Mobile App Security

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 19 November 2013

HP: 90% of Apple iOS mobile apps show security vulnerabilities

Posted on 13:59 by Unknown
Testing of more than 2,000 mobile apps developed by corporations reveals serious flaws

By Ellen Messmer, Network World
November 18, 2013 12:12 PM ET

Network World - HP today said security testing it conducted on more than 2,000 Apple iOS mobile apps developed for commercial use by some 600 large companies in 50 countries showed that nine out of 10 had serious vulnerabilities.

Mike Armistead, HP vice president and general manager, said testing was done on apps from 22 iTunes App Store categories that are used for business-to-consumer or business-to-business purposes, such as banking or retailing. HP said 97% of these apps inappropriately accessed private information sources within a device, and 86% proved to be vulnerable to attacks such as SQL injection.


The Apple guidelines for developing iOS apps help developers but this doesn’t go far enough in terms of security, says Armistead. Mobile apps are being used to extend the corporate website to mobile devices, but companies in the process “are opening up their attack surfaces,” he says.

In its summary of the testing, HP said 86% of the apps tested lacked the means to protect themselves from common exploits, such as misuse of encrypted data, cross-site scripting and insecure transmission of data.

Businesses offer best practices for escaping CryptoLocker hell

The same number did not have optimized security built in the early part of the development process, according to HP. Three quarters “did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker.” A large number of the apps didn’t implement SSL/HTTPS correctly.
To discover weaknesses in apps, developers need to involve practices such as app scanning for security, penetration testing and a secure coding development life-cycle approach, HP advises.

The need to develop mobile apps quickly for business purposes is one of the main contributing factors leading to weaknesses in these apps made available for public download, according to HP. And the weakness on the mobile side is impacting the server side as well.

“It is our earnest belief that the pace and cost of development in the mobile space has hampered security efforts,” HP says in its report, adding that “mobile application security is still in its infancy.”

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Computer Science, ICT Applications, ICT Research, Industry News, James Jones, Mobility, Security, Security; Identity Management, Web | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • LearningWorks: THE MISSING PIECE: Quantifying Non-Completion Pathways to Success
    ” . . . in the California Community College system . . . nearly one-third of students took an average of just two courses over about two yea...
  • Cisco Career Certifications Awarded American National Standards Institute Accreditation
    Achievement Demonstrates Compliance With Rigorous, Internationally Recognized Standards SAN JOSE, CA--(Marketwire - Jan 16, 2013) - Unders...
  • CyberWatch West Free Student 2 Student Webinar October 30th
    Online Workshop Oct 30 at 10:30 am PDT Man-in-the-Middle Attacks Using Mobile Devices Register @ cyberwatchwest.webex.com Student 2 Student ...
  • Spring 2013 NEW CCCApply Webinar Series
      Monday, 28 January 2013, TechEDge Written by Tim Calhoon Saturday, 26 January 2013 The New CCCApply online admissions application...
  • Community college grads out-earn bachelor's degree holders
    By Jon Marcus at The Hechinger Institute @CNNMoney February 26, 2013: 6:23 AM ET Nearly 30% of Americans with associate's degrees now ...
  • ACM CCECC Alice Summer Workshops Registration now open
    Registration has opened for the Alice Summer Workshops! A week has been set aside for a Community College focused workshop at Walt Disn...
  • CA Career Cafe: CALJOBS Job Search Service Now Available
    “ Somewhere someone is looking for exactly what you have to offer. ”                                                                    - ...
  • Code.org Launches To Help Make Computer Programming Accessible To Everyone
    Drew Olanoff ,  TechCrunch       Drew Olanoff has over 10 years of marketing, PR, customer service and support, relationship buildin...
  • EDGE goals addressed in 2013-14 California State Budget
    California's 2013-14 State Budget and an accompanying trailer bill, AB 86, address key EDGE goals of 1) beginning to restore dedicated f...
  • NCRIC Cyber Internship Program
    Northern California Regional Intelligence Center Cyber Internship Program Northern California Regional Intelligence Center (“NCRIC”) Mission...

