Disclaimer
Effective Date: August 31, 2026
This disclaimer applies to all online tools, knowledge base articles, and specification index content provided by CardWise at cupass.com. By using this website, you acknowledge that you have read and agree to this disclaimer.
1. Tool Usage Risks
The online tools provided on this website (including but not limited to APDU status word reference, ATR decoder, TLV parser, GP key derivation calculator, AES/SM4 encryption, RSA, SM2, X.509 certificate parser, and others) are based on well-established algorithms and the Web Crypto API. However:
- No guarantee of accuracy: While we make every effort to ensure the correctness of tool outputs, we do not warrant the absolute accuracy, completeness, or fitness for a particular purpose of any result. Tool outputs may vary due to browser implementation differences, JavaScript engine precision, or input data format issues.
- Not professional advice: Tool outputs do not constitute professional advice in security engineering, cryptography, or law. For security-critical decisions, consult a qualified professional.
- User responsibility: You are solely responsible for any results and decisions arising from your use of the tools on this website.
2. Cryptographic Tool Limitations
Our cryptographic tools (AES, RSA, SM2, SM3, SM4, HMAC, hash digests, etc.) are implemented in the browser environment. Browser-based cryptography has the following inherent limitations:
- Memory management: JavaScript's garbage collection mechanism may cause key material to remain in memory for unpredictable durations, creating side-channel attack risks.
- Uncontrolled environment: Browser extensions, other page scripts, or underlying runtime environments may compromise the security of cryptographic operations.
- Not for production: Production-grade key generation, digital signing, encryption, and decryption should use certified Hardware Security Modules (HSM) or dedicated cryptographic devices. Browser-based cryptographic tools are suitable only for development, debugging, learning, and prototype validation.
The cryptographic algorithm implementations we use come from the Web Crypto API (browser-native) and community-verified open-source libraries. However, correct algorithm implementation does not equal secure usage — correct algorithms used in the wrong environment can still produce security issues.
3. Smart Card Operation Risks
Our smart card-related tools (APDU command reference, ATR parsing, AID lookup, GP key derivation, EMV tag lookup, etc.) are provided for reference and debugging purposes only:
- Different card vendors' COS implementations may vary; APDU command behavior may not fully match standard descriptions.
- Key derivation and session key calculation results must be verified on the target card platform before use.
- Before performing operations on real cards, always test thoroughly on test cards and follow your security policies and operational procedures.
- We are not liable for card damage, data loss, or security incidents resulting from improper use of our tools.
4. Specification and Standards Copyright
Our specification index pages provide summaries and official links to standards from organizations including ISO, EMVCo, GlobalPlatform, ETSI, GSMA, 3GPP, NIST, PBOC, and Chinese national cryptographic standards.
- Summaries, not full text: We only provide brief summaries and key information about standards. We do not store or provide full PDF texts or complete electronic versions of any standard.
- Copyright belongs to the organizations: All standard copyrights belong to their respective publishing organizations. To obtain full standard texts, please purchase or download through official channels.
- Information is for reference only: Summary content may contain inaccuracies due to our interpretation or standard updates. Always refer to the officially published standard text as authoritative.
5. Third-Party Links
This website contains links to third-party websites, including but not limited to:
- Official standards organization websites (ISO, EMVCo, NIST, etc.)
- Product retailers (such as Amazon affiliate links)
- Technical documentation and open-source projects
We are not responsible for the content, privacy practices, or product availability of these third-party websites. When visiting third-party sites, please review their respective privacy policies and terms of service. Third-party website content, pricing, and availability may change at any time without our monitoring.
6. Amazon Affiliate Disclosure
The English edition of this website (cupass.com/en/) is a participant in the Amazon Services LLC Associates Program. This means certain product links are Amazon affiliate advertising links. As an Amazon Associate, we earn a commission from qualifying purchases. This commission is paid by Amazon and does not increase your purchase price.
Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.
7. Advertising Notice
This website may display advertisements through third-party ad networks. Ad content is served by the ad network based on your browsing history and interests, and we cannot fully control the specific ads shown. If you encounter inappropriate advertisements, please report them to [email protected].
8. Content Currency
Our knowledge base articles and tool implementations may become outdated as technology evolves. We strive to update content regularly but cannot guarantee that all information is current. Please refer to the latest versions of relevant standards and official documentation for authoritative information.
9. Contact
If you have any questions about this disclaimer, please contact us:
- Email: [email protected]
See also: Privacy Policy | Terms of Service | About Us | Contact Us