Site navigation

Are Your Apps Leaking Sensitive Data?

Tom Quinn

,

app security
A new study from Zimperium highlights the hidden data risks of using popular work apps.

Some of the most popular Android and iOS work apps used by enterprise device fleets contain severe cryptography flaws, such as misconfigured cloud storage, hardcoded credentials and exposed credentials, according to a new security report from Zimperium.

After analysis of more than 54,000 work apps available from official app stores, including 9,078 for Android and 45,570 for iOS, Zimperium’s study found that 88% of all apps, and 43% of the top 100, use one or more cryptographic methods that don’t follow best practices.

Those include what Zimperium claims are high-severity cryptography flaws, such as hardcoded cryptographic keys, the use of outdated algorithms like MD2, the recycling of cryptographic keys, and insecure random number generators that could potentially be exploited to break encryption.

Added to that, 62% of all analysed apps used some kind of cloud API or Software Development Kit (SDKs), however, 103 popular Android apps were found to use unprotected or misconfigured cloud storage, with four of these apps ranking in the top 1000 in Google’s app store.

Zimperium warned that in several instances, file and directory indexes were publicly accessible, and in some cases, entire repositories could be accessed without authentication, leaving them open for threat actors using scanning tools to locate and extract sensitive data.

Ten Android apps Zimperium analysed contained exposed credentials to AWS cloud services, potentially allowing malicious actors access to read data, or in the worst case, encrypt it to hold for ransom.

The consequences of cloud misconfigurations can be devastating for firms, with some of the world’s biggest car makers, including Volkswagen and Toyota suffering data breaches which impacted thousands of customers because of vulnerabilities in their cloud environments.


Recommended reading


While data exposure is a major risk, and can leave firms open to the loss of sensitive customer and corporate information, these cloud and cryptographic vulnerabilities can also create compliance issues, not to mention financial impacts, with figures from IBM putting the average cost of a data breach last year at $4.88 million (£3.6m) per incident.

To mitigate these risks, Zimperium advises mobile fleet managers to gain greater visibility into app behaviour, including assessing the security of cloud service integrations, reviewing embedded cloud SDKs, and validating the use of third-party cryptographic tools.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data