news4geeks.net
22Oct/120

Android apps get SSL wrong, expose personal data

More than 1,000 out of a sample of 13,000 Android applications analysed by German researchers contained serious flaws in their SSL implementations.

In this paper (PDF), the researchers from Leibniz University in Hannover and Philipps University of Marburg found that 17 percent of the SSL-using apps in their sample suffered from implementations that potentially made them vulnerable to man-in-the-middle MITM attacks.

They state that they were “able to capture credentials from American Express, Diners Club PayPal, bank accounts, Facebook, Twitter, Google, Yahoo, Microsoft Live ID, Box, WordPress, remote control servers, arbitrary e-mail accounts, and IBM Sametime”.


In addition, since virus software also uses SSL, “We were able to inject virus signatures into an anti-virus app to detect arbitrary apps as a virus or disable virus detection completely.”

The problems arise because of developers misusing the SSL settings the Android API offers. Examples given by the researchers including apps that are instructed to trust all certificates presented to them (21 of 100 apps selected for a MITM test); 20 of the MITM-tested apps were configured to accepts certificates regardless of its associated hostname (for example, an app connecting to PayPal would accept a certificate from another domain). Other issues included SSL stripping and “lazy” SSL implementations.

Furthermore, the researchers note that a number of apps provided insufficient feedback to users – for example, failing to tell the user whether or not it was using SSL to transmit user credentials.

The researchers say the tool they developed for scanning apps’ SSL implementations, MalloDroid, will be available as a Web app and as part of the Androguard security scanner.

(Source: theregister.co.uk)

 

Google this week is extending an invitation to developers to try out its new Google Play Developer Console, which is centered on developing and publishing applications to the ...
READ MORE
Research in Motion Wednesday released a BlackBerry PlayBook OS update that adds full device encryption to secure personal data stored on the device to go along with the ...
READ MORE
Obama online privacy plan faces challenge
Privacy advocates Thursday welcomed a White House privacy plan that would give consumers more control over how personal data is collected, used, stored and shared by websites and online ...
READ MORE
Research in Motion is trying to woo developers by giving a free BlackBerry PlayBook tablet to coders who port their Android application for its BlackBerry Tablet OS. The promotion, ...
READ MORE
Anonymous breaches San Francisco’s public transport site
The hacking collective Anonymous released personal data on Sunday belonging to more than 2,000 public transport customers in the San Francisco area in retaliation for the Bay Area ...
READ MORE
Google invites developers to try out Google Play
PlayBook OS 2.1 update boosts security, management
Obama online privacy plan faces challenge
RIM offers free PlayBook to attract Android developers
Anonymous breaches San Francisco’s public transport site

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.