【特朗普簽行政命令 禁支付寶等8個中國應用程式交易】
據《路透社》報道,美國總統特朗普簽署行政命令,禁止美國人與8個中國應用程式進行交易。
8個程式包括支付寶、WeChat Pay、騰訊QQ、QQ Wallet、WPS Office、掃描全能王(CamScanner)、VMate和SHAREit。
美國商務部長羅斯表示,支持特朗普致力保護美國人的私隱和安全,免受中共威脅。
全文︰http://www.passiontimes.hk/article/01-06-2021/69364
#支付寶
請支持PassionPrime:
http://passiontimes.hk/prime/
請支持熱血時報印刷版︰
http://passiontimes.hk/4.0/regform.php
請支持熱血文青課金計劃:
http://www.passiontimes.hk/?view=raise2
請支持熱血主持育成計劃:
http://www.passiontimes.hk/?view=raise
《熱血時報》 iOS,Android App 歡迎下載:
iPhone
https://apple.co/2IfgPoP
Android
https://bit.ly/2HqB4Q4
--------------------
成功之前,我們絕對不要放棄夢想!
Till our dreams come true, we'll fight on.
「全能掃描王安全」的推薦目錄:
- 關於全能掃描王安全 在 PassionTimes 熱血時報 Facebook 的最佳貼文
- 關於全能掃描王安全 在 洞見國際事務評論-Insight Post Facebook 的最讚貼文
- 關於全能掃描王安全 在 唐家婕 - Jane Tang Facebook 的最讚貼文
- 關於全能掃描王安全 在 [討論] 「掃描全能王」被發現含有特洛伊木馬- 看板MobileComm 的評價
- 關於全能掃描王安全 在 電腦職人東東- 過去「掃描全能王」是安全的 - Facebook 的評價
- 關於全能掃描王安全 在 [討論] 「掃描全能王」被發現含有特洛伊木馬 - Mo PTT 鄉公所 的評價
- 關於全能掃描王安全 在 [討論] 「掃描全能王」被發現含有特洛伊木馬- 看板MobileComm 的評價
- 關於全能掃描王安全 在 掃描全能王有毒嗎?沒被下架? - Mobile01 的評價
全能掃描王安全 在 洞見國際事務評論-Insight Post Facebook 的最讚貼文
川普簽署行政命令,禁止使用支付寶以及其他數個中國App
其他App包含「掃描全能王」CamScanner、騰訊QQ錢包、VMate、微信支付、WPS Office。
此禁令以資安疑慮為由。其中不乏已經被第三方資安公司多次警告有安全漏洞的App,例如掃描全能王。
美國商務部預計會在1/20川普卸任之前,對此命令採取行動。
資料來源:華爾街日報、耶路撒冷郵報
https://www.wsj.com/articles/trump-signs-order-banning-alipay-and-other-chinese-apps-11609889364?st=jzvetr6rxlo3hzx&reflink=article_copyURL_share
https://m.jpost.com/breaking-news/trump-signs-order-banning-transactions-with-8-chinese-apps-report-654402
全能掃描王安全 在 唐家婕 - Jane Tang Facebook 的最讚貼文
Breaking‼️
美東時間1月5日傍晚,川普以國家安全為由,用行政命令方式禁止阿里支付寶、微信支付、QQ錢包在內的8款中國應用程式(App)。
行政命令發佈後45天,禁止任何人與實體與這8款中國應用程式(App)進行交易。
按照日程,美國下任政府將在15天後,1月20日上任。
—
美國商務部長在同一時間發聲明表示,已指示商務部按行政命令執行禁令,「支持川普總統保護美國人民隱私與安全,免於受到中國共產黨的威脅。」
—
▫️8款App:
支付寶(Alipay)、掃描全能王(CamScanner)、QQ錢包(QQ Wallet)、茄子快傳(SHAREit)、騰訊QQ(Tencent QQ)、阿里巴巴旗下海外短視頻應用VMate、微信支付(WeChat Pay)和辦公型App WPS Office。
圖三:美國商務部聲明
圖四:美國國安顧問聲明
—
▫️白宮行政命令全文:
The White House
Office of the Press Secretary
FOR IMMEDIATE RELEASE
January 5, 2021
EXECUTIVE ORDER
- - - - - - -
ADDRESSING THE THREAT POSED BY APPLICATIONS AND OTHER SOFTWARE DEVELOPED OR CONTROLLED BY CHINESE COMPANIES
By the authority vested in me as President by the Constitution and the laws of the United States of America, including the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.) (IEEPA), the National Emergencies Act (50 U.S.C. 1601 et seq.), and section 301 of title 3, United States Code,
I, DONALD J. TRUMP, President of the United States of America, find that additional steps must be taken to deal with the national emergency with respect to the information and communications technology and services supply chain declared in Executive Order 13873 of May 15, 2019 (Securing the Information and Communications Technology and Services Supply Chain). Specifically, the pace and pervasiveness of the spread in the United States of certain connected mobile and desktop applications and other software developed or controlled by persons in the People's Republic of China, to include Hong Kong and Macau (China), continue to threaten the national security, foreign policy, and economy of the United States. At this time, action must be taken to address the threat posed by these Chinese connected software applications.
By accessing personal electronic devices such as smartphones, tablets, and computers, Chinese connected software applications can access and capture vast swaths of information from users, including sensitive personally identifiable information and private information. This data collection threatens to provide the Government of the People's Republic of China (PRC) and the Chinese Communist Party (CCP) with access to Americans' personal and proprietary information -- which would permit China to track the locations of Federal employees and contractors, and build dossiers of personal information.
