Secret 'keys' in applications can lead to data theft
Serious security problems in the Android app store, Google Play, were identified by researchers at Columbia University School of Law in a large-scale study.
Security problems include secret "keys" that developers store in their applications, which if recovered, can be used for malicious purposes, such as intercepting user data.
The researchers used a tool called "PlayDrone" to classify and analyze apps, identifying issues and vulnerabilities that had not been found before because very little is known about what is uploaded to Google Play, the researchers said.
"Google Play has over 1 million apps and over 50 billion have been downloaded, but no one cares about what goes on Google Play. Anyone can buy a $25 account and upload whatever they want. We know very little about what's there overall. Given the huge popularity of Google Play and the potential risks to millions of users, we thought it was important to look at the content of Google Play," said Professor Jason Nieh, who led the research.
After analyzing the findings, the scientific team works with Google to "close" security gaps and remove vulnerabilities.
Source: newsbeast.gr

