website statistics

A number of researchers, who have been examining the security of Android apps, have revealed that a significant number of these apps have poor SSL implementations, leaving critical vulnerabilities.
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading...

Google has been trying to up the quality of apps in the Google Play store. However, Android apps still lack a lot when it comes to security and quality, in comparison with iOS apps. Now, a new group of researchers has confirmed this, citing poor SSL implementations in many Android apps.


Google Play

The research was a joint collaboration between multiple German universities and during the course of it, 13,500 popular Google Play apps were analysed. Surprisingly, more than 1,000 of these apps had rather poor SSL/TLS implementations, leaving them open to serious security exploits.

Poor SSL implementation in an app leaves it open to the middle-man attack. This means that a person can intercept critically important data between the user and the app developer. The data may comprise of personal information as well as financial credentials.

To prove the case, the researchers mounted a proof-of-concept attack against the vulnerable apps and were able to gather credit card numbers, bank account details as well as detailed information of the users’ social media accounts.

According to the paper published by these researchers, “Of the 100 apps selected for manual audit, 41 apps proved to have exploitable vulnerabilities. We could gather bank account information, payment credentials for PayPal, American Express and others. Furthermore, Facebook, email and cloud storage credentials and messages were leaked, access to IP cameras was gained and control channels for apps and remote servers could be subverted.”

While that serves as a reminder for Google to improve the security of the apps it hosts on Google Play store, it is also a warning for the users. While the official apps from notable vendors are often fool-proof security-wise, third-party apps are not always secure.

A security researcher advised Android users to be careful when using such third-party apps, “As far as users go, I think the biggest lesson to be learned is that downloading third-party unofficial apps can be risky (eg.  downloading an unofficial banking app instead of the one actually released by your bank) for a number of reasons including poor coding practices.”

Source: Research Paper

Courtesy: Threat Post

Buy Cheapest Related Product From Amazon.com


NASA Developing A Service Robot That Will Refuel Satellites

Rovio Teases Angry Birds Star Wars With “Too Short” Trailer
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On October 22, 2012(3 years, 10 months ago.)

You May Also Like:

What Do You Think?

Leave a Reply




Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.


Recent Search

Recent Tutorials

Check out this tutorial to know how to install Apple watchOS 3 beta certificate on your Apple Watch and start enjoying the new version.
If you are trying to jailbreak iPhone, iPad or iPod on iOS 9.2 - 9.3.3 without using a computer or Apple ID, then check this video tutorial.
Pokemon Go users are complaining about the crashing and server issues. Check out the tutorial to solve error problems and thanks us later.
Turning off Wi-Fi Assist is a great way to save mobile data since it automatically starts using cellular data when Wi-Fi signal is poor .
If you want to secure your SIM card from others using it, then check out this tutorial to know how to set up the SIM Pin code on your iPhone.
CiderTV is a great alternative to control Apple TV from the Notification Center. Check out this tutorial to set up CiderTV on your iPhone.
Are you annoyed by the split screen mode on the iPhone 6 Plus or 6s Plus? Check out this quick tutorial to turn off split screen feature.
If you could not wait to installed the iOS 10 beta version on you iPhone and now struggling for the errors, then this tutorial is for you.
Siri might not understand the question you asked. But you can use Siri by editing the text that you asked & it will give an updated answer.
Perhaps, you are new Apple user and you might have no idea how to change name of your iPhone. Check out this tutorial to change the name.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook