150M Android Apps Still Susceptible to Heartbleed
April 24, 2014 12:48 PM
comment(s) - last by
Researchers say that some of the 17 apps for Android claiming to search for Heartbleed are fake
Heartbleed has been an
interesting topic of discussion for the past few weeks
. Just last week, a
19-year-old Canadian was arrested
for allegedly hacking into the Canada Revenue Agency (CRA) portal by using Heartbleed.
Word has now surfaced that Heartbleed may be ready to cause a significant problem for Android users. Reports indicate that 150 million Android apps are vulnerable to Heartbleed. Security researchers say that while there are 17 Android apps that are able to scan for Heartbleed, at least six of that number use methods of scanning that are insufficient.
The findings came from
researchers Yulong Zhang, Hui Xue and Tao Wei. The researchers wrote, "For the Android platform, we find that roughly 150M downloads of Android apps contain OpenSSL libraries vulnerable to Heartbleed."
Some versions of Android aren’t vulnerable to Heartbleed, including Jelly Bean 4.1 and 4.1.1, since they don't use OpenSSL or use it in a way where the flawed features susceptible to Heartbleed are disabled by default.
Most of the apps that are vulnerable are games according to the researchers.
On the plus side, the number of apps vulnerable to Heartbleed has declined according to the researchers since April 10 when 220 million were estimated to be vulnerable.
This article is over a month old, voting and posting comments is disabled
RE: Word has just now surfaced?
4/24/2014 2:47:32 PM
I would rather no news than the typical overhyped nature of Android security reports.
I mean most Heartbleed articles, including this one, paint the picture of imminent threats to the end user. As if millions and millions of Android devices are on the verge of being hacked at any moment.
But what does Heartbleed ACTUALLY mean for the end user? The articles never say!
Turns out it's mostly nothing:
When you read this and see how Heartbleed actually leaves you vulnerable, and what a hacker would have to go through to get any useful information, it's highly unlikely Heartbleed poses a real-world risk to the end user.
Also people are reporting that every Android device not running Jelly Bean or Kit Kat is at risk. Which is just not true at all.
"So, I think the same thing of the music industry. They can't say that they're losing money, you know what I'm saying. They just probably don't have the same surplus that they had." -- Wu-Tang Clan founder RZA
Mounties Arrest 19-Year-Old Who Delayed Canada's Tax Filing w/ Heartbleed
April 17, 2014, 3:24 PM
EFF: NSA May Have Used IRC Botnets to Exploit Heartbleed for Last Two Years
April 14, 2014, 4:43 PM
Target Missed Early Warning Signs of Holiday Data Breach
March 13, 2014, 1:45 PM
NPD: Online Shopping is up in 2014, But Brick & Mortar Retail is Booming Too
December 12, 2014, 9:09 AM
Amazon Joins 4K Arms Race, With Free 4K Streaming for Prime Members
December 10, 2014, 10:49 AM
Obama Tells Your Kids to Get Coding for CS Education Week
December 9, 2014, 8:01 AM
Microsoft Offers Office, Xbox, Skype Online Services Bundle for $149 -- 65% Off
December 8, 2014, 2:32 PM
Vimeo Offers 4K Uploads and Downloads, But No Streaming (Yet)
December 8, 2014, 11:55 AM
Comcast Ads "Reeducate" Public on TWC Merger's Net Neutrality "Benefits"
December 3, 2014, 6:01 PM
Most Popular Articles
Air Force Worries Hot Fuel Could Harm F-35, "Proactively" Paints Trucks Shiny
December 11, 2014, 9:06 AM
LaWS (Laser) "Kills" Boat-Hauled Fuel Tanks, UAV "Bomber" in the Persian Gulf
December 12, 2014, 8:31 PM
BlackBerry Classic Sells Out Online (Seriously, It Has) for North America
December 15, 2014, 7:07 PM
Lamborghini Offers Up $6,000 Leather-Bound Android Smartphone
December 12, 2014, 3:12 PM
Ford Announces QNX-Powered SYNC 3, Brags It's "More Smartphone-Like"
December 11, 2014, 10:32 PM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information