'Billions of Records at Risk from Mobile App Data Flaw'

Advertisement
By Reuters | Updated: 17 June 2015 13:29 IST
Security researchers have uncovered a flaw in the way thousands of popular mobile applications store data online, leaving users' personal information, including passwords, addresses, door codes and location data, vulnerable to hackers.

The team of German researchers found 56 million items of unprotected data in the applications it studied in detail, which included games, social networks, messaging, medical and bank transfer apps.

"In almost every category we found an app which has this vulnerability in it," said Siegfried Rasthofer, part of the team from the Fraunhofer Institute for Secure Information Technology and Darmstadt University of Technology.

Advertisement

Team leader Eric Bodden said the number of records affected "will likely be in the billions".

Another security researcher working separately, Colombian Jheto Xekri, said he had also found the same flaw.

Advertisement

The problem, Bodden said, is in the way developers - those who write and sell the applications - authenticate users when storing their data in online databases.

Most such apps use services like Amazon's Web Services or Facebook's Parse to store, share or back up users' data.

Advertisement

While such services offer ways for developers to protect the data, most choose the default option, based on a string of letters and numbers embedded in the software's code, called a token.

Attackers, Bodden says, can easily extract and tweak those tokens in the app, which then gives them access to the private data of all users of that app stored on the server.

Advertisement

The researchers said they had no documented evidence that the vulnerability had been exploited.

The vulnerable applications, which they declined to name, number in the tens of thousands, and include some of the most popular on the Apple and Google app stores.

Rasthofer said all four companies had responded to their findings; he said Apple staff had told him on Monday that they would soon incorporate warnings to developers to double check their security settings before uploading apps to its App Store.

Google declined to comment, while Apple and Amazon did not respond to queries.

A Facebook spokesperson said that after researchers notified it of the vulnerability the company had been working with affected developers. She declined to provide details.

App developers responsible
Facebook's Parse lists among its customers some of the world's biggest companies - all of which, Rasthofer said, were potentially affected.

Security researchers say mobile applications are more at risk of failing to secure users' data than those running on desktop or laptop computers. This is partly because implementing stronger security is harder, and partly because developers are in a rush to release their apps, said Ibrahim Baggili, who runs a cyber-security lab at the University of New Haven.

Others pointed to weaknesses in the ways apps transmit data. Bryce Boland, Asia Pacific chief technology offer at internet security company FireEye, said the report reflected deeper problems.

He said FireEye regularly found developers send users' names and passwords unencrypted, "so it's not surprising to find them storing them insecurely as well".

Bodden likened his team's discovery to the Heartbleed bug, a web-based vulnerability reported last year that left half a million web servers susceptible to data theft. Security researchers said this might be worse, since there was little users could do, and exploiting the vulnerability was easy.

"The amount of effort to compromise data by exploiting app vulnerabilities is far less than the effort to exploit Heartbleed," said Toshendra Sharma, founder of Bombay-based mobile security company Wegilant.

Other security researchers say that while responsibility for weak authentication lies with those developing the apps, others in the chain should shoulder some of the blame.

"The truth is that there is plenty of fault to go around," said Domingo Guerra, co-founder of mobile security company Appthority. Cloud providers and app stores, he said, should ensure best practices are implemented correctly and test apps for such holes.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Apple, Apps, Microsoft
Advertisement

Related Stories

Popular Mobile Brands
  1. HP OmniBook X 14, Ultra 16 Refreshed With Nvidia RTX Spark 'Superchip'
  2. Fable Delayed to February 2027 to Avoid Clash With GTA 6 Release
  3. Huawei Nova 16 Pro, Nova 16 Ultra Debut With 7,000mAh Battery: See Price
  4. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  5. Find X9 Ultra Review: Oppo's Crown Jewel
  6. Moto G37 Power Review: Covers All the Bases and More
  1. iPhone Ultra Tipped to Launch in White Colourway; May Feature Vapour Chamber Cooling
  2. Asus ROG Edition 20 Lineup Unveiled at Computex 2026 to Commemorate 20 Years of ROG Series Products
  3. Indian Startup Pawzeeble Is Building a Pet-Focused Social Networking Space for Indian Users
  4. Asus ROG Strix Scar 18 (2026) With 240Hz 4K Mini-LED Display Showcased at Computex 2026
  5. Huawei Nova 16 Pro, Nova 16 Ultra Launched With Kirin 9010S SoC, 7,000mAh Battery: Price, Specifications
  6. Huawei Nova 16 Launched With 7,000mAh Battery, 50-Megapixel Camera, Nova 16z Tags Along: Price, Specifications
  7. Computex 2026: AMD Unveils Ryzen 7 7700X3D, Radeon RX 9070 GRE; Extends AM5 Support to 2029
  8. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: Price, Features
  9. Vivo X Fold 6 Launch Timeline Leaked; Tipped to Arrive With MediaTek Dimensity 9500 Chip
  10. HP OmniBook Ultra 16 (2026), OmniBook X 14 (2026) Unveiled With Nvidia's RTX Spark 'Superchip'
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.