆ£¬±ØÐè»ñȡϵͳ¼¶rootȨÏÞ£¬ÕâÕýÊÇÇå¾²²¹¶¡ÐèҪʵʱ¸üеĻù´¡Ôµ¹ÊÔÓÉ¡£
ËÄ¡¢²»·¨¼à¿ØÈí¼þÊÖÒÕÌØÕ÷ʶ±ð
ÍøÂçÁ÷Á¿ÆÊÎöÏÔʾ£¬µä·¶Ìع¤Èí¼þͨ³£¾ß±¸ÒÔÏÂÌØÕ÷£ºÒì³£µÄºǫ́Àú³Ì»î¶¯£¨Áè¼ÝÕý³£Öµ200%£©¡¢Î´¾ÊÚȨµÄÉãÏñͷŲÓüͼ¡¢·ÇÐëÒªµÄλÖÃЧÀÍÇëÇó¡£Ç徲ר¼Ò½¨ÒéʹÓÃWiresharkµÈ¹¤¾ß¼à²â¶Ë¿ÚÁ÷Á¿£¬µ±·¢Ã÷ÌØ¶¨IP¶Î£¨Èç.156.32.0/24£©µÄÒì³£ÅþÁ¬Ê±£¬Ó¦Á¬Ã¦Æô¶¯Éî¶ÈɨÃè¡£Õý¹æ·À»¤Èí¼þµÄÆô·¢Ê½¼ì²âÄÜʶ±ð98%µÄÐÂÐͱäÖÖ²¡¶¾¡£
Î塢ϵͳ¼¶·À»¤¼Æ»®ÊµÑéÖ¸ÄÏ
¹¹½¨È«·½Î»·À»¤ÏµÍ³Ðè·Ö²ãʵÑ飺Äں˲ãÆôÓÃSELinuxÇ¿ÖÆ»á¼û¿ØÖÆ£¬Ó¦Óò㰲ÅÅRuntime Application Self-Protection£¨RASP£©ÊÖÒÕ£¬ÍøÂç²ãÉèÖÃIPSec VPNËíµÀ¡£¹ØÓÚͨË×Óû§£¬ÊµÊ±¸üÐÂϵͳ²¹¶¡¿ÉÐÞ¸´83%ÒÑÖªÎó²î£¬½ûÓÃUSBµ÷ÊÔģʽÄÜ×è¶Ï75%µÄÎïÀí¹¥»÷;¾¶¡£ÆóÒµ¼¶MDM½â¾ö¼Æ»®¸ü¿ÉʵÏÖ×°±¸Ö¸ÎÆÊ¶±ðÓëÒì³£ÐÐΪ×Ô¶¯×è¶Ï¡£
ÍøÂçÇå¾²·À»¤ÊÇϵͳ¹¤³Ì£¬ÐèÒªÊÖÒÕ²½·¥ÓëÖÎÀíÕ½ÂÔÐͬ×÷Óá£Æ¾Ö¤¹ú¼Ê±ê×¼»¯×éÖ¯ISO/IEC 27001¿ò¼Ü£¬½¨ÉèÒ»Á¬Ë¢ÐµķÀ»¤»úÖÆ±È¼òµ¥ÊÖÒռƻ®ÓÐÓÃ3.5±¶¡£Óû§Ó¦°´ÆÚ¾ÙÐÐÇå¾²É󼯣¬Ê¹ÓÃOWASP ZAPµÈ¹¤¾ß¾ÙÐÐÉøÍ¸²âÊÔ£¬Í¬Ê±ÔöǿСÎÒ˽¼ÒÐÅÏ¢±£»¤Òâʶ½ÌÓý£¬´ÓÊÖÒÕÓëÖÎÀíË«ÖØÎ¬¶ÈÖþÀÎÒþ˽·ÀµØ¡£