More than 1,800 iOS and Android apps are leaking your data



The alarm is being raised by Symantec, a cyber security organization with which the private information of millions of people can be accessed through multiple apps, most of them running iOS.

The problem will typically arise from the reuse of valid Amazon Web Services (AWS) tokens. Which will provide access to a large amount of information.

The reuse of hard-coded Amazon Web Services tokens has been identified as a serious security vulnerability in 1,859 applications, 98% of which are iOS-based. In fact, we find reuse of the same AWS credentials in 53% of applications tested by Symantec. The danger of this data is increasing tenfold. For Symantec, the problem stems from the supply chain, particularly when developing apps using software development kits (SDKs).

Android and iOS apps are prone to data leaks

According to the company, the vulnerability is limited if AWS code only allows access to a single file present in Amazon Simple Storage Service (S3), although this is not the case in this instance. One of the examples is the SDK of a B2B company. Which gives customers access to all of the company’s cloud infrastructure keys in addition to its platform. There are over 15,000 large and medium sized businesses listed out there. And Symantec claims that information about both customers and employees, as well as financial records, may have accidentally been the subject of leaks.



According to Symantec, “To access the AWS Translation Service, the business has hard-coded the AWS Access Token. However, anyone with the hard-coded Access Token will have access to all B2B Enterprise’s AWS Cloud services, rather than just the Translation Cloud service.” There was full, unrestricted access to the services.

Reusing these tokens, which provide full access to data across different applications, dramatically increases the risk of leakage. Even if it’s mainly unintentional on the part of the developers. According to an investigation by Symantec, 47% of the apps evaluated involve AWS tokens. Which not only provide access to files needed for coding, such as in a private cloud area. But also for millions of files held by Amazon (S3).

Source



Related News

8BitDo built a console-agnostic controller for players with limited mobility

Hong Kong-based gaming hardware company 8BitDo has announced that it is launching the 8BitDo Lite SE, a Bluetooth controller specifically designed to make

Get Your Best Photos With These iPhone 13 Photography Tips

We've been consistently impressed by Apple's iPhone 13 Pro and its great camera setup. Those three rear lenses can take stunning images that can easily rival

Telegram founder alleges that Apple ‘deliberately cripples’ web apps by not updating WebKit

One Hot Potato: Apple has seen almost no end of antitrust allegations over the years. Its defense against Epic Games was mostly successful, but regulators in

Seaflower hackers steal crypto in your Android and iOS wallets with secret backdoors

Researchers at Confident have published their findings detailing a widespread malware campaign the researchers are calling Seaflower. The campaign is targeted

Squid Game will come to life in Netflix’s new reality show

It was only a matter of time before that Squid Game come to life, turning into a reality show real. Soon Netflix will bring the famous Korean series to the

Endothermic ban: 2030 is the deadline for many brands

The decision of the European Parliament to stop the sale of endothermic cars starting from 2035 it has sparked controversy and controversy, especially among