The continuing activity of the PRC and the CCP to steal or otherwise obtain United States persons' data makes clear that there is an intent to use bulk data collection to advance China's economic and national security agenda. For example, the 2014 cyber intrusions of the Office of Personnel Management of security clearance records of more than 21 million people were orchestrated by Chinese agents. In 2015, a Chinese hacking group breached the United States health insurance company Anthem, affecting more than 78 million Americans. And the Department of Justice indicted members of the Chinese military for the 2017 Equifax cyber intrusion that compromised the personal information of almost half of all Americans.
In light of these risks, many executive departments and agencies (agencies) have prohibited the use of Chinese connected software applications and other dangerous software on Federal Government computers and mobile phones. These prohibitions, however, are not enough given the nature of the threat from Chinese connected software applications. In fact, the Government of India has banned the use of more than 200 Chinese connected software applications throughout the country; in a statement, India's Ministry of Electronics and Information Technology asserted that the applications were "stealing and surreptitiously transmitting users' data in an unauthorized manner to servers which have locations outside India."
The United States has assessed that a number of Chinese connected software applications automatically capture vast swaths of information from millions of users in the United States, including sensitive personally identifiable information and private information, which would allow the PRC and CCP access to Americans' personal and proprietary information.
The United States must take aggressive action against those who develop or control Chinese connected software applications to protect our national security.
Accordingly, I hereby order:
Section 1. (a) The following actions shall be prohibited beginning 45 days after the date of this order, to the extent permitted under applicable law: any transaction by any person, or with respect to any property, subject to the jurisdiction of the United States, with persons that develop or control the following Chinese connected software applications, or with their subsidiaries, as those transactions and persons are identified by the Secretary of Commerce (Secretary) under subsection (e) of this section: Alipay, CamScanner, QQ Wallet, SHAREit, Tencent QQ, VMate, WeChat Pay, and WPS Office.
(b) The Secretary is directed to continue to evaluate Chinese connected software applications that may pose an unacceptable risk to the national security, foreign policy, or economy of the United States, and to take appropriate action in accordance with Executive Order 13873.
(c) Not later than 45 days after the date of this order, the Secretary, in consultation with the Attorney General and the Director of National Intelligence, shall provide a report to the Assistant to the President for National Security Affairs with recommendations to prevent the sale or transfer of United States user data to, or access of such data by, foreign adversaries, including through the establishment of regulations and policies to identify, control, and license the export of such data.
