150M Android Apps Still Susceptible to Heartbleed
April 24, 2014 12:48 PM
comment(s) - last by
Researchers say that some of the 17 apps for Android claiming to search for Heartbleed are fake
Heartbleed has been an
interesting topic of discussion for the past few weeks
. Just last week, a
19-year-old Canadian was arrested
for allegedly hacking into the Canada Revenue Agency (CRA) portal by using Heartbleed.
Word has now surfaced that Heartbleed may be ready to cause a significant problem for Android users. Reports indicate that 150 million Android apps are vulnerable to Heartbleed. Security researchers say that while there are 17 Android apps that are able to scan for Heartbleed, at least six of that number use methods of scanning that are insufficient.
The findings came from
researchers Yulong Zhang, Hui Xue and Tao Wei. The researchers wrote, "For the Android platform, we find that roughly 150M downloads of Android apps contain OpenSSL libraries vulnerable to Heartbleed."
Some versions of Android aren’t vulnerable to Heartbleed, including Jelly Bean 4.1 and 4.1.1, since they don't use OpenSSL or use it in a way where the flawed features susceptible to Heartbleed are disabled by default.
Most of the apps that are vulnerable are games according to the researchers.
On the plus side, the number of apps vulnerable to Heartbleed has declined according to the researchers since April 10 when 220 million were estimated to be vulnerable.
This article is over a month old, voting and posting comments is disabled
Please, educate yourself!
4/24/2014 5:48:12 PM
The only version of android that is vulnerable is 4.1.1. AND, in order to be hacked by it, you have to have some sort of cross scripting attack done on the included android browser in another tab, which btw, is not included by default anymore after 4.0.3.
You can't have a cross attack in an app because there isn't anything there to take a peak, and all apps are sandboxed in their own accounts so each app can't talk to each other.
The people who need to worry are the major websites who used openssl on their web servers, and the users of them should change their passwords after they hopefully trashed their old certificates.
"I mean, if you wanna break down someone's door, why don't you start with AT&T, for God sakes? They make your amazing phone unusable as a phone!" -- Jon Stewart on Apple and the iPhone
Mounties Arrest 19-Year-Old Who Delayed Canada's Tax Filing w/ Heartbleed
April 17, 2014, 3:24 PM
EFF: NSA May Have Used IRC Botnets to Exploit Heartbleed for Last Two Years
April 14, 2014, 4:43 PM
Target Missed Early Warning Signs of Holiday Data Breach
March 13, 2014, 1:45 PM
Comcast Memo: Harassing Customers During Retention Calls Actually IS Our Policy
July 22, 2014, 5:19 PM
Aereo Now Claims It's a Cable Company, Reveals it Has Very Few Customers
July 22, 2014, 4:20 PM
Edward Snowden Presents Tech to Stop Government Spying
July 21, 2014, 12:00 PM
Verizon FiOS Network Upgrade Brings Symmetrical Upload/Download Speeds
July 21, 2014, 8:33 AM
Amazon Launches First Fire Phone TV Spot, Spends 30 Seconds Promoting Prime
July 18, 2014, 11:17 AM
Samsung Continues to Pick on Apple's iPad in Two New Commercials
July 13, 2014, 5:35 PM
Most Popular Articles
Quick Note: Nokia Devices Now Receiving Windows Phone 8.1 Update
July 15, 2014, 10:42 AM
Microsoft Kills Entertainment Unit, May Shelve Flagship Lumia "McLaren"
July 18, 2014, 7:40 PM
Boeing 777 Malaysian Airlines Flight 17 Crashes in Ukraine
July 17, 2014, 1:00 PM
Tesla Confirms “Model III” EV with 200+ Mile Range, Blames Ford for Missed "SEX"
July 15, 2014, 9:12 PM
FBI Report Suggests That Self-Driving Cars Could Be Used as Rolling Bombs
July 16, 2014, 11:02 AM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information