mardi 28 avril 2015

From Kaspersky To Webroot, Major Security Firms Can't Even Get Basic Android Encryption Right

When recently-appointed president of RSA, Amit Yoran, opened his company’s flagship conference yesterday, he warned the security industry was living in the dark ages. Protections just aren’t working, he said. Various anti-virus firms, including big names like Kaspersky and Webroot, have offered proof that the market’s many players get it wrong; they’re on a list of companies whose Google Play Android apps don’t do proper encryption checks, according to research from the Computer Emergency Response Team (CERT) at Carnegie Mellon’s Software Engineering Institute.

The CERT discovered a whopping 22,000 apps that weren’t carrying out “SSL validation”, where the software is supposed to check certificates over encrypted communications to ensure the parties involved are verified. Kaspersky’s Internet Security app and Webroot’s free offering and its “complete” tool (an apt name, perhaps?) both failed to carry out these checks, meaning an attacker sitting on the same network as a target user could, in theory, spoof those services and collect data the victim hands over to the fake application. That could be credit card data, especially where in-app purchases are taking place, as in both Kaspersky and Webroot anti-virus, or usernames and passwords. Users would understandably assume that apps using encryption were safe, so would likely be oblivious to such “man-in-the-middle” attacks.

1 commentaire:

  1. Delivering complete protection for your device and securing it against all major threats on the internet. Webroot Safe

    RépondreSupprimer