opinion

Malware Woes for Open Source App Distribution

As evolution impacts the mobile arena, malware threats and other factors are joining forces to cast a doubt on traditional Open Source Android apps and their free-for-all distribution channels that can lack substantial oversight and be rife with vulnerabilities.

For marketers of adult entertainment, Android’s huge audience cannot be ignored.

Vulnerability to MITM attacks and operator ignorance are only two of the problems facing Android app developers, who must now also contend with Google’s response to the app security issue.

Statistics from mid-November show that Android’s market share is sharply rising, with Google’s OS powering more than 72 percent of Smartphones sold in the past quarter — in comparison to competitor Apple’s iOS, which saw a nearly 14 percent share.

But the size of this market also makes it an attractive target for malicious attacks, such as those against the secure sockets layers (SSL) and transport layer security (TLS) protocols that are supposed to protect a user’s information, but can be compromised when careless coders fail to take the proper precautions.

A recent report by university teams from Hannover and Marburg, Germany, entitled, “Why Eve and Mallory Love Android: An Analysis of Android SSL (In)Security,” finds that while many Android apps have a legitimate need to communicate over the Internet, potential security threats from apps that use the SSL/TLS protocols make sensitive data vulnerable during transit, and calls on Android developers to better protect information they transmit.

The report cites a lack of visual security indicators for SSL/TLS use and inadequate use of SSL/TLS as exploitable for launching Manin-the-Middle (MITM) attacks.

The researchers used a tool known as Mallo-Droid to detect potential vulnerabilities to MITM attacks while targeting 13,500 free apps downloaded from Google’s Play Market.

Its analysis shows that while only 1,074 (8 percent) of the apps contained vulnerable SSL/TLS coding, they represent 17 percent of the apps containing HTTPS URLs — underscoring the false sense of security that an HTTPS link provides.

The team’s study also discovered various forms of SSL/TLS misuse during a manual audit of 100 selected apps and was then able to launch MITM attacks against 41 apps — successfully gathering “a large variety of sensitive data.”

According to the report, this included credentials for American Express, Diners Club, Facebook, Google, Microsoft Live, Paypal, Twitter, WordPress and Yahoo!, plus access to bank and email accounts, web servers and other supposedly secure environments.

Snooping wasn’t the only possibility the group found, however.

‘We have successfully manipulated virus signatures downloaded via the automatic update functionality of an antivirus app to neutralize the protection or even to remove arbitrary apps, including the antivirus program itself,” the report claims, adding that it is “possible to remotely inject and execute code in an app created by a vulnerable app building framework.”

The team estimates that up to 185 million Android users are vulnerable to MITM attacks based on data from Google’s Play Market — and with the threat extending to the deactivation of antivirus systems, it is a threat that users and developers should heed.

The report also reveals the results of an online survey seeking to evaluate perceptions about certificate warnings and HTTPS visual security indicators. It finds that half of the respondents did not know how to tell if their Android browser session was protected by SSL/TLS — highlighting the social aspects of the security equation.

Vulnerability to MITM attacks and operator ignorance are only two of the problems facing Android app developers, who must now also contend with Google’s response to the app security issue — a reply that could include escalating restrictions on applications, as well as the new malware scanning procedures now underway on the Google Play Store — bringing the portal closer to the Draconian policies employed by Apple’s App Store.

For adult app developers who appreciate the libertine airs of the Open Source world, these growing restrictions might not be welcome news, and may further accelerate moves to Android-compatible websites and applications.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

WIA Profile: Samantha Beatrice

Beatrice credits the sex positivity of Montreal for ultimately inspiring her to pursue work in adult entertainment. She had many friends working in the industry, from sex workers to production teams, so it felt like a natural fit and offered an opportunity to apply her marketing and social media savvy to support people she truly believes in and wants to see succeed.

Women In Adult ·
opinion

Understanding the Latest Server Processors

Over the last decade, we mostly stopped talking about CPU performance. Recently, however, there has been a seismic and exciting change in the CPU landscape, due to innovation by a chip company called Advanced Micro Devices (AMD).

Brad Mitchell ·
opinion

User Choice, Privacy and the Importance of Education in AV

As we discussed last month, age verification in the adult sector is critical to ensuring legal compliance with ever-evolving regulations, safeguarding minors from inappropriate content and protecting the privacy of adults wishing to view adult content.

Gavin Worrall ·
opinion

Maintaining Payment Processing Compliance When the Goalpost Keeps Moving

VIRP is the new four-letter word everyone loves to hate. The Visa Integrity Risk Program went into effect last year, and affects several business types — including MCC 5967, which covers adult and anything else with nudity, and MCC 7273, dating services that don’t allow nudity.

Jonathan Corona ·
opinion

Making the Most of Your Sales Opportunities

The compliance road has been full of twists and turns this year. For many, it’s been a companywide effort just to make it across that finish line. Hopefully, most of us can now return our attention to some important things we’ve left on the back burner for months — like driving revenue.

Cathy Beardsley ·
profile

YourPaysitePartner Marks 25-Year Anniversary Amid Indie Content Renaissance

For 25 years, YourPaysitePartner has teamed up with stars and entrepreneurial brands to bring their one-stop-shop adult content dreams to life — and given the indie paysite renaissance of the past few years, the company’s efforts have paid off in spades.

Alejandro Freixes ·
opinion

WIA Profile: B. Wilde

B. Wilde considers herself a strategic, creative, analytical and entertaining person by nature — all useful traits for a “marketing girlie,” a label she happily embraces.

Women In Adult ·
opinion

Proportionality in Age Verification

Ever-evolving age verification (AV) regulations make it critical for companies in the adult sector to ensure legal compliance while protecting the privacy of adults wishing to view adult content. In the past, however, adult sites implementing AV solutions have seen up to a 60% drop in traffic as a result.

Gavin Worrall ·
opinion

Goodbye to Noncompete Agreements in the US?

A noncompetition agreement, also known as a noncompete clause or covenant not to compete, is a contract between an employer and an employee, or between two companies.

Corey D. Silverstein ·
opinion

The Search for Perfection in Your Payments Page

There has been a lot of talk about changes to cross sales and checkout pages. You have likely noticed that acquirers are now actively pushing back on allowing merchants to offer a negative option, upsell or any cross sales on payment pages.

Cathy Beardsley ·
Show More