Sony Pixel Power calrec Sony

HP Research Reveals Nine out of 0 Mobile Applications Vulnerable to Attack

18/11/2013

HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack

NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.

According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.

As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.

While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.

Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.

The most common and easily addressable vulnerability sources reported include:

Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.

Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.

Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.

Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.

Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.

Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.

Methodology

Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.

Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.

(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1528865...
See more stories from hp

Most recent headlines

04/08/2024

Dalet Appoints Santiago Solanas as CEO to Lead Next Era of Growth and Innovation

Dalet, a leading technology and service provider for media-rich organizations, is excited to announce Santiago Solanas as its new Chief Executive Officer (CEO)....

03/06/2024

Dalet and Veritone Reach Agreement to Distribute, Transact and Monetize Media Archives

Dalet, a leading technology and service provider for media-rich organizations, a...

01/05/2024

Release Rundown: What to Watch in May, From I Saw the TV Glow to Power

Owen (Justice Smith) and Maddy (Brigette Lundy-Paine) develop an eerie connection to a supernatural TV show in Jane Schoebrun's I Saw the TV Glow....

01/05/2024

Celebrate May the 4th With Special Star Wars' Playlists, Audiobooks, and More

Spotify's Star Wars celebrations are in full Force starting today, and this ...

01/05/2024

Spotify's New Hardcore Gardening Playlist and Brain Dead Collab Will Rattle Greenhouses Everywhere

All around the world, millions of Spotify fans love listening to hardcore punk m...

01/05/2024

THE CALL FOR THE FIFTH PRESIDENTIAL EMPLOYMENT STIMULUS PROGRAMME (PESP5) FOCUSED ON THE AUDIO-VISUAL INDUSTRY, IS OPEN.

THE CALL FOR THE FIFTH PRESIDENTIAL EMPLOYMENT STIMULUS PROGRAMME (PESP5) FOCUSE...

01/05/2024

QTAKE Pioneers Live 3D Stream to Apple Vision Pro

QTAKE, the leading video assist and on-set collaboration software trusted by professional filmmakers worldwide, launched a new cutting-edge feature at NAB 2024....

01/05/2024

LA County Opens Entertainment Business Interruption Fund Grant Program for Small Business, LAEDC Offers Updates

In HPA's ongoing focus on providing input and insight from city and county g...

01/05/2024

Trailblazing AI Storytelling by Empowering Storytellers: Curious Refuge

HPA Newsline had the opportunity to speak with Caleb and Shelby Ward, founders of Curious Refuge. Caleb and Shelby were participants in the 2024 HPA Tech Retrea...

01/05/2024

Supporting Global Air Traffic Modernization through Managed Services Infrastructure

L3Harris works with air navigation service providers who efficiently manage air ...

01/05/2024

Q&A with Scott Alexander, Aerojet Rocketdyne's new Missile Solutions President

Scott Alexander, Missile Solutions President, Aerojet Rocketdyne...

01/05/2024

Comcast: More Than Half of Viewers Frustrated About Finding Content

NEW YORK Just over half of U.S. viewers are frustrated over their ability to be able to find content to watch on TV according to Comcast....

01/05/2024

Bally RSNs Go Dark On Comcast Systems

Bally Sports Regional Networks were taken off Comcast's systems on April 30 when their existing distribution agreement expired and Diamond Sports Group was ...

01/05/2024

NXTGENbps powers Molinare's Notorious DIT

NXTGENbps battery solutions are designed to replace diesel generators and offer silent, emission-free power for various applications in film, TV, outside broadc...

01/05/2024

Elodie Ichter Joins Light Iron as Senior Colorist

Light Iron, the post-production creative-services division of Panavision, is excited to announce that lodie Ichter has joined the company's artist roster a...

01/05/2024

CJP presents live mo-cap demos at MPTS

CJP Broadcast Service Solutions, systems integration, production and content digitisation specialist, will feature live motion capture demonstrations at the 202...

01/05/2024

Media Links Partners with Sunteq for Representation in S...