Categories

  • Big Data
  • CATV
  • CENIC
  • Certifications
  • Cloud
  • Computational Thinking
  • Computer Engineering
  • Computer Science
  • CTE
  • Database
  • Digital Divide
  • Digital Literacy
  • Digital Media
  • Diversity
  • Educational Technology
  • elearning
  • Electronics
  • Entrepreneur
  • ethics
  • funding opportunity
  • Gaming
  • GIS
  • Grants
  • Hacking
  • Healthcare IT
  • ICT Applications
  • ICT Core Competencies
  • ICT Education
  • ICT Infrastructure
  • ICT Jobs
  • ICT pathways
  • ICT Regulation
  • ICT Research
  • Industry News
  • Innovation
  • Internships
  • James Jones
  • K-12
  • law
  • Linux
  • Mobility
  • MOOC
  • MPICT Announcements
  • Multimedia
  • Networking
  • networking security
  • Olivia Herriford
  • Open Source
  • Operating Systems
  • Pierre Thiry
  • Piracy
  • Public Policy
  • Security
  • Security; Identity Management
  • Smart Grid
  • Social Media
  • Soft Skills
  • Software Assurance
  • Software Engineering
  • Spanish
  • STEM Education
  • Storage
  • Teaching and Learning
  • Telecom
  • Tools
  • virtualization
  • Web
  • WIB
  • Wireless
  • women
  • Women in ICT
  • Workforce Development

Blog Archive

  • ▼  2013 (418)
    • ▼  November (41)
      • NSA 'infected' 50,000 networks with malware
      • Techies must nip growing scorn in bud
      • Is the tide turning? Women filled 60% of tech jobs...
      • Transfer Program Between California Community Coll...
      • Talent Shortage May Impede New Hiring by Technolog...
      • Time for the United States to Re-Skill ?
      • Tim Berners-Lee says 'surveillance threatens web'
      • Start a Microsoft TEALS Computer Science Program f...
      • 7 Ways to Find the Best IT Jobs
      • Cal Poly Announces Major New Initiative In Cyberse...
      • WebProfessionals.org Announces STEM to STEAMIE Ini...
      • US Department of Labor: $100m Youth Career Connec...
      • CompTIA: Why Are We Still Talking About Security?
      • New Milestone for CompTIA Troops to Tech Careers I...
      • HP: 90% of Apple iOS mobile apps show security vul...
      • Career tech at community colleges should not be un...
      • ITIF: A Guide to the Internet of Things
      • Guardian: Cyber-attacks eclipsing terrorism as gr...
      • CTI: Tech Leaders Warn IT Talent Shortage Could C...
      • Robert Half Technology 2014 Technology Salary Guid...
      • 5 Technology Jobs That Didn’t Exist 5 Years Ago
      • ATE@20: MPICT Runs Three Tests of International T...
      • Please Sign Petition to Make Computer Science Coun...
      • Opinion: The Case for Citywide Broadband in LA
      • New broadband report reveals £20 return on every £...
      • IASE Unclassified Cyber Awareness Challenge
      • LearningWorks: THE MISSING PIECE: Quantifying Non...
      • IT budgets, headcount set to grow in 2014: study
      • IBM to Announce More Powerful Watson via the Internet
      • Here Come the WiFi Drones
      • Netflix, YouTube Account for 50% of North American...
      • Quick Tips: Flip Your Class
      • New CompTIA Mobility+ Certification Addresses Skil...
      • Bay Area Computer User & Network Support Marketpla...
      • Los Angeles Citywide Gigabit Fiber RFP: Is This th...
      • Microsoft and Facebook offer bounties to bug hunters
      • How Much Media? 2013
      • Hour of Code Tutorials Are Ready to Try - 1.5m Stu...
      • ICT jobs in California ripe for the picking
      • Joint Workforce Development, CBO and MPICT Webinar...
      • Center for Community College Student Engagement Re...
    • ►  October (53)
    • ►  September (44)
    • ►  August (21)
    • ►  July (30)
    • ►  June (28)
    • ►  May (43)
    • ►  April (43)
    • ►  March (35)
    • ►  February (43)
    • ►  January (37)
  • ►  2012 (82)
    • ►  December (25)
    • ►  November (40)
    • ►  October (17)
Powered by Blogger.

About Me

Unknown
View my complete profile