BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.hackfest.ca//hf2022//talk//GCKBJA
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hf2022-GCKBJA@cfp.hackfest.ca
DTSTART;TZID=EST:20221029T090000
DTEND;TZID=EST:20221029T092000
DESCRIPTION:In 2022\, most of us have bought goods and services online or u
 sing mobile apps\, for convenience\, for safety (e.g.\, pandemic) or as a 
 matter of personal preference. As mobile payments and integrations with th
 ird-party payment processors become more and more prevalent\, common AppSe
 c mistakes from the past reappear under new forms. Merchants who overlook 
 security best practices and fail to secure their systems can be victims of
  fraud.\n\nIn this talk\, we will cover some examples of payment APIs and 
 mobile in-app purchases (e.g.\, with Apple Pay or Google Play Store) that 
 fail to perform sufficient validation in ways that may have devastating fi
 nancial and reputational impact to merchants. We aim to bring awareness to
  these often-overlooked issues and provide recommendations to avoid these 
 vulnerabilities with real-world examples.
DTSTAMP:20260711T182543Z
LOCATION:Track 2
SUMMARY:Defrauding merchants like it’s Y2K - Craig Barretto\, Yuk Fai Chan
URL:https://cfp.hackfest.ca/hf2022/talk/GCKBJA/
END:VEVENT
END:VCALENDAR
