Jump to content


Photo

Think These Apps are Secure? Think Again!


  • Please log in to reply
10 replies to this topic

#1 mjs27541

mjs27541

    I have no idea what's going on...

  • News Writer
  • PipPipPipPip
  • 1,276 posts
  • LocationSouthern MD
  • Current Device(s):LG G2

Posted 04 September 2014 - 08:21 PM

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  1.05MB   33 downloads

 

     We've known for a while now that there are apps on the Play Store that don't perform proper security certifications over HTTPS, leaving them, and by extension you, vulnerable to man in the middle attacks, whereby you think you're interacting with a secure app server, but are really communicating with an attacker.  Using SSL certification over HTTPS is supposed to protect against this, but only when it's done properly.  Researchers at Carnegie Mellon University have begun to compile a list of apps available in the Play Store that either don't perform proper SSL certification, or worse, don't do it at all.  The list of vulnerable apps is 

Please Login or Register to see this Hidden Content

, prepare to be shocked at some of the names you see on this list.

 

Source:  CSOOnline.com (thanks cmh714!)


  • Thach likes this

#2 androidlearner

androidlearner

    Droid Master

  • Dedicated Supporter
  • PipPipPip
  • 904 posts
  • LocationPeoria, AZ

Posted 08 September 2014 - 10:25 AM

Tapatalk is on there...



#3 cmh714

cmh714

    Tech Service & Beyond

  • Smod
  • 3,272 posts
  • LocationSoCal
  • Current Device(s):Nexus 6

Posted 08 September 2014 - 11:04 AM

Yes, it is



#4 Thach

Thach

    Motorola Fanboy

  • Administrator
  • 2,364 posts
  • Twitter:thach2639
  • Google+:Thach26
  • LocationGrand Forks ND
  • Current Device(s):OG Droid, Droid X, Droid X2, Droid Razr, Droid Bionic, Droid Xyboard 8.2, Nexus 7

Posted 09 September 2014 - 02:09 PM

Damn that's a lot, gonna take a while to look at them all lol.

Thach%20Admin%20device%20list.png


#5 King Howie

King Howie

    Minister of Jackbooted Thugs

  • Dedicated Supporter
  • PipPipPip
  • 882 posts
  • Current Device(s):Galaxy S4 GPE, Nexus 7 (2013)

Posted 11 September 2014 - 02:08 AM

Kaspersky internet security is on there. Really? An internet security app isn't secure

#6 mjs27541

mjs27541

    I have no idea what's going on...

  • News Writer
  • PipPipPipPip
  • 1,276 posts
  • LocationSouthern MD
  • Current Device(s):LG G2

Posted 11 September 2014 - 02:34 AM

Yeah I chuckled at that one. Even though it isn't really funny. But still.

#7 Gblake13

Gblake13

    n00b

  • Members
  • Pip
  • 12 posts
  • Current Device(s):Droid razr m XT907

Posted 11 September 2014 - 02:54 AM

So what's the recommened action for this security issue? There's an awful lot of apps to avoid.

Sent from my DROID RAZR HD using Xparent Cyan Tapatalk 2



#8 mjs27541

mjs27541

    I have no idea what's going on...

  • News Writer
  • PipPipPipPip
  • 1,276 posts
  • LocationSouthern MD
  • Current Device(s):LG G2

Posted 11 September 2014 - 11:58 AM

I don't think there's anything you can do other than uninstall the apps

#9 KFTheTruth

KFTheTruth

    n00b

  • Dedicated Supporter
  • Pip
  • 21 posts
  • Twitter:@KFTheTruth
  • LocationNorth America
  • Current Device(s):SGP Blackphone & Razr HD Maxx xt926

Posted 14 September 2014 - 10:12 AM

Canadian DMV....

 

Do you know if  this list going to be continually updated or is it just a study for a set period of time?



#10 mjs27541

mjs27541

    I have no idea what's going on...

  • News Writer
  • PipPipPipPip
  • 1,276 posts
  • LocationSouthern MD
  • Current Device(s):LG G2

Posted 14 September 2014 - 10:58 AM

It's being updated periodically. There were new ones added since I originally posted this. The link in the OP takes you to the updated list.

#11 Daino92

Daino92

    Member

  • Members
  • PipPip
  • 258 posts
  • Google+:chrisdaino@gmail.com
  • LocationFort Collins
  • Current Device(s):SCH-1535

Posted 23 September 2014 - 11:43 AM

That's a way longer list than I would have thought.... I LoL'd when I saw Kerparsky on the list... lol 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users