HomeLatest ThreadsGreatest ThreadsForums & GroupsMy SubscriptionsMy Posts
DU Home » Latest Threads » Forums & Groups » Main » Latest Breaking News (Forum) » Android apps used by mill...

Mon Oct 22, 2012, 12:47 PM

Android apps used by millions vulnerable to password, e-mail theft

Source: ARS

Android applications downloaded by as many as 185 million users can expose end users' online banking and social networking credentials, e-mail and instant-messaging contents because the programs use inadequate encryption protections, computer scientists have found.

The researchers identified 41 applications in Google's Play Market that leaked sensitive data as it traveled between handsets running the Ice Cream Sandwich version of Android and webservers for banks and other online services. By connecting the devices to a local area network that used a variety of well-known exploits, some of them available online, the scientists were able to defeat the secure sockets layer and transport layer security protocols implemented by the apps. Their research paper didn't identify the programs, except to say they have been downloaded from 39.5 million and 185 million times, based on Google statistics.

"We could gather bank account information, payment credentials for PayPal, American Express and others," the researchers, from Germany's Leibniz University of Hannover and Philipps University of Marburg, wrote. "Furthermore, Facebook, email and cloud storage credentials and messages were leaked, access to IP cameras was gained and control channels for apps and remote servers could be subverted." Other exposed data included the contents of e-mails and instant messages.

A Google spokesman declined to comment. There was no evidence any of the vulnerable apps were developed by Google employees, although the researchers said there are steps Google engineers could take to better ensure Android apps implement the encryption more securely.

Read more: http://arstechnica.com/security/2012/10/android-apps-expose-passwords-e-mail-and-more/

2 replies, 1338 views

Reply to this thread

Back to top Alert abuse

Always highlight: 10 newest replies | Replies posted after I mark a forum
Replies to this discussion thread
Arrow 2 replies Author Time Post
Reply Android apps used by millions vulnerable to password, e-mail theft (Original post)
onehandle Oct 2012 OP
DreWId Oct 2012 #1
nebenaube Oct 2012 #2

Response to onehandle (Original post)

Mon Oct 22, 2012, 12:52 PM

1. Exploits built into the app

Forget hacks or exploits, why would a calculator app need access to my personal data, playlist, and location?

It's pretty ridiculous what permissions some of the apps out there ask for.

Reply to this post

Back to top Alert abuse Link here Permalink


Response to onehandle (Original post)

Mon Oct 22, 2012, 01:39 PM

2. ha...

The secure sockets layer and transport layer security protocols are provided by the OS and consumed by the apps. It's the same specification on any phone or computer.

Reply to this post

Back to top Alert abuse Link here Permalink

Reply to this thread