Report finds glaring security flaws in mobile payment apps
Most of the leading modern mobile payment systems are not sufficiently protected to handle the amount of auditing effort that criminals are typically willing to put into payment systems, as a recent report by Bluebox shows.
The company studied ten of the most popular mobile payment apps, ranging from mobile wallet apps (e.g., Apple Pay, Google Wallet, Samsung Pay) to one-click payment merchants (e.g., Amazon, BestBuy, Target), and to peer-to-peer payment apps (e.g., Venmo, Square Cash, SnapCash) as well as apps that connect to bank accounts (e.g., Dash, Uber, Lyft).
According to Bluebox, three major issues were identified. The first relates to communication channels that are not properly protected and would allow attackers to redirect payments to their desired location.
The second issue has to do with the third-party code included in these applications, which generally constitutes 75% of an app’s code. If this code is “simply included” in mobile payment applications without going through proper security checks, various problems could easily occur in the system .
Mobile payment apps aren't ready for primetime
To make matters worse, in the event that a device is compromised, none of the apps analyzed by the Bluebox team encrypt data stored on disk. This means that, when the device is hacked, all financial information stored within these apps is up for grabs.
Bluebox says that all of the applications studied were easily accessible to at least one of the following three attacks: dynamic execution time attacks, traffic interception attacks, and application code manipulation attacks.
The study’s results are worrying, especially with Black Friday and Cyber Monday just around the corner. With many companies like Google, Apple, and Samsung pushing mobile payment apps, cybercriminals will follow the money and turn their attention to these new payment systems.

