What is the issue - Aite Group tested 30 Android financial apps that are available for download in the Google Play store and found several vulnerabilities in the apps.
The vulnerabilities include a lack of binary protections, insecure data storage, unintended data leakage, weak encryption, and insecure random-number generation.
Why it matters - These vulnerabilities could expose source code, sensitive data, access to other apps via APIs, and more.
More details on the analysis
Why it matters?
“There's clearly a systemic issue here – it's not just one company, it's 30 companies and it's across multiple financial services verticals,” Alissa Knight, cybersecurity analyst at Aite Group and the researcher behind the study told ZDNet.
“API keys are basically that private password you don't want to get out. What was a systemic finding across multiple financial services mobile apps was that these private API keys were being found in the code. It's almost as if the developers who wrote the code didn't realise that it's possible to actually browse the directory structure of this mobile app and pull these files out, pull the keys out of subdirectories,” Knight added.
Publisher