


· 夏末 (人像数枚) (2011-2-11) yeu008 · 【参加活动】Santa Pet Competition-大家圣诞快乐の麻麻也来凑热闹 (2010-12-7) 舞美拉
· 自助e-tax退税Deduction部分大汇编 (2006-9-21) neo · 我的故事:走出惊恐焦虑+抑郁,以及给病者家属的一点建议 (2008-8-1) dorin

我们一个新来的leader昨天踌躇满志的跟我说..... [复制链接]

发表于 2010-11-19 23:52 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 cdfei 于 2010-11-19 23:47 发表


发表于 2010-11-19 23:53 |显示全部楼层
此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-19 23:56 |显示全部楼层
此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整


参与人数 1积分 +3 收起 理由
乱码 + 3 你太有才了


发表于 2010-11-19 23:57 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 kawara 于 2010-11-19 23:53 发表


got it.

How does the Online Security Device Security Code work?
The Online Security Device generates a time-sensitive, single-use six digit Security Code for you to use when logging on to Internet Banking and for selected online transactions. The Security Code is generated by an algorithm based on time within the Online Security Device. Each Online Security Device has a matching file, stored securely in a database at HSBC, with the matching algorithm.

When you activate your Online Security Device, HSBC identifies which Device you have by asking you to enter the serial number. The serial number has no security value; it is simply a means of identifying to the Bank which Device a customer has. Once activated, a Device becomes unique to the PBN it was activated with.

When you are using Internet Banking and are required to enter a Security Code, the system compares the entered Code with the expected Code within the file. If they match, you are granted access. If they do not match, you will be asked to re-enter the Security Code.

http://www.hsbc.com.au/1/2/perso ... et-banking/faq/faq6

[ 本帖最后由 乱码 于 2010-11-19 23:59 编辑 ]

发表于 2010-11-19 23:58 |显示全部楼层

回复 91# 的帖子

此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:03 |显示全部楼层
此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整

主要是server 和token时间有误差的时候不好处理。


[ 本帖最后由 kawara 于 2010-11-20 00:05 编辑 ]

发表于 2010-11-20 00:03 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 cdfei 于 2010-11-19 23:58 发表



发表于 2010-11-20 00:05 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 kawara 于 2010-11-20 00:03 发表

主要是server 和token时间有误差的时候不好处理


发表于 2010-11-20 00:06 |显示全部楼层

回复 96# 的帖子

此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:07 |显示全部楼层
此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:11 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 乱码 于 2010-11-19 22:14 发表


我也同意带着javascript的确有隐患,不过要看产品对安全级别的要求,我不觉得我们的产品有什么值得去hack的东西,不过classic asp这个framework在安全上的support的确很有问题,稍微不注意,肯定被人ha ...


发表于 2010-11-20 00:12 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 cdfei 于 2010-11-20 00:06 发表
真正银行被击破导致偷钱的事情其实很少,主要还是木马、钓鱼网站等使客户密码用户名丢失,所以银行在验证客户身份上就很下功夫,起码中国的是这样。 ...



发表于 2010-11-20 00:13 |显示全部楼层
此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:14 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 kawara 于 2010-11-19 22:59 发表
过去的网站简单,整个网银也没几处JS,validation全部是server side,哪像现在都要求client side validation.以前的UX也就是要排版好看之类。

当时我们卖了个网银给南非的一家银行,人家有钱,从俄罗斯找了一帮从良的黑客来测 ...

