Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

SSL certificate proves that Wechat Open course pro version is innocent.

2025-03-29 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >

Share

Shulou(Shulou.com)06/01 Report--

On the evening of January 10, just as WeChat circle of friends was brushed by the PRO version of WeChat Open Class "My Story with WeChat," news suddenly emerged and spread rapidly, saying that the open class application link would steal micro-signals and payment treasure numbers. Subsequently, local police, Tencent, Alipay, etc. continued to refute rumors. However, the impact of the incident has not dissipated, a large number of people believe it, Tencent officials confirmed that millions of users untied WeChat bundled bank cards or cash withdrawals. (The above report is quoted from Shenzhen Special Zone Daily)

Although Tencent urgently refuted rumors, there are still many netizens who have doubts. This was Tencent's carefully planned online marketing, but in exchange for millions of people untied bank cards at a heavy price. Here, CFCA security engineers can't help but complain for Tencent, because the PRO version of WeChat Open Class is actually an HTTPS security page protected by SSL Certificates.

In order to more intuitively check the security of the open class page, we first open the link of the open class on the computer side:

Open the link of Open Class, click the lock icon (Security Lock) to view the information of SSL Certificates on the page. What does this certificate do? The first is to identify the identity, proving that this page is an official WeChat link belonging to weixin.qq.com. The second is HTTPS in the address bar, which means encrypted transmission. For example, your WeChat data will be retrieved by the activity page, and the data will be encrypted during the retrieval and transmission process, and will not be intercepted by a third party. This SSL Certificates is applied by Tencent to a third-party digital certificate certification authority such as CFCA. When applying, it is necessary to provide company information stamped with the official seal of the enterprise, and it can only be awarded after verification. Therefore, this SSL Certificates are unique like *** and cannot be forged.

Well, the page has a security certificate proving that it is officially released by WeChat and encrypted, but why is it still suspected of being a fraud page? First of all, the popularity of SSL Certificates in China's websites is too low, and most websites are not installed, which indirectly leads to little public knowledge and lack of awareness of checking page security certificates. The second is a defect of WeChat, that is, opening the webpage link with WeChat, unable to view the URL, also unable to view HTTPS and security lock logo, but also need users to click "open in browser" to view, which is troublesome.

On the one hand, CFCA security engineers should praise Tencent for using SSL Certificates to improve page security (hope all websites can follow suit); on the other hand, we also hope that in the future, if you use WeChat to open a webpage, the WeChat interface can display links or HTTPS and other security marks, which is helpful for users to distinguish authenticity. After all, if someone makes a page that is highly similar to the open class, it is against the user experience if the user still needs to open it with a browser to distinguish it.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report