Friday, 7 March 2014

Avoid Samsung's Fingerprint Payment system


Paypal says Samsung fingerprint payments 'very secure' : "The important thing about this announcement is that none of your biometric data is stored on that phone.
"It's not storing your fingerprints locally. It takes your fingerprint, encrypts it, sends it to PayPal, they decrypt it, checks it's the same, and then you're authenticated. It's very, very secure."
Well, I think this is a very dangerous method!! Samsung's implementation is fundamentally flawed. i) 3rd party keeps your un-encrypted biometric info ii) encryption key leakage from 3rd party or Samsung iii) local hardware hack, if there is no specifical chip handle the scan and encryption directly (I don't see it right now) iv) android system's security...

Further research shows: 
The inside story is that Samsung is the first smartphone maker to deploy a fingerprint sensor that uses the new FIDO Alliance authentication standard (FIDO stands for Fast IDentity Online).
The FIDO Alliance is based on the simple idea that a user can authenticate to their own device and then use public key encryption to authenticate to the network. PKE is very strong encryption (though NSA shenanigans have raised concern about back doors) and, like Apple’s scheme, does not involve biometric data itself residing in the cloud.


Ok, sounds better now. It seems the security flaw in theory could only happen locally, on Samsung's phone. Point ii, iii & iv are still valid.

Sunday, 23 February 2014

“吸血鬼” 余额宝?

有感于余额宝在国内火爆非常,但被银行的喉舌成为吸血鬼,提高了融资成本:
真搞笑,很明显国内没有合理的投资途径,利率也很低,银行一直是储蓄的吸血鬼。
余额宝就是让大家有个低成本接触一个收益还可以的基金而已,吸血鬼们就跳出来了。

Thursday, 30 January 2014

Soft pouch for PS VITA with Hand Grip attached

So, finally a soft pouch for my PS VITA with Hand Grip attached.

Perfect size. Looks great. Low price.



Yeah, it is just a pencil case. Got it for $2 at local Dollarama. If you feel not enough protection with this pencil case, just keep the foam inside the case.