(d) The prohibitions in subsection (a) of this section apply except to the extent provided by statutes, or in regulations, orders, directives, or licenses that may be issued pursuant to this order, and notwithstanding any contract entered into or any license or permit granted before the date of this order.
(e) Not earlier than 45 days after the date of this order, the Secretary shall identify the transactions and persons that develop or control the Chinese connected software applications subject to subsection (a) of this section.
Sec. 2. (a) Any transaction by a United States person or within the United States that evades or avoids, has the purpose of evading or avoiding, causes a violation of, or attempts to violate the prohibition set forth in this order is prohibited.
(b) Any conspiracy formed to violate any of the prohibitions set forth in this order is prohibited.
Sec. 3. For the purposes of this order:
(a) the term "connected software application" means software, a software program, or group of software programs, designed to be used by an end user on an end-point computing device and designed to collect, process, or transmit data via the Internet as an integral part of its functionality.
(b) the term "entity" means a government or instrumentality of such government, partnership, association, trust, joint venture, corporation, group, subgroup, or other organization, including an international organization;
(c) the term "person" means an individual or entity;
(d) the term "personally identifiable information" (PII) is information that, when used alone or with other relevant data, can identify an individual. PII may contain direct identifiers (e.g., passport information) that can identify a person uniquely, or quasi-identifiers (e.g., race) that can be combined with other quasi-identifiers (e.g., date of birth) to successfully recognize an individual.
(e) the term "United States person" means any United States citizen, permanent resident alien, entity organized under the laws of the United States or any jurisdiction within the United States (including foreign branches), or any person in the United States.
Sec. 4. (a) The Secretary, in consultation with the Secretary of the Treasury and the Attorney General, is hereby authorized to take such actions, including adopting rules and regulations, and to employ all powers granted to me by IEEPA, as may be necessary to implement this order. All agencies shall take all appropriate measures within their authority to implement this order.
(b) The heads of agencies shall provide, in their discretion and to the extent permitted by law, such resources, information, and assistance to the Department of Commerce as required to implement this order, including the assignment of staff to the Department of Commerce to perform the duties described in this order.
Sec. 5. Severability. If any provision of this order, or the application of any provision to any person or circumstance, is held to be invalid, the remainder of this order and the application of its other provisions to any other persons or circumstances shall not be affected thereby.
Sec. 6. General Provisions. (a) Nothing in this order shall be construed to impair or otherwise affect:
(i) the authority granted by law to an executive department, agency, or the head thereof; or
(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.
(b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations.
(c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.
DONALD J. TRUMP
THE WHITE HOUSE,
January 5, 2021.
全能掃描王安全 在 電腦職人東東- 過去「掃描全能王」是安全的 - Facebook 的推薦與評價
過去「掃描全能王」是安全的,但最近的免費廣告版卻藏了惡意程式,會悄悄強制下載各種攻擊的木馬程式,會讓App 有更多的彈出式廣告、偷偷複製銀行 ... ... <看更多>
全能掃描王安全 在 [討論] 「掃描全能王」被發現含有特洛伊木馬 - Mo PTT 鄉公所 的推薦與評價
幾乎可以說是市面上最知名的掃描軟體「掃描全能王」(Cam Scanner,或 ... iOS 的還沒被下架,不知道安不安全在「生產力工具」類中排名第12. ... <看更多>
全能掃描王安全 在 [討論] 「掃描全能王」被發現含有特洛伊木馬- 看板MobileComm 的推薦與評價
知名安卓軟體「掃描全能王」被發現含有特洛伊木馬!下載量超過一億次
由 小柴犬 · 八月 28, 2019
習慣使用手機取代掃描機的安卓用戶要注意了!
幾乎可以說是市面上最知名的掃描軟體
「掃描全能王」(Cam Scanner,或叫CamScanner — Phone PDF Creator 和
CamScanner-Scanner to scan PDFs,掃描全能王)
被卡巴斯基發現內含惡意的廣告模組,建議立即刪除!