当年有好多网站连SQL injection都不检测,完全是裸奔。但最近几年形势完全变了,看看CVE里面的entry,大的漏洞基本上都快挖完了,结构性的漏洞基本上没有了,现在能找到的基本上就是网管的愚蠢导致的东西

发表于 2010-11-20 00:16 |显示全部楼层

回复 102# 的帖子

此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:18 |显示全部楼层

回复 104# 的帖子

此文章由 cdfei 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 cdfei 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 00:19 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 乱码 于 2010-11-19 23:16 发表


https是传输方面用binary,防止有人在中间用proxy侦听,在客户这端可以用任何方式改request parameter,都没问题。

I'd call it encryption rather than binary - and SSL can be MITM attacked as well, if you know how to do it ;)

发表于 2010-11-20 00:19 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 bulaohu 于 2010-11-20 00:11 发表


同意,所以我会定期清清browser,尤其是log in自己银行帐户的时候,都用safari干这个,除了查帐,我根本不用它


参与人数 1积分 +6 收起 理由
bulaohu + 6 聪明


发表于 2010-11-20 00:20 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 乱码 于 2010-11-19 23:31 发表

申请客户证书是怎么回事?谁来issue? 也是3rd party well-known的机构么?年费是多少?有点搞阿~~


Same as server cert.

发表于 2010-11-20 00:22 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 乱码 于 2010-11-19 23:49 发表

我不是很明白这个数字狗的原理,你能解释一下么?是不是一组数对应一个用户,只要输入其中一个就可以?server side存者每个用户的那组数字?

Search for OTP


参与人数 1积分 +3 收起 理由
乱码 + 3 你太有才了


发表于 2010-11-20 00:22 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 cdfei 于 2010-11-20 00:16 发表


发表于 2010-11-20 00:25 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 cdfei 于 2010-11-20 00:13 发表


发表于 2010-11-20 00:26 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整

发表于 2010-11-20 08:27 |显示全部楼层
此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 bulaohu 于 2010-11-20 00:20 发表

Same as server cert.

不是的。搜索 mutral auth trust store

发表于 2010-11-20 08:38 |显示全部楼层


此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整
The Situation

When GraysOnline sought to re-develop their website, they were referred to Readify to help architect and develop the solution.

GraysOnline sought to augment their successful auction business with a range of fixed price "buy now" products.

This required a significant update to their existing web property to support the new sales model, providing an opportunity to revamp the existing website at the same time.

With the move into fixed price retailing, a key requirement of the solution was to provide a system upon which GraysOnline could rapidly develop and refine their offering.
The Solution

The solution was an e-Commerce system that encompassed everything from the internet website to back-end tools and integration components.

A team of Readify consultants led the effort to produce this system using ASP.NET with Commerce Server 2007 to build a rich and interactive shopping experience. In order to provide a consistent experience to all users, all HTML and CSS is standards compliant. Also, to ensure JavaScript was not a user requirement, the concept of progressive enhancement was enforced.

The result was a rich front-end application supporting auction and fixed price offerings to provide GraysOnline customers with a unified and satisfying experience when purchasing goods. It allows users to keep track of items they are bidding on in the same way a traditional retail website allows users to manage their cart.

The back-end tools provide the ability to manage products, users and marketing on the website. Business users utilise the standard business tools that are provided out of the box by Commerce Server, along with custom tools built during development to ensure the website runs smoothly with the provided content.

The integration components communicate events to other systems inside the GraysOnline ecosystem. Components were built to manage communication between Commerce Server and the existing warehousing and inventory systems, which were primarily built around auction principles.

The GraysOnline website is a great example of Readify's front-end engineering experience, combined with deep technical skills required to make a site of this magnitude perform.

Stewart McGrath, Chief Information Officer, GraysOnline commented, "Readify has been exceptionally flexible and adaptable to meet our needs and their core strength has been in the capability of its people".
The Methodology

Part of this engagement was the introduction of the SCRUM methodology to GraysOnline. Readify Principal Consultant, Richard Banks, was involved in training the developers and managers to comply with the SCRUM methodology. Team Foundation Server (TFS) and the Conchango SCRUM template were used to manage the User Stories, Sprints, Tasks and Bugs, thereby providing an integrated experience with Visual Studio and reporting tools to allow management to track the product development process.

Several quality indicators and were also automated. The use of TFS allowed for the setup of Continuous Integration builds that provided reporting on indicators such as unit test coverage and standards compliance. Deployments were automated in order to provide quick verification of build stability and ease of transition from one environment to another.

