Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
  • Home
  • Islamabad
  • Karachi
  • Lahore
  • National
  • Transfers and Postings
  • Chambers & Associations
  • Business
No Result
View All Result
Customs Today
No Result
View All Result
Home Science & Technology Technology

70% of top 100 mobile banking apps on Android OS are vulnerable to security attacks, data leaks: report

byCustoms Today Report
03/04/2015
in Technology
Share on FacebookShare on Twitter

NEW DELHI: Mobile security firm, Appvigil is reporting that as many as 70 per cent of the top 100 mobile banking apps on the Android operating system in the APAC region are vulnerable to security attacks and data leaks. Don’t live in the said region? That’s no reason to relax. The report further pinpoints vulnerabilities in mobile banking apps found in other regions as well.

The security firm tested the mobile banking apps of the top 29 Indian banks and 71 more in the Asia Pacific region and the results are staggeringly bad. “Most of the mobile banking apps failed and many didn’t employ even the basic security checks expected. The communication between the apps & their servers is still in the unencrypted format i.e. in HTTP instead of HTTPS,” the report reveals.

You might also like

Tesla driverless system to use updated radar technology

12/09/2016

Apple to develop its own self-driving technology

10/09/2016

In the past couple of years as security threats reached new heights, most of the banks in European and American regions implemented security measures such as authentication using e-tokens, one-time passwords (OTP), and confirmation of transactions through codes sent to Android phones, but as Appvigil points out – which is in line with news reports we have seen previously – cybercriminals have developed tools that bypass these measures.

“There are numerous ways by which security loopholes can arise in an Android application. Organisations today, are focusing more on state of the art features, responsive and performance optimisation issues without paying much heed to security. In most of the cases people react to security issues only when they face some discrepancies via a malicious threat agent,” the report adds.

Furthermore, the report chalks out loopholes – such as issues of system clock accuracy, and time synchronisation – arising due to ignorance by our carriers and network admins. “If certain processes run out of sequence, such as transaction processing and backups, then the results of these processes may cause discrepancies, due to the transaction times failing to tally. Mismatched timestamps often cause financial and database program errors.”

vulnerability in banking apps 2

The firm found a staggering 983 security vulnerabilities in the 100 mobile banking apps it tested. These vulnerabilities include exploits such as intent spoofing, unintended data leakage, SQL injection, JavaScript injection, XML injection, and unencrypted sockets among others. “The findings of our analysis presented in this report have a different story to tell. It’s evident from the report that most of the apps are vulnerable to security attacks with 82 per cent of apps carrying high severity vulnerabilities in them. On an average, 14 security bugs per app are present. Surprisingly, we found five mobile banking apps which had more than 50 security vulnerabilities in each of them”. You can read more about it here.

You should be concerned about this even if you don’t live in the APAC region. Gizmodo did a comprehensive rundown of existing security measures utilised by all major banks in the United States and other regions, and the results were woeful. We contacted AVG, a popular mobile security firm to see what they think about this report. “There are banking apps in many markets which can be vulnerable to compromise but we are aware that banks do prioritise working on a fix obviously”, Yuval Ben-Itzhak, CTO at AVG, said.

“An example of one of these vulnerabilities is where an app downloads data and caches it on the device in multiple places. Some of these files may be able to be accessed by other apps and may not be removed after the banking app has used them. An uninstaller app would help ensure such data is removed for security purposes. Another example would be where an app is using a vulnerable WebView component, such as on a version of Android that is earlier than 4.1, which may leave it open to risk,” he added.

Tags: 70 per cent of the top 100

Related Stories

Tesla driverless system to use updated radar technology

byCT Report
12/09/2016

WASHINGTON: Electric carmaker Tesla announced Sunday it was upgrading its Autopilot software to use more advanced radar technology. In a...

Apple to develop its own self-driving technology

byCT Report
10/09/2016

SAN FRANCISCO: Apple may not become an automaker, but it still wants to develop its own self-driving technology. The iPhone-maker's...

‘YouTubers’ outshining old-school television

byCT Report
09/08/2016

SAN FRANCISCO: A media revolution is taking place, and most people over 35 years of age aren’t tuned in. Millennial...

Google pays tribute to Edhi

byCT Report
11/07/2016

ISLAMABAD: The technology giant, Google, has paid tribute to renowned social activist, philanthropist and humanitarian Abdul Sattar Edhi by placing...

Next Post

American Airlines to put Boeing 787 on D/FW-Shanghai route in June

  • Terms and Conditions
  • Disclaimer

© 2011 Customs Today -World's first newspaper on customs. Customs Today.

No Result
View All Result
  • Transfers and Postings
  • Latest News
  • Karachi
  • Islamabad
  • Lahore
  • National
  • Chambers & Associations
  • Business
  • About Us

© 2011 Customs Today -World's first newspaper on customs. Customs Today.