Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

This is a discussion on Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data within the Android News forums, part of the Android.net category; According to a new study by German researchers from Leibniz University in Hannover and Philipps University of Marburg, a large swath of Android apps apparently ...

Results 1 to 1 of 1

Thread: Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

  1. #1
    Editor in Chief dgstorm's Avatar
    Join Date
    Dec 2010
    Posts
    3,319
    Thanked
    239 times

    Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data


    According to a new study by German researchers from Leibniz University in Hannover and Philipps University of Marburg, a large swath of Android apps apparently do not implement their SSL correctly. The researchers sampled 13,000 apps and found that 1,000 of them exposed users' personal data. Here's a quote with a few more details,

    In this paper (PDF), the researchers from Leibniz University in Hannover and Philipps University of Marburg found that 17 percent of the SSL-using apps in their sample suffered from implementations that potentially made them vulnerable to man-in-the-middle MITM attacks.


    They state that they were “able to capture credentials from American Express, Diners Club PayPal, bank accounts, Facebook, Twitter, Google, Yahoo, Microsoft Live ID, Box, WordPress, remote control servers, arbitrary e-mail accounts, and IBM Sametime”.

    In addition, since virus software also uses SSL, “We were able to inject virus signatures into an anti-virus app to detect arbitrary apps as a virus or disable virus detection completely.”
    The researchers were able to determine that it wasn't really a flaw in Android, so much as it was sloppy or lazy implementation of the SSL. This seems rather disturbing. What do you guys think?

    Thanks for the tip, furbearingmammal!

    Source: Android apps get SSL wrong, expose personal data ? The Register

  2. # ADS
    Ads
    Google Advertisement
    Join Date
    Always
    Posts
    Many
    Android.net is the premier Android Forum on the internet.


Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Similar Threads

  1. Replies: 25
    Last Post: 05-08-2013, 12:33 AM
  2. Lock Your Apps and Data on Android Easily
    By akapribot in forum Android Apps
    Replies: 1
    Last Post: 08-28-2012, 10:10 AM
  3. Find Apps Not Just Depend on Keywords
    By bravose in forum Android Forum
    Replies: 2
    Last Post: 03-12-2012, 03:47 AM
  4. How to Find Apps or Games that You Exactly Want
    By bravose in forum Android Forum
    Replies: 0
    Last Post: 02-02-2012, 09:10 PM
  5. Where do you find data usage?
    By georgiaed in forum Introductions & Site Assistance
    Replies: 2
    Last Post: 01-02-2011, 08:01 AM

Search tags for this page

researchers at the leibniz university of hannover and the philipps university of marburg android

Click on a term to search our sites for related topics.
Android Forum