{"id":2085,"date":"2024-12-18T09:42:08","date_gmt":"2024-12-18T08:42:08","guid":{"rendered":"https:\/\/www.mobisec.com\/?post_type=press-release&#038;p=2085"},"modified":"2024-12-18T09:42:10","modified_gmt":"2024-12-18T08:42:10","slug":"from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers","status":"publish","type":"press-release","link":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/","title":{"rendered":"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec&#8217;s ethical hackers."},"content":{"rendered":"<h3>The tests were conducted locally, without any attempt to intrude into the servers.<\/h3>\n<p><em>Mobisec conducted an analysis of mobile apps in various sectors: healthcare, finance, energy, GDO, and telco. Subjected to nine different security tests, none of the apps were able to pass them all completely.<\/em><\/p>\n<p><span style=\"text-decoration: underline;\">Treviso, September 17, 2024<\/span> \u2013 Five industry sectors, namely healthcare, finance, energy, GDO, and telco, nine different security tests conducted: the results of the dry runs (a testing process used to ensure that a system functions correctly and does not cause severe failures) performed using proprietary software by <strong>Mobisec<\/strong>&#8216;s ethical hackers, a Treviso-based company specializing in mobile application cybersecurity, are discouraging. None of the tested apps managed to pass all nine tests they were subjected to.<\/p>\n<p><strong>THE TESTS<\/strong><br \/>\nMobisec&#8217;s team of ethical hackers conducted all of these tests locally, installing the apps on both Android and iOS smartphones.<strong> There was no attempt to intrude into the servers.<\/strong> The tests were carried out using several of the tests outlined in the <strong>MASTG<\/strong> (Mobile Application Security Testing Guide), which is the manual that includes all the tests to assess whether a mobile app complies with the guidelines established by the <strong>MASVS<\/strong> (Mobile Application Security Verification Standard).<\/p>\n<p>In other words, the Mobisec team took on the role of a hacker who, in the preliminary phase before an attack, aims to get a quick and general view of the potential access points to a mobile application in order to identify the perfect target. Among the elements tested were data encryption protection, the updating of libraries and security certificates, and the consistency between the service offered by the app and the permissions it requests (such as access to contacts or the camera).<\/p>\n<p>&nbsp;<\/p>\n<p><strong>HEALTHCARE<\/strong><\/p>\n<p>Regarding the healthcare sector, the analysis focused on apps for appointment booking and access to diagnostic test results from various regions in Italy. In this case, <strong>27.7%<\/strong> of the tests conducted ended in failure. The main issue for the Android versions (all of which failed this test) was the verification of digital signature certificates, a problem that could allow the insertion of malicious software. On the other hand, 50% of the iOS applications showed the possibility of inserting fake data into security certificates, which are used for automatic system checks.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>GDO<\/strong><\/p>\n<p>The Android apps in the GDO sector (apps from several large retail chains, both food and non-food) failed <strong>54%<\/strong> of the tests. Specifically, all of them had the keyboard cache enabled, meaning they automatically filled in text fields containing potentially sensitive information (such as usernames and passwords, but also tax codes\u2014information that, if malware were present on the smartphone, could be easily stolen). On the iOS side, the main issue affecting <strong>75%<\/strong> of the tested apps was the mismatch between the security certificates on the app and those on the servers.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>FINANCE<\/strong><\/p>\n<p>There are two main issues with Italian banking apps: data encryption and the consistency between the services offered and the permissions requested. <strong>67%<\/strong> of the apps tested, both on iOS and Android, did not pass these tests.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>ENERGY<\/strong><\/p>\n<p>One of the most prominent issues found in energy sector applications is the use of <strong>third-party libraries,<\/strong>pieces of code written by other developers. While this solution saves time, it exposes the app to the risk that the code may be malicious and provide an entry point for attackers.<strong> 86%<\/strong> of the apps in this sector, both on iOS and Android, rely on outdated and insecure versions of these third-party libraries.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>TELCO<\/strong><\/p>\n<p><strong>80%<\/strong> of the apps from telecommunications companies failed the test that checks the consistency between the security certificates on the app and those installed on the server. This situation can expose the app to <strong>sniffing<\/strong> attacks, where an attacker intercepts the communication between the app and the server or <strong>server spoofing<\/strong> attacks, where the attacker impersonates a server and steals the data sent by the app.