Media Links, manufacturer and pioneer in Media over IP transport technology, has partnered with Sunteq spol s.r.o., a leading reseller located in Slovakia to st...

01/05/2024

Dot Group Showcases Enhanced Data Management and Sustaina...

Dot Group, a leader in cutting-edge data management solutions and the premier European reseller of critical Broadcast supporting IBM technologies, will demonstr...

01/05/2024

Glensound shows the latest in IP audio at MPTS

Glensound, industry leader in high quality audio systems, is showcasing the latest additions to its extensive portfolio of networked audio products at MPTS. Aud...

01/05/2024

Hitomi Broadcast to demonstrate ST2110 MatchBox at MPTS

Hitomi Broadcast, a leader in audio/video alignment and latency solutions, will be demonstrating advancements in SMPTE ST2110 workflows ensuring broadcasters ha...

01/05/2024

Leading UK vendors join in the CABSAT 30th anniversary ce...

Taking a leading role in the 30th anniversary CABSAT exposition (Dubai World Trade Centre, 21 23 May), the GREAT Britain and Northern Ireland pavilion will fe...

01/05/2024

NXTGENbps Powers Notorious DITs Green Energy Initiative w...

NXTGENbps, a pioneer in green energy solutions, proudly announces its partnership with Notorious DIT, a leading provider of digital imaging technology services ...

01/05/2024

Videosys Broadcast Brings Pan and Tilt To Coverage Of The...

As Cambridge celebrated its double win over Oxford in the 2024 Boat Race, behind the scenes celebrations were also taking place at Videosys Broadcast to mark th...

01/05/2024

Live After 5' summer concert series returns to downtown Raleigh

A popular - and free - summer concert series is coming back to downtown Raleigh! WRAL is proudly partnering with Downtown Raleigh Alliance for its Live After ...

01/05/2024

Cadent Launches Performance TV To Boost Omnichannel Ad Results

Cadent said it launched Performance TV, designed to increase the effectiveness of campaign by combining the reach of traditional linear TV with the targeting of...

01/05/2024

Eric Johnson, KOMO Seattle Anchor, Sets Retirement

Eric Johnson, anchor at KOMO Seattle, will retire as of June 6. Johnson anchors the 5 and 6 p.m. weekday newscasts and writes/produces/hosts Eric's Heroes,...

01/05/2024

T-Mobile Dials Deeper Into Ad Business With Retail Network (NewFronts)

T-Mobile said it is expanding its advertising business, creating an in-store retail media network and adding Plex, the video streaming platform for its footprin...

01/05/2024

Samsung Ads Expands AI Tools To Target Streaming Viewers (NewFronts)

Samsung Ads said it was introducing new opportunities for advertisers to use data about its viewers to target viewers across the full marketing funnel at its Ne...

01/05/2024

Samsung TV Plus Swings for the Fences With Streaming Sports Channels (NewFronts)

Samsung's ad-supported streaming platform Samsung TV Plus is putting more sports in its lineup with free channels about baseball, golf, hockey, auto racing ...

01/05/2024

Dan Rather Documentary Offers Open-Book' Look at Newsman

Rather, a documentary about famed newsman Dan Rather, premieres on Netflix May 1. The film looks at his rise to prominence in TV news, including his work coveri...

01/05/2024

Ken Wayne, KRON San Francisco Anchor, Retires Next Month

Ken Wayne, evening anchor at KRON San Francisco, is retiring after 33 years in Bay Area television. He was born in Marin County, started his journalism career a...

01/05/2024

Jeff Blaszak Promoted To Senior VP at ShowSeeker

ShowSeeker, the company behind the Pilot cloud-based order management system, said it promoted Jeff Blaszak to senior VP of business operations and strategy....

01/05/2024

Great American Media Picks VideoAmp As Ad Currency

Great American Media said it reached an agreement with VideoAmp that will enable clients to use VideoAmp's ad buying measurement and data capabilities when ...

