Mobile security vulnerabilities threaten millions in Latin America: ICFP and Citizen Lab fellow Beau Kujath finds security vulnerabilities in mobile applications in Latin America region.
ID: a09879e0-9514-5db9-bb42-0f1b0ddae42d
STIX ID: report--a09879e0-9514-5db9-bb42-0f1b0ddae42d
Feed Name: The Citizen Lab
Citizen Lab and an Open Technology Fund fellow analyzed popular Latin American mobile applications and found systemic security and privacy issues: several telecom apps use cleartext HTTP (allowing eavesdropping and injection), apps transmit personal data to third-party servers contrary to stated privacy claims, a Salvadoran crypto wallet uses Microsoft CodePush enabling remote updates outside app-store controls, and SMS-delivered links in multiple apps are vulnerable to SSL-strip attacks — collectively exposing millions of users to data leakage, manipulation, and potential supply-chain style compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
