The researchers who discovered the vulnerability Heartbleedfound that more than half of the 50 most popular Android apps have security vulnerabilitiesdue to irresponsible recycling of code libraries.
The list of these applications will be announced later this month by Codenomicon , which coined the term “Heartbleed,” while it will publish its conclusions for those who neglected to adopt stronger security practices.
What these Android apps do is send the user's Android ID to third-party advertising networks , apparently without the user's permission .
According to the study, 1 in 10 applications send the device's IMEI code or location data to third parties, 1 in 10 applications are connected to more than two advertising networks , while the fact that there is even an application that sends the user's mobile phone number is surprising
Also, 30% of applications transmit personal data in plain text and many others do not encrypt data during transmission.
Codenomicon's chief security officer, Olli Jarva, told ITNews that 80% to 90% of mobile applications consist of reusable libraries, most of which are available in the open source framework.
This is because developers don't want to invest in rewriting code for every application they have.
Consequently, applications inherit security vulnerabilities, either due to poor designor errors when integrating code into applications.
These security vulnerabilities are sometimes detected, other times, as in the case of Heartbreed, they are discovered years.
Finally, Jarva hinted that some developers operate “intentionally”to serve the interests of advertisers.
Source: e-pcmag.gr

