Many Android Apps Identified For Leaking Sensitive Data
As many as 41 apps in Google’s Play Market were found to leak sensitive data, such as online banking and social networking credentials, as well as email and instant messaging communications. The programs identified were running on handsets using the Ice Cream Sandwich version of Android software. The apps that make user phones vulnerable were identified in a research paper published by computer scientists at the Leibniz University of Hannover and the Philipps University of Marburg, both in Germany.
Specific apps were not identified, however researchers conducted analysis on 13,500 free apps they downloaded from the Google Play Market. Findings conclude that as many as 39.5 million users have downloaded these apps 185 million times, according to statistics listed by Google.
The researchers identify the legitimate need for apps to communicate over the internet, yet say these apps are then responsible for protecting potentially sensitive data during transit. Not all apps follow through in shoring up security holes. The paper looks to understand the potential security threats posed by Android apps that use SSL and TLS protocols to protect the data transmitted. According to researchers, benign apps inadvertently contain inadequate SSL/TLS code that is potentially vulnerable to Man-in-the-Middle (MITL) attacks.
Using a tool called MalloDroid, researchers were able to detect which apps expose potential vulnerability against MTIM attacks. In the paper, researchers identified 1,074 (8%) of the apps examined contained SSL/TLS code that is potentially vulnerable to MITM attacks.
The problem is the apps failed to implement standard scrambling systems, according to an article in BBC News on the paper. Failure to scramble the data allows MITM attacks to reveal data that passes back and forth between devices and websites or servers.
To conduct the study, researchers created a fake Wi-Fi hotspot using a specially created attack tool, MalloDroid, to spy on the data the apps sent to servers. BBC News reports that researchers were able to identify a number of ways data were revealed. Researchers were able to capture login details for online bank accounts, email services, social media sites and corporate networks. They were also able to disable security programs, or fool programs into labeling secure apps as infected. The programmers were able to inject computer code into the data stream that made apps carry out specific commands.
Even if the apps themselves were not designed to capitalize on this data, the apps allow a back door for hackers and others who are looking to gain access to phones and the data on them.
“We could gather bank account information, payment credentials for PayPal, American Express and others,” Ars Technica quotes the researchers on the paper as explaining. “Furthermore, Facebook, email and cloud storage credentials and messages were leaked, access to IP cameras was gained and control channels for apps and remote servers could be subverted.
Findings shine a light on the vulnerabilities of SSL and TLS protocols. Ars Technica said the technology itself is generally considered secure, yet any security measures can be undermined when certificate authorities don’t take the steps necessary to secure their infrastructure.
redOrbit.com
offers Science, Space, Technology, Health news, videos, images and
reference information. For the latest science news, space news,
technology news, health news visit redOrbit.com frequently. Learn
something new every day.\”
2012-10-23 04:25:38
Source: http://www.redorbit.com/news/technology/1112717729/android-apps-security-issues-102212/
Source:
Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.
"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.
LION'S MANE PRODUCT
Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules
Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.
Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.
