Breaking News

Apple unleashes M5 CPU and new devices PlayStation Plus Game Catalog for October 2025 Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES MSI Unveils the AI-Ready Cubi Z AI Series Mini PC

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Fraunhofer Reports Massive Security Issues with Apps

Fraunhofer Reports Massive Security Issues with Apps

Smartphones Dec 16,2013 0

Many popular Android apps pose significant security threats, according to researchers at the Fraunhofer Institute for Secure Information Technology in Darmstadt, Germany (Fraunhofer SIT). The researchers conlcuded that by exploiting weaknesses in the way the Secure Sockets Layer (SSL) protocol is used, attackers can steal sensitive access data, e.g., user names and passwords. Fraunhofer SIT informed over 30 affected app manufacturers and so far, 16 closed the security gap. Among those were Amazon, Yahoo, Google, and Volkswagen Bank.

The user's security risk depends on the specific app: With some apps only personal photos might be at risk; with banking apps, access data might be used for unauthorized money transfers. An especially grave risk may occur if apps use the single-sign on services of Google or Microsoft. In these cases access data is used for a variety of services, like email and cloud storage.

MIT's researchers say that the vulnerability is introduced by an incorrect use of SSL. SSL cryptographically protects the connection between apps and servers. This protection relies on so-called public-key certificates. When receiving a certificate, apps are supposed to verify that it actually belongs to the server they want to communicate with. The researchers found that in the listed apps, this verification is not done correctly.

"From a technical perspective, this is a small mistake. But it can have a huge impact on security," says Dr. Jens Heider from Fraunhofer SIT. For example, an attacker just needs to manipulate the communication that takes place while the victim is surfing via an unprotected WLAN, e.g., at an airport or in a restaurant. It is in these situations that the SSL encryption is supposed to ensure secure communication.

"In principle, the vulnerability is extremely easy to fix," says Heider. He and his team already informed the manufacturers several weeks ago and asked for the weakness to be remedied. The team has rechecked every new update. "Users need to make sure they always update their apps to the newest version," recommends Heider.

Fraunhofer SIT tested a total of 2,000 Android apps.

Tags: Fraunhofer
Previous Post
New AMD Radeon R7 260 GPU Shipping Mid-January
Next Post
Intel To Buy Wireless Infrastructure Division of Mindspeed

Related Posts

  • Globalfoundries to Work With Fraunhofer on FDSOI

  • Fraunhofer Scientists Find Dangerous Security Holes in Tracker Apps

  • MP3 Has Been Set Free Of Licensing

  • Fraunhofer IIS Showcases MPEG-H Enabled 3D Soundbar

  • Fraunhofer To Showcase The Future Of TV at IBC

  • Fraunhofer IIS to Present MPEG-H Audio at CES

  • Fraunhofer Makes CD-like Voice Available for VoIP Apps

  • Fujitsu and Fraunhofer To Partner on Nanometre Technology

Latest News

Apple unleashes M5 CPU and new devices
Enterprise & IT

Apple unleashes M5 CPU and new devices

PlayStation Plus Game Catalog for October 2025
Gaming

PlayStation Plus Game Catalog for October 2025

Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd
Consumer Electronics

Logitech Muse, the Digital Pencil for Apple Vision Pro, Launches October 22nd

NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES
Cameras

NIKON EXPANDS DX LENS LINEUP WITH TWO NEW NIKKOR LENSES

MSI Unveils the AI-Ready Cubi Z AI Series Mini PC
Enterprise & IT

MSI Unveils the AI-Ready Cubi Z AI Series Mini PC

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed