Audio By Carbonatix
Millions of people are using Android apps that can be tricked into revealing personal data, research indicates.
Scientists tested 13,500 Android apps and found almost 8% failed to protect bank account and social media logins.
These apps failed to implement standard scrambling systems, allowing "man-in-the-middle" attacks to reveal data that passes back and forth when devices communicate with websites.
Google has yet to comment on the research and its findings.
Researchers from the security group at the University of Leibniz in Hanover and the computer science department at the Philipps University of Marburg tested the most popular apps in Google's Play store.
By creating a fake wi-fi hotspot and using a specially created attack tool to spy on the data the apps sent via that route, the researchers were able to:
capture login details for online bank accounts, email services, social media sites and corporate networks
disable security programs or fool them into labelling secure apps as infected
inject computer code into the data stream that made apps carry out specific commands
An attacker could even re-direct a request to transfer funds, while making it look to the app user like the transaction was proceeding unchanged.
Some of the apps tested had been downloaded millions of times, the researchers said.
And a follow-up survey of 754 people suggests users could struggle to spot when they were at risk.
"About half of the participants could not judge the security state of a browser session correctly," the researchers wrote.
"Most importantly, research is needed to study which counter-measures offer the right combination of usability for developers and users, security benefits and economic incentives to be deployed on a large scale."
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
AFCON 2025: Morocco second half brilliance seals win over Comoros in opener
14 minutes -
Boankra Integrated Logistics Terminal: Tribunal orders Justmoh Construction to refund $33.3m to APSL
47 minutes -
Fitch affirms Bank of Africa at ‘BB’; outlook stable
2 hours -
Fuel prices: Ghana ends year at 23rd position in Africa
2 hours -
Remain vigilant during the festivities; cybercriminals do not take holidays – CSA cautions
2 hours -
NSA to close registration portal for 2025/2026 National Service year
2 hours -
BoG Governor targets single-digit interest rates to boost businesses
3 hours -
BAWA-ROCK Ltd honoured for sustainable gold trading at Africa Development Conference
3 hours -
Fire guts Unique Floral shop at Tse Addo
3 hours -
GPL 2025/26: Kotey strike hands Gold Stars crucial away win at Hohoe
3 hours -
Dormaahene urges Mahama to pursue accountability over National Cathedral project
3 hours -
GPL 2025/26: Mamah strike powers Samartex past Heart of Lions
3 hours -
Mahama directs release of GH¢1bn to contractors owed since 2017
4 hours -
GPL 2025/26: Aduana hold Hearts in Dormaa
4 hours -
Sekyi-Brown Reginald: Transforming infrastructure into preventive healthcare
4 hours
