SURPRISE: Mobile Apps Are Not Very Secure
Probably this does not come as a surprise. Unfortunately.
Researchers analyzed a half million apps and here is what they found.
One in five (20%) have hard coded the encryption keys that protect your data, so that anyone who has the app can look at your data.
One in six use software libraries that have known vulnerabilities.
And two thirds use weak or broken encryption.
The problem is that a lot of the apps do not get any routine maintenance and even the ones that do don’t do a great job of protecting you.
60 percent of developers use app frameworks to make life easier, but 16 percent of these have known vulnerabilities. Known, that is, to someone, but, in many cases, not to the developers.
Neither Apple nor Google test apps that appear on their store for bugs. They do look for egregious rule violations, but beyond that, not much.
The challenge is that there is not a lot that end users can do. We do recommend uninstalling any apps that you don’t need. Credit: Dark Reading