Sony Pixel Power calrec Sony

HP Research Reveals Nine out of 0 Mobile Applications Vulnerable to Attack

18/11/2013

HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack

NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.

According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.

As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.

While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.

Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.

The most common and easily addressable vulnerability sources reported include:

Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.

Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.

Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.

Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.

Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.

Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.

Methodology

Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.

Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.

(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1528865...
See more stories from hp

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

10/05/2025

The National Film and Video Foundation Members of the Appeal Review Committee Call is Open

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

10/05/2025

Samsung Ads Debuts the Samsung Television Network

NEW YORK During the IAB NewFronts 2025, Samsung Ads announced the debut of STN, the Samsung Television Network, a FAST channel with live content that will be av...

10/05/2025

TMobile Demo Sets a 5G Uplink Record

SEATTLE T-Mobile has announced that it set a new uplink speed record of 550 Mbps in sub-6 GHz spectrum using cutting-edge 5G Advanced tech....

10/05/2025

22 Republican U.S. Senators Urge FCC to Modernize Ownership Rules

WASHINGTON Twenty-two U.S. Senators have sent a letter to Federal Communications Commission chair Brendan Carr urging him to modernize ownership caps that are...

10/05/2025

Meet Graduates from Berklees Class of 2025

Meet Graduates from Berklees Class of 2025 Members of this years graduating class reflect on their proudest moments at Berklee and look ahead to whats next. ...

09/05/2025

Journalism Under Gender Apartheid: An Interview with Malala Yousafzai and Zahra Joya

At the Frontline Club in London, a venue long associated with media freedom and ...

09/05/2025

Spotify Data Reveals Eurovision 2025 Fan Favorites, With Sweden's KAJ Leading the Pack

As excitement builds for the annual Eurovision Song Contest, Spotify data offers...

09/05/2025

The National Film and Video Foundation Marketing and Distribution Advisory Panel Call.

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

09/05/2025

The Future of Consumer Engagement

In our latest blog, Laura Rognoni dives into the shifting currents of change in the digital entertainment landscape, revealing the trends that will keep viewers...

09/05/2025

Netflix to Rollout New More Flexible UI Starting May 19

LOS GATOS, Calif. Netflix has announced that starting May 19 it will begin rolling out a major upgrade to its user interface and the TV experience it offers str...

09/05/2025

Iger: Pay TV Subs to Get Upcoming ESPN DTC App

The Walt Disney Co. CEO Bob Iger told analysts the direct-to-consumer ESPN app often referred to as ESPN Flagship will be available to the linear channel'...

09/05/2025

Berklee Online Signs Transfer Articulation with Conservatorio Nacional de Msica

Berklee Online Signs Transfer Articulation with Conservatorio Nacional de M sica The new agreement allows CNM students in the Dominican Republic to transfer i...

09/05/2025

Wooden Camera Launches Accessories for the Blackmagic URS...

Wooden Camera, a leading innovator in camera accessories, is proud to announce the launch of a new line of products for the Blackmagic URSA Cine Cameras. These ...

09/05/2025

LYNX Technik Expands Series 5000 Platform with New 12G-SD...

LYNX Technik, provider of modular signal processing solutions is expanding its popular Series 5000 platform with three new 12G-SDI cards. The new cards provide ...

09/05/2025

Pebble migrates ON TV to new technology platform

Pebble, the leading automation, content management and integrated channel specialist, has completed a project to migrate ON TV, the major independent broadcaste...

09/05/2025

NUGEN Audio Unveils DialogCheck Speech Intelligibility So...

NUGEN Audio launches its new speech intelligibility plug-in, DialogCheck. A mono, stereo and multichannel dialog clarity meter, the software provides an objecti...

09/05/2025

Disguise to Showcase Turnkey Solutions at Middle Easts To...

Disguise the technology platform and solutions provider that powered MDL Beast Soundstorm 2024, Dubai Expo's Al Wasl Dome and visual displays at the Burj ...

09/05/2025

CVP Brings Cutting-Edge Broadcast Live Production and Stu...

CVP has announced it will demonstrate its cutting-edge broadcast, live production and studio solutions at MPTS 2025. Taking place at Olympia London from 14th - ...

09/05/2025

Mediagenix and White Peaks Solutions Team Up to Power Sha...

Mediagenix, a global leader in smart content solutions to profitably connect the right content to the right audience, and White Peaks Solutions, the prominent e...

09/05/2025

SportsEngine Play Extends Award-Winning Collaboration Wit...

SportsEngine Play, the first-of-its-kind streaming service for youth sports, has agreed to a multi-year extension with AI-automated sports content leader, Pixel...

09/05/2025

TOD by beIN goes live with Friend MTS to tackle piracy in...

Friend MTS, a leading global provider of content protection services, today announced that TOD, the premier sports and entertainment OTT subscription service fo...

09/05/2025

ZEISS Demos One-Click Virtual Lens Tech for VFX and Compo...

ZEISS announces that it is in development on a new virtual lens technology that will allow visual effects and compositing artists to apply an authentic lens loo...

09/05/2025

Cerberus Tech at MPTS Unifying Cloud and On-Premises Cont...

At the 2025 Media Production & Technology Show (MPTS), Cerberus Tech will showcase the latest major enhancement to its Livelink IP video delivery platform the...

09/05/2025

Warren Thomas Named Vice President and General Counsel of Capitol Broadcasting Company

Capitol Broadcasting Company welcomed Warren Thomas as the new Vice President an...

