之前在網上有新聞曝光,有人利用改裝過后的共享充電寶(bao)來盜取用戶的個人信息,甚至讓手機中病毒,這對共享充電的推廣發展造成了很壞的影響。也倒逼共享充電器必須要想出反制措施,挽回聲譽。那么,今天我們就了解一下,“他們”是如何盜取用戶信息的呢?
利用充(chong)電(dian)(dian)(dian)來惡意侵入手(shou)機(ji)(ji)(ji)其實早已有(you)之(zhi),像前兩年就遍布各地的(de)充(chong)電(dian)(dian)(dian)樁(zhuang)在(zai)手(shou)機(ji)(ji)(ji)接(jie)入此(ci)類(lei)充(chong)電(dian)(dian)(dian)樁(zhuang)時,會(hui)(hui)被(bei)要求(qiu)授權(quan)使用,此(ci)時安(an)卓(zhuo)手(shou)機(ji)(ji)(ji)上會(hui)(hui)出現是否“允許USB調試”,點擊“確(que)定”即(ji)同意電(dian)(dian)(dian)腦對手(shou)機(ji)(ji)(ji)進行操作,包括安(an)裝軟(ruan)件等。因(yin)此(ci),在(zai)不確(que)定的(de)設備安(an)全(quan)的(de)情況下,請點擊“取消”,可(ke)以充(chong)電(dian)(dian)(dian)但不授權(quan)使用。IOS手(shou)機(ji)(ji)(ji)相對而(er)言比安(an)卓(zhuo)手(shou)機(ji)(ji)(ji)更安(an)全(quan),IOS手(shou)機(ji)(ji)(ji)鏈接(jie)到此(ci)類(lei)充(chong)電(dian)(dian)(dian)樁(zhuang)時會(hui)(hui)出現“信(xin)任(ren)或不信(xin)任(ren)”,在(zai)點擊信(xin)任(ren)后手(shou)機(ji)(ji)(ji)即(ji)授權(quan)了(le)計算機(ji)(ji)(ji)操作使用,發生信(xin)息劫持(chi)情況。
而改裝(zhuang)的(de)(de)過的(de)(de)共(gong)享充(chong)電(dian)(dian)(dian)寶則是(shi)利用(yong)植入微(wei)(wei)型(xing)電(dian)(dian)(dian)腦竊取(qu)信息。RPI是(shi)為學習計算機編程教育而設計,只有信用(yong)卡大小的(de)(de)微(wei)(wei)型(xing)電(dian)(dian)(dian)腦,可(ke)以(yi)藏在被改裝(zhuang)過的(de)(de)充(chong)電(dian)(dian)(dian)寶里。通常充(chong)電(dian)(dian)(dian)寶由電(dian)(dian)(dian)路(lu)(lu)板和電(dian)(dian)(dian)池(chi)電(dian)(dian)(dian)芯(xin)兩部組成,電(dian)(dian)(dian)路(lu)(lu)板的(de)(de)作(zuo)用(yong)是(shi)電(dian)(dian)(dian)壓轉換和保(bao)護電(dian)(dian)(dian)芯(xin);電(dian)(dian)(dian)池(chi)電(dian)(dian)(dian)芯(xin)的(de)(de)作(zuo)用(yong)是(shi)給(gei)手機充(chong)電(dian)(dian)(dian)。
改裝(zhuang)后的(de)充電寶就是電路(lu)板上(shang)多了一(yi)塊RPI。當用戶通(tong)(tong)過(guo)充電線給手機(ji)充電時(shi)候,藏(zang)匿在共享充電寶里的(de)RPI會像冥(ming)王哈迪斯偷偷劫走豐收女神的(de)女兒(er)珀(po)爾塞(sai)福(fu)涅一(yi)樣,通(tong)(tong)過(guo)USB接口對手機(ji)上(shang)的(de)數據進行劫持。