The Jerusalem Post

Mobile-app errors said to expose data on 180 million smartphone­s

- R #Z 45&1)&/ /&--*4

Up to 180 million smartphone owners are at risk of having some of their text messages and calls intercepte­d by hackers because of a simple coding error in at least 685 mobile apps, cybersecur­ity firm Appthority warned last week.

Developers mistakenly coded credential­s for accessing services provided by Twilio Inc., Appthority director of security research Seth Hardy said. Hackers could access those credential­s by reviewing the code in the apps, then gain access to data sent over those services, he said.

The findings highlight new threats posed by the increasing use of third-party services such as Twilio that provide mobile apps with functions such as text messaging and audio calls. Developers can inadverten­tly introduce security vulnerabil­ities if they do not properly code or configure such services.

“This isn’t just limited to Twilio. It’s a common problem across third-party services,” Hardy said. “We often notice that if they make a mistake with one service, they will do so with other services as well.”

Many apps use Twilio to send text messages, process phone calls and handle other services. Hackers could access related data if they log into the developer accounts on Twilio, Hardy said.

The mistakes were caused by developers, not Twilio, he said. Twilio’s website warns developers that leaving credential­s in apps could expose their accounts to hackers.

Twilio spokesman Trak Lord said the company has no evidence that hackers used credential­s coded into apps to access customer data, but it was working with developers to change the credential­s on affected accounts.

The vulnerabil­ity only affects calls and texts made inside of apps that use messaging services from Twilio, including some business apps for recording phone calls, according to Appthority’s report.

Credential­s for back-end services such as Twilio are coveted by hackers because developers often reuse their accounts to build multiple apps.

In a survey of 1,100 apps, Appthority found 685 problem apps that were linked to 85 affected Twilio accounts. That suggests the theft of credential­s for one app’s Twilio account could pose a security threat to all users of as many as eight other apps.

Appthority said it also warned Amazon.com Inc. that it had found credential­s for at least 902 developer accounts with cloud-service provider Amazon Web Services in a scan of 20,098 different apps.

Those credential­s could be used to access app user data stored on Amazon, Hardy said.

An Amazon representa­tive declined comment.

Newspapers in English

Newspapers from Israel