<\/p>\n<p>\u00abThe elements we tested represent potential weaknesses that a malicious hacker could try to exploit to gain access to data, both that stored on individual smartphones and on servers\u00bb, emphasizes <strong>Riccardo Poffo<\/strong>, Chief Technical Officer of Mobisec. \u00abBoth Apple and Google invest heavily in the security of their operating systems, as do the developers who create the hundreds of libraries that populate software. However, daily patches are released to fix security issues, but they are not applied with the necessary frequency by those maintaining the apps\u00bb,he continues, \u00abThis is a cultural problem imposed by the market and modern software development practices, with developers facing tight deadlines and focusing too much on continuous releases, without allocating the time required to apply these crucial security updates that are essential to prevent cyber incidents. That\u2019s why a service like Mobisec DSA (Dynamic Security Analysis), which enables continuous and regular security checks on apps, helps promptly identify potential security vulnerabilities and take action to fix them\u00bb.<\/p>\n","protected":false},"featured_media":0,"template":"","meta":{"_acf_changed":false,"content-type":""},"class_list":["post-2085","press-release","type-press-release","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec&#039;s ethical hackers. | Mobisec<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec&#039;s ethical hackers. | Mobisec\" \/>\n<meta property=\"og:description\" content=\"The tests were conducted locally, without any attempt to intrude into the servers. Mobisec conducted an analysis of mobile apps in various sectors: healthcare, finance, energy, GDO, and telco. Subjected to nine different security tests, none of the apps were able to pass them all completely. Treviso, September 17, 2024 \u2013 Five industry sectors, namely [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/\" \/>\n<meta property=\"og:site_name\" content=\"Mobisec\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-18T08:42:10+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\\\/\",\"url\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\\\/\",\"name\":\"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec's ethical hackers. | Mobisec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#website\"},\"datePublished\":\"2024-12-18T08:42:08+00:00\",\"dateModified\":\"2024-12-18T08:42:10+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Homepage\",\"item\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Press releases\",\"item\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/press-release\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec&#8217;s ethical hackers.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/\",\"name\":\"Mobisec\",\"description\":\"Protect your mobile security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec's ethical hackers. | Mobisec","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/","og_locale":"en_US","og_type":"article","og_title":"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec's ethical hackers. | Mobisec","og_description":"The tests were conducted locally, without any attempt to intrude into the servers. Mobisec conducted an analysis of mobile apps in various sectors: healthcare, finance, energy, GDO, and telco. Subjected to nine different security tests, none of the apps were able to pass them all completely. Treviso, September 17, 2024 \u2013 Five industry sectors, namely [&hellip;]","og_url":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/","og_site_name":"Mobisec","article_modified_time":"2024-12-18T08:42:10+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/","url":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/","name":"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec's ethical hackers. | Mobisec","isPartOf":{"@id":"https:\/\/www.mobisec.com\/en\/#website"},"datePublished":"2024-12-18T08:42:08+00:00","dateModified":"2024-12-18T08:42:10+00:00","breadcrumb":{"@id":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.mobisec.com\/en\/press-release\/from-healthcare-to-gdo-including-finance-energy-and-telco-there-are-no-100-secure-apps-results-of-an-analysis-by-mobisecs-ethical-hackers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Homepage","item":"https:\/\/www.mobisec.com\/en\/"},{"@type":"ListItem","position":2,"name":"Press releases","item":"https:\/\/www.mobisec.com\/en\/press-release\/"},{"@type":"ListItem","position":3,"name":"From Healthcare to GDO, including Finance, Energy, and Telco: There are no 100% Secure Apps Results of an analysis by Mobisec&#8217;s ethical hackers."}]},{"@type":"WebSite","@id":"https:\/\/www.mobisec.com\/en\/#website","url":"https:\/\/www.mobisec.com\/en\/","name":"Mobisec","description":"Protect your mobile security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mobisec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/press-release\/2085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/press-release"}],"about":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/types\/press-release"}],"wp:attachment":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/media?parent=2085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}