Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,180,187 members, 7,910,238 topics. Date: Saturday, 03 August 2024 at 10:40 PM

Over A Billion Apps Can Be Hacked With This Simple Hack - Science/Technology - Nairaland

Nairaland Forum / Science/Technology / Over A Billion Apps Can Be Hacked With This Simple Hack (649 Views)

Earth Was A 'Waterworld' Covered By A Global Ocean 3.2 Billion Years Ago / A Nigeria Tech Company Says It Can Never Be Hacked By Hackers! / I Have A Billion Dollar Idea And Cash To Sponsor But Neeba Developer (2) (3) (4)

(1) (Reply)

Over A Billion Apps Can Be Hacked With This Simple Hack by djayflex: 8:04pm On Nov 06, 2016
Security researchers from the Chinese University Of Hong Kong have discovered a way to target a huge number of Android apps that could allow them to remotely sign into any victim's mobile app account without any knowledge of the victim

.
They discovered that most of the popular Android apps that support single sign-on (SSO) service have implemented OAuth 2.0 the awfully wrong way.

OAuth 2.0 is an open standard for authorization that allows app users to log in to other third-party services by verifying existing identity of their Google, Facebook, or Microsoft Accounts.

This process enables users to sign-in to any service without providing additional usernames or passwords.

How are app developers supposed to implement OAuth? (The Right Way)



Usually when a user signs into a third party app via OAuth, the app verifies with the ID provider, let’s say, Facebook, that it has correct authentication details. If it does, OAuth will receive an 'Access Token' from Facebook which is then issued to the server of that mobile app.

Once the access token has been issued, the app server asks for the user's authentication information from Facebook, verify it and then let the user sign in with his/her Facebook credentials.

How most app developers are really implementing OAuth? (The Wrong Way)



The researchers found that the developers of a massive number of Android apps did not properly verify the validity of the information sent from the ID provider, like Facebook or Google.

Instead of verifying OAuth information (Access Token) attached to the user's a


Read more: http://www.istylmagazine.com/news/technology/over-a-billion-apps-can-be-hacked-with-this-simple-hack/
Re: Over A Billion Apps Can Be Hacked With This Simple Hack by FlySly05: 8:28pm On Nov 06, 2016
Well let's just say we are bleeped with the knowledge of this glitch in Chinese' hands.


I said Bleep.ed and not a fucking sound.

(1) (Reply)

Chrome Remote Desktop: Operate Your PC With Your Android Device / How thieves are pickpocketing wallet apps in China / Team7project - Youth Technology Development Centre Launches Project GSBO'100

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 9
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.