{"id":255891,"date":"2021-05-21T21:19:51","date_gmt":"2021-05-21T18:19:51","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/misconfiguration-of-third-party-mobile-apps-exposes-the-data-of-100-million-users\/"},"modified":"2021-05-21T21:19:51","modified_gmt":"2021-05-21T18:19:51","slug":"misconfiguration-of-third-party-mobile-apps-exposes-the-data-of-100-million-users","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/misconfiguration-of-third-party-mobile-apps-exposes-the-data-of-100-million-users\/","title":{"rendered":"#Misconfiguration of third party mobile apps exposes the data of 100 million users"},"content":{"rendered":"<p>&#8220;<strong>#Misconfiguration of third party mobile <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>s exposes the data of 100 million users<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/misconfiguration-of-th.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/misconfiguration-of-th.jpg\" data-sub-html=\"Check Point Research backend code. Credit: Check Point Research\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/misconfiguration-of-th.jpg\" alt=\"Misconfiguration of third party mobile apps exposes the data of 100 million users\" title=\"Check Point Research backend code. Credit: Check Point Research\" width=\"567\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Check Point Research backend code. Credit: Check Point Research<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>Despite the obvious benefits of contemporary cloud-based, mobile application development solutions\u2014such as cloud storage, notification management, real-time databases, and analytics\u2014many developers of these solutions fail to properly take into account the potential security risks involved when these apps are misconfigured.<\/p>\n<p>                                                                                Most recently, Check Point Research has discovered misconfigurations and implementation issues that have exposed the data of 100 million mobile application users. This kind of exposure places both the users as well as the app developers at risk of reputation threats and security damage. In this instance, the developers left open notification managers, storage locations and real-time databases to access by attackers, thus leaving 100 million users vulnerable. <\/p>\n<p>In terms of real-time databases, cloud services can help mobile app users sync their data to the cloud in real time. However, when developers do not correctly implement this service with authentication, any user can theoretically access that database, including all mobile customer data. In fact, researchers expressed surprise at facing no obstacles to accessing these open databases for certain apps on Google Play. Some of the aspects obtainable in this case were device locations, email addresses, passwords, private chats and user identifiers, among other attack vectors. Such vulnerabilities leave all of these users at risk for fraud and identity theft. <\/p>\n<p>Indeed, the popular horoscope app Astro Guru is one app with such vulnerabilities, potentially exposing all users to a leak of personally identifiable information (PII) \u2013 such as birthdate, email, gender and location as well as payment information\u2014following a recorded 10 million downloads. <\/p>\n<p>Similarly, the taxi app T&#8217;Leva which already has more than 50,000 installs allowed researchers to pull the full names of users as well as phone numbers and both destinations and intended pickup locations by sending just one request to the database.<\/p>\n<p>Next, researchers also found that even the push notification manager had fallen vulnerable. This means that any malicious actor able to gain access to the manager could send the user notifications on the developer&#8217;s behalf. <\/p>\n<p>Moreover, cloud storage of these mobile apps presents a particular risk to users, as the research team also found that many developers left exposed both the access keys as well as the secret keys to stored data within the Screen Recorder service application. Evidently, a cursory analysis of the application file enabled researchers to recover these keys and access user recordings. <\/p>\n<p>Finally, research showed that CopyCat malware also has the ability to retrieve keys for at-risk cloud storage services, demonstrating how malicious developers can also take advantage of these vulnerabilities.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Unsecured cloud configurations expose data across thousands of mobile apps\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                Hazum, A., et al. &#8220;Mobile App Developers&#8217; Misconfiguration of Third Party Services Leave Personal Data of over 100 Million Exposed.&#8221; Check Point Research, Check Point Research, 20 May 2021, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/research.checkpoint.com\/2021\/mobile-app-developers-misconfiguration-of-third-party-services-leave-personal-data-of-over-100-million-exposed\/\">research.checkpoint.com\/2021\/m \u2026 100-million-exposed\/<\/a>.<\/p><\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Misconfiguration of third party mobile apps exposes the data of 100 million users (2021, May 21)<br \/>\n                                                 retrieved 21 May 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-05-misconfiguration-party-mobile-apps-exposes.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-05-misconfiguration-party-mobile-apps-exposes.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Misconfiguration of third party mobile apps exposes the data of 100 million users&#8221; Check Point Research backend code. Credit: Check Point Research Despite the obvious benefits of contemporary cloud-based, mobile application development solutions\u2014such as cloud storage, notification management, real-time databases, and analytics\u2014many developers of these solutions fail to properly take into account the potential security&#8230;<\/p>\n","protected":false},"author":1,"featured_media":255892,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/misconfiguration-of-th.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-255891","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/255891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=255891"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/255891\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/255892"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=255891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=255891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=255891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}