全球許多人使用的掃描軟體,竟然內含惡意廣告模組
卡巴斯基發現,這個惡意模組是一個特洛伊木馬程式,
這意味著它被設計成「惡意軟件的傳遞工具」,
可以使用dropper來安裝竊取銀行憑據或生成虛假廣告點擊,
或製造假的訂閱。
卡巴斯基將這個惡意模組命名為「Trojan-Dropper.AndroidOS.Necro.n」,
研究人員建議,所有有安裝這款軟體的人應該立刻移除。
部分來自中國的手機,甚至預先安裝了這款軟體,一樣造成了非常麻煩的資安隱憂。
目前Google Play上已經將「掃描全能王」下架了。
消息來源:卡巴斯基
https://www.kaspersky.com/blog/camscanner-malicious-android-app/28156/
來源:
https://applealmond.com/posts/57647
-----
又有 APP 被指出有資安疑慮,
但這種 APP 現在還很多人用嗎?
近幾年以台灣來說應該比較少人使用吧?
有下載或被內建的人要注意一下囉。
公司:
上海合合信息
https://www.ccint.com/personal-camscanner
官方聲明:
https://www.camscanner.com/disclaimer/gpException
給了新的 APK 載點
微博:
https://bit.ly/2PkW53T
Reddit:
CamScanner booted from Play Store after discovery of malicious code
https://bit.ly/2PjxUmt
May 22, 2019: 5.10.6.20190522 – safe
June 6, 2019: 5.11.0.20190611 – safe
June 14, 2019: 5.11.3.20190614 – safe
June 16, 2019: 5.11.3.20190616 – unsafe
June 24, 2019: 5.11.5.20190624 – unsafe
July 10, 2019: 5.11.7.20190710 – unsafe
July 23, 2019: 5.12.0.20190723 – unsafe
July 25, 2019: 5.12.0.20190725 – unsafe
July 30, 2019: 5.12.0.20190730 – safe
August 8, 2019: 5.12.3.20190809 – safe
August 14, 2019: 5.12.3.20190814 – safe
August 16, 2019: 5.12.5.20190816 – safe
August 20, 2019: 5.12.5.20190820 – safe
Trojan Dropper Malware Found in CamScanner,
Google removed the app from the Play Store
after Kaspersky's researchers reported their findings
https://bit.ly/2zqWBCx
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 220.133.14.178 (臺灣)
※ 文章網址: https://www.ptt.cc/bbs/MobileComm/M.1567007606.A.4BF.html
這款被下架 當然搜尋不到
人家是谷歌的編輯精選(Editors' Choice)欸
https://bit.ly/2zvw32Q
iOS 的還沒被下架,不知道安不安全
在「生產力工具」類中排名第 12
https://apps.apple.com/tw/app/camscanner-free-pdf-document/id388627783
上海合合信息
Kaspersky researchers examined
a recent version of the app and found the malicious module there.
是檢驗最近的版本發現的
We reported our findings to Google,
and the app was promptly removed from Google Play.
還在的是不同東西
還在的是不同東西
官方發了聲明,還給了新的APK載點
Dear CamScanner Android Users,
Our CamScanner Team has recently detected that the advertisement SDK provided by a third-party named AdHub, integrated in Android Version 5.11.7, has been reported for containing a malicious module that produces unauthorized advertising clicks.
Injection of any suspicious codes violates the CamScanner Security Policy! We will take immediate legal actions against Adhub! Fortunately, after rounds of security check, we have not found any evidence showing the module could cause any leak of document data.
We have removed all the ads SDKs not certified by Google Play and a new version would be released. Meanwhile, you may contact [email protected] for a direct upgrade or tap HERE to download the new version.
We would appreciate your patience and understanding.
Best Regards,
CamScanner
※ 編輯: kouta (220.133.14.178 臺灣), 08/29/2019 15:02:05
... <看更多>