01/05/2024

NXTGENbps powers Molinaire's Notorious DIT

NXTGENbps battery solutions are designed to replace diesel generators and offer silent, emission-free power for various applications in film, TV, outside broadc...

01/05/2024

Amazon CEO: AWS has multi-billion dollar revenue run rate in AI already

Sales rose to $25bn during the first three months of 2024, up 17 per cent year-on-year By Matthew Corrigan Published: May 1, 2024 Sales rose to $25bn duri...

01/05/2024

Roku to Offer NBC Olympics Zone

NEW YORK NBCUniversal and Roku are teaming up to offer the NBC Olympic Zone on Roku, a new destination on the Roku Home Screen Menu. The dedicated channel wil...

01/05/2024

U.K.'s Freely Officially Launches

Freely the new streaming service backed by Britain's leading broadcasters BBC, ITV, Channel 4 and Channel 5 is now available through the next generation of ...

01/05/2024

Study: FAST Channel Growth Accelerates

NEW YORK A new report on free, ad-supported streaming channels indicates that their growth continues to accelerate, with the number of channels hours views and ...

01/05/2024

VuWall Unveils New Capabilities For VuStream 150 Video Encoder

MONTREAL VuWall has enhanced its VuStream 150 H.264 video encoder with new features and capabilities, including support for HDMI signals at resolutions up to 38...

01/05/2024

Samsung TV Plus Announces New High-Profile FAST Channels for Sports

NEW YORK At the IAB NewFronts 2024, Samsung Ads announced a new lineup of premium sports, music, family and entertainment content on its leading FAST service Sa...

01/05/2024

WAPA TV Celebrates 70th Anniversary As #1 Station in Puerto Rico

SAN JUAN, PUERTO RICO WAPA TV has announced that it will be celebrating its 70th anniversary on May 1 as the number 1 broadcasters on the island....

01/05/2024

Diamond Sports Group Renews Its Distribution Deal with Cox

SOUTHPORT, Conn. & ATLANTA Diamond Sports Group and Cox Communications have reached a multi-year renewal of their distribution agreement for the continued carri...

01/05/2024

Warner Bros. Discovery Networks Dropped by Fubo

As the NBA playoffs heat up on TNT, Warner Bros. Discovery and FuboTV have been unable to reach a new distribution deal. That impasse forced the vMVPD to drop T...

01/05/2024

Time for NAB Reality Check

Time for NAB Reality Check Andy Marken April 30, 2024 0 Comments Above image source - Allegiant, Summit Entertainment Great leaders don't seek...

01/05/2024

Dream Street Productions Switches Live Corporate Events with ATEM Television Studio HD8 ISO

Dream Street Productions Switches Live Corporate Events with ATEM Television Stu...

01/05/2024

lodie Ichter Joins Light Iron as Senior Colorist

lodie Ichter Joins Light Iron as Senior Colorist Brie Clayton April 30, 2024 0 Comments Acclaimed colorist brings global expertise on high-profile pro...

01/05/2024

SVG Digital Engagement Forum: Sessions Now Available to Watch on SVG PLAY

SVG Digital Engagement Forum: Sessions Now Available to Watch on SVG PLAY Catch up on the latest in streaming, interactivity, engagement and more from this inau...

01/05/2024

David Beckham Scores on the Cover of 'Queue' Issue 16

Back to All News David Beckham Scores on the Cover of Queue Issue 16 David Beckham on the cover of Queue. Krista Smith Director, Queue Entertainment 01 Ma...

01/05/2024

Haivision Celebrates 20 Years of Leadership and Innovation in Live Video

MONTREAL, CANADA - May 1, 2024 - Haivision Systems Inc. ( Haivision ) (TSX: HAI), a leading global provider of mission-critical, real-time video networking and ...

01/05/2024

MPTS. London. May 15-16, 2024

Wednesday, 15 May 11:35 The Gallows Pole - Creating a Workflow to Support the Creative Vision FilmLight sits down with the award-winning Residence Pictures t...