mHealth Apps Expose Millions to Cyberattacks
#1
Information 
Quote:Some 23 million mobile health (mHealth) application users are exposed to application programming interface (API) attacks that could expose sensitive information, according to researchers.
 
Generally speaking, APIs are an intermediary between applications that defines how they can talk to one another and allowing them to swap information. Researcher Alissa Knight with Approov tried to break into the APIs of 30 different mHealth app vendors, with the agreement she wouldn’t ID the vulnerable ones. Turns out, they were all vulnerable to one degree or another.
 
The average number of downloads for each app tested was 772,619.

According to the resulting report from Approov, out of 30 popular mHealth apps analyzed, 77 percent of them contained hardcoded API keys, which would allow an attacker to intercept that exchange of information — some of which don’t expire. Seven percent of these belonged to third-party payment processors that explicitly warn against hard-coding their secret keys in plain text.

Read more: https://threatpost.com/mhealth-apps-mill...ks/163966/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.6.6 / 19.6.7 Update
Changes in 19.6.6:...harlan4096 — 07:37
AdGuard for iOS 4.5.19
AdGuard for iOS 4....harlan4096 — 07:35
Adobe Acrobat Reader DC 26.001.21431
Adobe Acrobat Read...harlan4096 — 07:34
360 Total Security 11.0.0.1314
11.0.0.1314 Apr 8,...harlan4096 — 07:33
HWiNFO v8.46
HWiNFO v8.46 Re...harlan4096 — 07:31

[-]
Birthdays
Today's Birthdays
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>