The Enterprise Security Supersite NewsFactor Sites:     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
This ad will display for the next 20 seconds. Click for more information, or
Home Network Security Viruses & Malware Cybercrime Security Solutions More Topics...
Free Gartner Report:
Drive innovation & collaboration
with the "Everyone's IT" approach.

View the research report
Personal Tech
Gartner's #1 for endpoint backup
Average Rating:
Rate this article:  
Mobile Apps for Android and iOS Flunk Security Test

Mobile Apps for Android and iOS Flunk Security Test
By Barry Levine

Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

A study by ViaForensics has discovered that three-quarters of the examined applications for Android and iOS fail to encrypt usernames, and 10 percent store passwords in the open. ViaForensics rated financial apps as the most secure, while social-networking apps were the least secure. Productivity mobile apps, including Gmail, were rated poor.

A new study provides specifics about how insecure mobile applications can be. The findings by Chicago-based security company ViaForensics include the discovery that three-quarters of the examined applications for Google's Android and Apple's iOS devices store usernames without encryption.

The study from November through June also found that 10 percent store passwords similarly in the open. One hundred financial, social-networking, productivity and retail apps were included in the study, which rated apps as pass, fail or warn. Pass indicated encryption or other unavailability of sensitive data, fail was the opposite, and warn refers to data that isn't secure but doesn't appear to put the user at risk. Of the apps examined, 39 received a fail, 17 a pass, and 44 a warning.

Social Apps 'Least Secure'

Not surprisingly, financial applications were among the most secure, with 14 of 32 getting a pass and 10 a warning. Several financial apps failed, including Wikinvest and Square for the iPhone, and Mint for Android devices and the iPhone.

Social-networking apps were "the least secure group" tested. None of the 19 received a passing grade, and 14 of them failed. These apps, such as LinkedIn for Android, failed to encrypt passwords and data used in the application.

The study noted that social-networking apps "are inherently different" from financial apps, in that much of the information is meant for public consumption. But, it pointed out, IM logs and direct messages are meant to be seen only by the people intended, so the ability to access this information provoked a failing grade.

Productivity apps, which include such widely used programs as Gmail, iPhone mail, WordPress and Yahoo Mail, also did poorly. Of the 35 apps tested in that category, only three passed. One of the reasons cited was that the text in e-mails, which can often be confidential, was not stored securely.

Only two of 14 retail apps passed, and the others got off with a warning. The study noted that Groupon's app for Android failed because of its password-recovery technique.

Android, Apple OSes

The study also noted the relative differences between Android and iOS security efforts.

Android 3.0, Honeycomb, was the first Android OS with encryption for the user partition on a device, but it's currently only available on tablets, not smartphones. ViaForensics pointed out that Android developers have discovered how to get root access on Android smartphones, which promotes the development of innovative apps as well as providing full access to a user's data.

By contrast, the report said that, since version 3, Apple's iOS has had encryption for the file system to protect user data on iPhone 3GS and later devices. Apple completely reworked the encryption method with iOS 4. However, the user needs to set up a passcode, or files on the device are not fully protected. In addition, hacker tools have already been developed to get around the passcode, the report said, "with varying degrees of success, depending on the strength of passcode used."

Brad Shimmin, an analyst with industry research firm Current Analysis, noted that the study shows mobile applications are still in a "buyer beware" era.

He said smartphone insecurity is the reason many financial employees have two phones -- one that has been locked down by their IT departments, and one for personal use. Until smartphone apps develop better security, he said, "it's inevitable there will be catastrophes of information being stolen" on a large number of mobile devices, which hopefully will provide "a kick in the pants" for users and developers.

Tell Us What You Think


UCS Invicta: Integrated Flash Why wait for the future? Unlock the potential of your applications and create new business opportunities today with UCS Invicta Series Solid State Systems. Take advantage of the power of flash technology. See how it can help accelerate IT, eliminate data center bottlenecks, and deliver the peak application performance and predictability your users demand. Click here to learn more.

 Personal Tech
1.   Bounty Offered for Oculus Rift Bugs
2.   Glass Adds Voice Access to Contacts
3.   Foursquare: All Customer Experience
4.   Sony Intros 'Album of the Day' App
5.   DogVacay Captures Better Dog Pics

New App To Manage Time Better
Helping to organize your busy life.
Average Rating:
OkCupid Experiments with Daters
Unethical without user consent?
Average Rating:
Foursquare: All Customer Experience
App's new focus is on recommendations.
Average Rating:

Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Researchers Find Malicious Android Apps Can Hack Gmail
A new study shows that a weakness in the Android mobile operating system can be used to steal sensitive, personal info from unwitting users. Gmail proved to be the easiest app to attack; Amazon, the hardest.
UPS Stores in 24 States Hit by Data Breach
Big Brown has been breached. UPS said that about 105,000 customer transactions at 51 of its UPS Store locations in 24 states could have been compromised between January and August.
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.

Enterprise Hardware Spotlight
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
Feds OK $2.3 Billion IBM-Lenovo x86 Server Deal
IBM and Lenovo are celebrating U.S. approval of their x86-based server deal, having cleared some major security hurdles. The deal makes Lenovo a major player for enterprise data centers.
Three New Lenovo PCs Aimed at Business Users
With businesses wanting computing solutions that do more for less money, Lenovo has unveiled three new desktop PCs that it says offer solid computing at a budget-minded price.

Mobile Technology Spotlight
Screen Shortage Briefly Puts Brakes on iPhone 6
RAM? Check. Antenna switch? Check. Screen? Oops. Parts suppliers for Apple have found themselves facing a shortage of screens for the new iPhone 6 as next month's release date for the new smartphone looms.
Bounty Offered to Coders for Oculus Rift Bugs
Coders who find bugs in software for the Oculus Rift VR immersive headset could receive a reward of at least $500 under Facebook's White Hat bounty program. Facebook acquired Oculus in March.
Google Glass Adds Voice Access to Phone Contacts
The latest update to Google Glass will let users access their top 20 phone contacts with voice commands alone. A user can then choose a phone call, Google hangouts, e-mail or text messaging.

Enterprise Security Today
Home/Top News | Network Security | Viruses & Malware | Cybercrime | Security Solutions | Mobile Security | Disaster Recovery | Windows Security
Data Security | EST Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.