Over the lifetime of the project the team has had to adapt to changes in business drivers. While the website was in the initial phase of development, sprints were organised into two week iterations of work. During this phase the team grew to ten developers so it was split into two teams. Work was split amongst these two teams depending on the areas of expertise of developers.

Each of the development teams was provided with one or two testers depending on the size of the team at the time. The usual ratio of developers to testers was 2:1. This allowed for ongoing quality assurance.

Once the solution was deployed, feature development continued at a slower rate as stabilisation was the primary concern. Sprint durations were cut to one week in order to provide a quick turn-around on priority issues.
The Challenges

During development, it was necessary to maintain the classic site side-by-side in order to provide a smooth transition from one system to another. This also meant that GraysOnline could expose the new system to a select group of loyal customers to allow the opportunity of collecting feedback on the progression of the new concept.

It was also necessary to ensure the existing back-end systems, such as warehousing, inventory management and reporting, continued to function once the retail system was put in place. In order to achieve this, new back-end systems were created to foster the communication of events that occurred between the retail system and the existing back-end systems.
The Benefits

Implementing the retail solution using Commerce Server 2007 allowed the development team to quickly produce a fully functional e-commerce framework by utilising the catalogue, ordering, profiling and marketing sub-systems that it provides out of the box. This meant that development efforts could be focused on delivering a rich front-end experience to combine both the auction and retail businesses and give customers an interactive shopping experience - whether bidding or buying.

Readify delivered benefits to the partnership through the full lifecycle of the project in the form of SCRUM methodology coaching, requirement scoping, solution architecture, development and go-live transition management. Use of a strong SCRUM methodology allowed the project to adapt to and deliver upon a complex and changing scope.

"Readify has helped us execute code cutting, architecture, development processes and performance testing. We look forward to Readify's continued support", says McGrath.

The new GraysOnline site is a significant asset and is allowing Grays to expand into other business areas. Using Readify's ALM experience it is now possible for GraysOnline to easily maintain the solution and roll it out to production.

发表于 2010-11-20 09:03 |显示全部楼层
此文章由 bulaohu 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 bulaohu 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 kawara 于 2010-11-20 08:27 发表

不是的。搜索 mutral auth trust store

dude he's asking what a client cert is, not how mutual SSL authentication is performed I assume.

发表于 2010-11-20 09:50 |显示全部楼层
此文章由 kawara 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kawara 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 bulaohu 于 2010-11-20 09:03 发表

dude he's asking what a client cert is, not how mutual SSL authentication is performed I assume.



乱码知道cert是什么,他只是不确定client cert该由谁签发。

发表于 2010-11-20 13:02 |显示全部楼层
此文章由 乱码 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 乱码 所有!转贴必须注明作者、出处和本声明,并保持内容完整
原帖由 kawara 于 2010-11-20 09:50 发表

网站的certificate一般要大CA机构签发,像Verisign啥的,费用很高。原因是browser的truststore里面只有那几个大CA。其他的CA会被浏览器警告。可以编辑浏览器truststore避免,但是不能要求客户那么做,否则也失去了验证的意 ...

嗯,我只是不确定谁来issue这个certificate,如果每个行都采取client certificate的方式,还不如由银监会/人民银行来签发,这样形势更统一,在client那边只有一个certificate,而不是每个银行一个。

发表于 2010-11-20 18:35 |显示全部楼层
此文章由 典 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 典 所有!转贴必须注明作者、出处和本声明,并保持内容完整
我们公司使用Verisign, 好像不贵,可能是因为我们的网页只有几百个内部用户


发表于 2010-11-20 18:52 |显示全部楼层
此文章由 kr2000 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 kr2000 所有!转贴必须注明作者、出处和本声明,并保持内容完整


参与人数 1积分 +3 收起 理由
乱码 + 3 感谢分享



您需要登录后才可以回帖 登录 | 注册

