HomeSecurityWiFi Finder: Over 2 Million Wi-Fi Network Passwords Leaked

WiFi Finder: Over 2 Million Wi-Fi Network Passwords Leaked

WiFi Finder, an Android app installed by more than 100,000 users on Google Play, has leaked over 2 million Wi-Fi.

While the app is designed to locate and connect to public Wi-Fi hotspots near the user, it also has a feature that allows users to share the hotspots they find with others. This is where the security and privacy concerns come in.

To make it easier for users to not only locate the nearest Wi-Fi hotspot but also connect to them, WiFi Finder includes a feature that allows users to load network passwords.

The app, which appears to be of Chinese origin, encourages users to share this information and become part of a Wi-Fi community. The description of the app, which is still available for download from Google Play, asks users to “be social and share Wi-Fi hotspots.”

According to security researcher Sanyam Jain, who is a member of the GDI Foundation, the database resulting from these uploads was "open and unprotected, allowing anyone to access and upload the content."

Wi-Fi

What information has been exposed?

The exposed database did not contain contact information for the Wi-Fi network owners whose data was included, but it did include Wi-Fi network names, precise geographic location, and passwords stored in plain text. What's worse is that although the app developer claims that the app only provides passwords for public hotspots, a review of the data showed countless home Wi-Fi networks.

What does this mean?

There seem to be three main issues here:

  • Users have accidentally uploaded their own Wi-Fi network passwords, prompted by the “share Wi-Fi” message in the app.

The app's developers failed to secure the database where all this data is stored and failed to adhere to basic security rules, such as never storing unencrypted passwords.

  • Because the app does not distinguish between public access points and home Wi-Fi networks, the latter are vulnerable to a potential hacking attack.

It should be noted that while the possibility of an attack exists, in this case there is no evidence of systems being compromised. The database has now been taken offline

What should you do now?

If you haven't downloaded and installed the WiFI Finder app, there's really no reason to worry. The only reason to worry arises if you've shared your own Wi-Fi using the community upload feature. If you have, then you should change your Wi-Fi password immediately. Overall, this incident should be seen as a warning about why downloading apps from unknown and therefore untrustworthy developers is risky.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS