Hello and welcome to our community! Is this your first visit?
Register
Reigster at Galaxy S3 Forums
Results 1 to 9 of 9
Like Tree6Likes
  • 4 Post By CR6
  • 2 Post By RyanJ

Thread: Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

  1. #1
    Super Moderator dgstorm's Avatar
    Join Date
    May 2012
    Posts
    443
    Member #
    7
    Liked
    160 times

    Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data


    According to a new study by German researchers from Leibniz University in Hannover and Philipps University of Marburg, a large swath of Android apps apparently do not implement their SSL correctly. The researchers sampled 13,000 apps and found that 1,000 of them exposed users' personal data. Here's a quote with a few more details,

    In this paper (PDF), the researchers from Leibniz University in Hannover and Philipps University of Marburg found that 17 percent of the SSL-using apps in their sample suffered from implementations that potentially made them vulnerable to man-in-the-middle MITM attacks.


    They state that they were “able to capture credentials from American Express, Diners Club PayPal, bank accounts, Facebook, Twitter, Google, Yahoo, Microsoft Live ID, Box, WordPress, remote control servers, arbitrary e-mail accounts, and IBM Sametime”.

    In addition, since virus software also uses SSL, “We were able to inject virus signatures into an anti-virus app to detect arbitrary apps as a virus or disable virus detection completely.”
    The researchers were able to determine that it wasn't really a flaw in Android, so much as it was sloppy or lazy implementation of the SSL. This seems rather disturbing. What do you guys think?

    Thanks for the tip, furbearingmammal!

    Source: Android apps get SSL wrong, expose personal data ? The Register

  2. #2
    Administrator CR6's Avatar
    Join Date
    May 2012
    Location
    Idaho
    Posts
    7,295
    Member #
    19
    Liked
    2691 times
    Device
    United States SCH-I535

    Re: Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

    Oh that's nice! (sarcasm)

    tap'n



    Welcome to the Galaxy S3 Forums!

    Guidelines of Conduct

  3. #3
    Senior Member RyanJ's Avatar
    Join Date
    Sep 2012
    Posts
    121
    Member #
    2434
    Liked
    3 times
    These issues make me wish I had stayed with apple...

  4. #4
    Administrator CR6's Avatar
    Join Date
    May 2012
    Location
    Idaho
    Posts
    7,295
    Member #
    19
    Liked
    2691 times
    Device
    United States SCH-I535

    Re: Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

    You're sorely misinformed if you think this can't happen on an iPhone. Security risks , collecting of personal data, malware, etc can and do happen on iPhones as well. A simple Google search will yield plenty of articles/instances if you're so inclined to look. Here's just one of many interesting articles that brings to light the false sense of security that many Apple users blindly trust in by believing they're immune from issues such as this. http://anti-virus-rants.blogspot.com...-free.html?m=1

    tap'n
    Jeffrey, Mujibar, jwalz and 1 others like this.



    Welcome to the Galaxy S3 Forums!

    Guidelines of Conduct

  5. #5
    Senior Member RyanJ's Avatar
    Join Date
    Sep 2012
    Posts
    121
    Member #
    2434
    Liked
    3 times
    Wow I guess your right.... and I was one of the blind ones that thought that!

  6. #6
    Super Moderator Jeffrey's Avatar
    Join Date
    May 2012
    Location
    Thailand
    Posts
    2,877
    Member #
    71
    Liked
    743 times
    Device
    International GT-I9300
    Quote Originally Posted by RyanJ View Post
    These issues make me wish I had stayed with apple...
    You can always go back.....
    Galaxy S3 I9300 Rooted Running WanamLite JB 4.2.1
    Asus TF 101 16 Gig B60 W/Dock
    Macbook Pro 13.3
    Asus N56U Wireless Network Router
    Airport Extreme Wireless Router
    Asus WL-330N3G Portable Wireless Router



  7. #7
    Super Moderator Jeffrey's Avatar
    Join Date
    May 2012
    Location
    Thailand
    Posts
    2,877
    Member #
    71
    Liked
    743 times
    Device
    International GT-I9300
    This is obviously a Developer issue. I think it's impossible for Google to check the code of every app created
    Galaxy S3 I9300 Rooted Running WanamLite JB 4.2.1
    Asus TF 101 16 Gig B60 W/Dock
    Macbook Pro 13.3
    Asus N56U Wireless Network Router
    Airport Extreme Wireless Router
    Asus WL-330N3G Portable Wireless Router



  8. #8
    Senior Member RyanJ's Avatar
    Join Date
    Sep 2012
    Posts
    121
    Member #
    2434
    Liked
    3 times
    Go back?!?! Not a chance! I love my freedom!
    CR6 and maybish like this.

  9. #9
    Super Moderator furbearingmammal's Avatar
    Join Date
    Jun 2012
    Location
    The great northern wastes of NY state near Fort Drum.
    Posts
    2,127
    Member #
    332
    Liked
    552 times

    Re: Researchers find 1,000 insecure Android apps; SSL Vulnerabilities Expose Data

    The vulnerabilities were mostly off use only for man in the middle attacks, which are fairly difficult to implement without detection on a wide scale.

    Still, troubling that the devs aren't as protective as th they should be.

    Sent from my SCH-I535
    Due to the lack of robots, our staff contains the occasional human being which may respond unpredictably to being abused. Please, be considerate so as to avoid unpredictable responses.

    Hey, did you know I'm an author? I am. Curious? Check out my author page on Amazon or my blog.


 

Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Similar Threads

  1. Replies: 6
    Last Post: 10-03-2012, 07:58 AM
  2. Data Saving apps.
    By Dmillertime in forum Galaxy S3 Apps
    Replies: 3
    Last Post: 09-22-2012, 11:16 AM
  3. Replies: 0
    Last Post: 09-07-2012, 08:17 AM
  4. Replies: 0
    Last Post: 09-05-2012, 03:32 PM
  5. Box Launching One Cloud for Android with 50 Apps
    By dgstorm in forum Galaxy S3 News
    Replies: 0
    Last Post: 06-26-2012, 09:36 AM

Search tags for this page

galaxy s3 android apps 1000

Click on a term to search for related topics.