09/05/2025

Harvard Taps Studio Technologies for Sports Telecasts

CAMBRIDGE, Mass. Studio Technologies said the Harvard University athletics department has integrated Dante-enabled equipment from the vendor into its broadcast ...

09/05/2025

ITN, Magnite Launch Programmatic Solution for Local Linear TV

NEW YORK ITN, a provider of a local linear supply side platform, and Magnite, a independent sell-side advertising company, have announced that they working toge...

09/05/2025

Nugen Audio Unveils DialogCheck Speech Intelligibility Software

LEEDS, U.K. Nugen Audio has launched a new speech intelligibility plug-in, DialogCheck and offered up quotes from technologists working at places like Netflix p...

09/05/2025

AJA I/O Gear: The Heart of Broadcast Solutions' VEGO Mobile Editing Solution

AJA I/O Gear: The Heart of Broadcast Solutions' VEGO Mobile Editing Solution Brie Clayton May 8, 2025 0 Comments When working remotely on broadcas...

09/05/2025

What do they teach in an Advanced Adobe After Effects Course?

What do they teach in an Advanced Adobe After Effects Course? Roland Kahlenberg May 8, 2025 0 Comments There aren't many advanced After Effects co...

09/05/2025

Larry Jordan Sits with Trevor Morgan of OpenDrives at NAB 2025

Larry Jordan Sits with Trevor Morgan of OpenDrives at NAB 2025 Brie Clayton May 8, 2025 0 Comments Trevor Morgan, COO of OpenDrives, shares how the co...

09/05/2025

Berklee Popular Music Institute Announces UK Festival Debut and Tour Dates

Berklee Popular Music Institute Announces UK Festival Debut and Tour Dates For the first time, BPMI will bring Berklee-affiliated artists and students to the ...

09/05/2025

MLB Sunday Leadoff' 2025: MLB Local Media Pulls the Production, Operational Strings in Second Season on Roku

MLB Sunday Leadoff' 2025: MLB Local Media Pulls the Production, Operational ...

09/05/2025

LTN, Pro Volleyball Federation To Wrap Second Season With Championship Weekend

LTN, Pro Volleyball Federation To Wrap Second Season With Championship Weekend PVF's broadcast coverage has risen 350% from its debut season By Mark J Burn...

09/05/2025

Evertz's Ray Kasprzyk on Meeting the Unique Technological Needs of Massive Live Esports Productions

Evertz's Ray Kasprzyk on Meeting the Unique Technological Needs of Massive L...

09/05/2025

With Real Madrid-FC Barcelona, ESPN Preps for Most Ambitious LaLiga Match Coverage Yet

With Real Madrid-FC Barcelona, ESPN Preps for Most Ambitious LaLiga Match Covera...

09/05/2025

Sky Original documentary The Girl Who Caught a Killer to air on Sky and streaming service NOW on 25 May

Friday 9 May 2025 Download images HERE Episodes are available on Sky Media Vil...

09/05/2025

SO JI-SUB Returns With Cold and Intense Noir Action Series Mercy For None', Premiering June 6

Back to All News SO JI-SUB Returns With Cold and Intense Noir Action Series Me...

09/05/2025

Netflix Announces Our First-Ever Nordic Medical Drama Starring Sara Khorami in the Lead Role

Back to All News Netflix Announces Our First-Ever Nordic Medical Drama Starring...

09/05/2025

Marquis launches Postflux for Pro Tools' audio production management software

New beta programme for Avid Pro Tools users provides versioned backup/archive M...

09/05/2025

RT Statement: Eurovision Song Contest 2025

Further to the comments from RT Director-General, Kevin Bakhurst on Wednesday 7th May included below in which he asked the EBU for a discusion on Israel...

09/05/2025

Tom Brady, Nadine Coyle, Joe Duffy and EMMY among guests on this week's Late Late Show season finale

Here is your host, Patrick Kielty! In the season finale of The Late Late Show, ...

09/05/2025

My Eurovision Party 2025 - join in on the fun with RT Kids and Marty Whelan avatar!

My Eurovision Party 2025 - join in on the fun with RT Kids! Eurovision launche...

08/05/2025

What to Watch: 6 Sundance Institute-Supported Films by Filipino Directors

A sinister fairy infiltrates a desperate family in Kenneth Dagatan's In My Mother's Skin, which premiered at the 2023 Sundance Film Festival. Photo co...

08/05/2025

Expected weak market dynamics weigh on business development in the first three months 2025

As expected, continued weak demand from key sales markets and declining economic...

08/05/2025

BBC announces Agatha Christie's Endless Night, adapted by Sarah Phelps

A new three-part series is coming to BBC iPlayer and BBC One (Image: The Christie Archive Trust) The BBC has announced Agatha Christie's Endless Night, a...

08/05/2025

Managing the Mission: Teaching Technique to C3ISR Operators

For skyward-bound operators, training focuses on the unique aspects of flying ISR missions, including the management of onboard surveillance equipment and the e...

08/05/2025

Cable Industry Backs Broadcasters' Move to Software-Based EAS

The cable industry has told the Federal Communications Commission it supports the National Association of Broadcasters' proposal to allow broadcasters to us...

08/05/2025

CTA Tells FCC: Dont Mandate ATSC 3.0 Tuners

WASHINGTON The Consumer Technology Association has continued its opposition to mandates requiring that NextGen TV/ATSC 3.0 tuners be included in new TV sets, sa...

08/05/2025

TAG Video Systems Appoints Paul Maroni as Vice President...

TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real time visualization, has named Paul Maroni as Vice Pres...