The Enterprise Security Supersite NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Druva inSync Free Trial
Druva inSync with DLP, analytics & secure file sharing.
www.druva.com/inSync-Trial
You are here: Home / Enterprise I.T. / Mobile Apps Flunk Security Test
Real-time info services with Neustar
Mobile Apps for Android and iOS Flunk Security Test
Mobile Apps for Android and iOS Flunk Security Test
By Barry Levine / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
AUGUST
09
2011


A new study provides specifics about how insecure mobile applications can be. The findings by Chicago-based security company ViaForensics include the discovery that three-quarters of the examined applications for Google's Android and Apple's iOS devices store usernames without encryption.

The study from November through June also found that 10 percent store passwords similarly in the open. One hundred financial, social-networking, productivity and retail apps were included in the study, which rated apps as pass, fail or warn. Pass indicated encryption or other unavailability of sensitive data, fail was the opposite, and warn refers to data that isn't secure but doesn't appear to put the user at risk. Of the apps examined, 39 received a fail, 17 a pass, and 44 a warning.

Social Apps 'Least Secure'

Not surprisingly, financial applications were among the most secure, with 14 of 32 getting a pass and 10 a warning. Several financial apps failed, including Wikinvest and Square for the iPhone, and Mint for Android devices and the iPhone.

Social-networking apps were "the least secure group" tested. None of the 19 received a passing grade, and 14 of them failed. These apps, such as LinkedIn for Android, failed to encrypt passwords and data used in the application.

The study noted that social-networking apps "are inherently different" from financial apps, in that much of the information is meant for public consumption. But, it pointed out, IM logs and direct messages are meant to be seen only by the people intended, so the ability to access this information provoked a failing grade.

Productivity apps, which include such widely used programs as Gmail, iPhone mail, WordPress and Yahoo Mail, also did poorly. Of the 35 apps tested in that category, only three passed. One of the reasons cited was that the text in e-mails, which can often be confidential, was not stored securely.

Only two of 14 retail apps passed, and the others got off with a warning. The study noted that Groupon's app for Android failed because of its password-recovery technique.

Android, Apple OSes

The study also noted the relative differences between Android and iOS security efforts.

Android 3.0, Honeycomb, was the first Android OS with encryption for the user partition on a device, but it's currently only available on tablets, not smartphones. ViaForensics pointed out that Android developers have discovered how to get root access on Android smartphones, which promotes the development of innovative apps as well as providing full access to a user's data.

By contrast, the report said that, since version 3, Apple's iOS has had encryption for the file system to protect user data on iPhone 3GS and later devices. Apple completely reworked the encryption method with iOS 4. However, the user needs to set up a passcode, or files on the device are not fully protected. In addition, hacker tools have already been developed to get around the passcode, the report said, "with varying degrees of success, depending on the strength of passcode used."

Brad Shimmin, an analyst with industry research firm Current Analysis, noted that the study shows mobile applications are still in a "buyer beware" era.

He said smartphone insecurity is the reason many financial employees have two phones -- one that has been locked down by their IT departments, and one for personal use. Until smartphone apps develop better security, he said, "it's inevitable there will be catastrophes of information being stolen" on a large number of mobile devices, which hopefully will provide "a kick in the pants" for users and developers.

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY BE OF INTEREST
Protect 100% of your Data The prevalence of laptops and mobile devices in the enterprise makes corporate data increasingly vulnerable to loss and breach. And yet, workforce productivity is now inextricably linked to mobility. Click here to access the white paper "Top 10 Endpoint Backup Mistakes" to learn more about how to confidently protect data across platforms and devices while also providing features designed to enhance the end user experience.
MORE IN ENTERPRISE I.T.
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Dairy Queen Latest Retailer To Report Hack
Known for its hot fries and soft-serve ice cream, Dairy Queen just made cyber history as the latest victim of a hack attack. The fast food chain said that customer data at some stores may be at risk.
 
Lessons from the JPMorgan Chase Cyberattack
JPMorgan Chase is investigating a likely cyberattack. The banking giant is cooperating with law enforcement, including the FBI, to understand what data hackers may have obtained.
 
Who Is the Hacker Group Lizard Squad?
Are they dangerous or just obnoxious? That’s what many are wondering about the hacker group Lizard Squad, which tweeted out a bomb threat that grounded a flight with a Sony exec aboard.
 

Enterprise Hardware Spotlight
Intel Intros Lightning-Fast PC Processors
Call it extreme. Intel just took the covers off its first-ever eight-core desktop processor, which is aimed at hardcore power users who expect more than the status quo from their computers.
 
HP Previews ProLiant Gen9 Data Center Servers
Because traditional data center and server architectures are “constraints” on businesses, HP is releasing new servers aimed at faster, simpler and more cost-effective delivery of computing services.
 
Apple Set To Release Largest iPad Ever
Tech giant Apple seems to have adopted the mantra “go big or go home.” The company is planning to introduce its largest iPad ever: a 12.9-inch behemoth that will dwarf its largest existing models.
 

Mobile Technology Spotlight
Samsung Maps Its Way with Nokia's 'Here' App for Galaxy Phones
Korean electronics giant Samsung has opted to license Here, Nokia’s mapping app -- formerly known as Nokia Maps -- for its Tizen-powered smart devices and Samsung Gear S wearable.
 
Will iPhone Finally Catch Up with NFC Mobile Payment Ability?
Apple's latest version of the iPhone may have a mobile wallet to pay for purchases with a tap of the phone. The iPhone 6 reportedly is equipped with near-field communication (NFC) technology.
 
Visual Search To Shop: Gimmick or Game Changing?
Imagine using your phone to snap a photo of the cool pair of sunglasses your friend is wearing and instantly receiving a slew of information about the shades along with a link to order them.
 

Navigation
Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.