Close Menu
  • Home
  • Android
  • Android Operating
  • Apple
  • Apps
  • Gadgets
  • Galaxy
  • Ipad
  • IPhone
  • Smartphone
  • Tablet

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Muse Dash, Hyperforma, Tower of Fortune 4, etc.

March 28, 2025

Best Kitchen Gadgets of 2025

March 18, 2025

The best drawing tablets of 2025: Expert tested and recommended

February 13, 2025
Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
Wtf AndroidWtf Android
  • Home
  • Android
  • Android Operating
  • Apple
  • Apps
  • Gadgets
  • Galaxy
  • Ipad
  • IPhone
  • Smartphone
  • Tablet
Wtf AndroidWtf Android
Home » AWS, Azure authentication keys found in Android and iOS apps used by millions of users
Apps

AWS, Azure authentication keys found in Android and iOS apps used by millions of users

adminBy adminOctober 22, 2024No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


AWS, Azure authentication keys found in Android and iOS apps used by millions of users

Several popular mobile applications for iOS and Android come with hard-coded, unencrypted credentials for cloud services such as Amazon Web Services (AWS) and Microsoft Azure Blob Storage, which protect user data and Your source code has been exposed to a security breach.

If this type of credential is exposed, it can easily lead to unauthorized access to storage buckets or databases containing sensitive user data. Apart from this, attackers can also use them to manipulate or steal data.

According to a report from Symantec, a Broadcom company, these keys exist in the app’s codebase due to errors or poor practices during development.

“Recent analysis reveals an alarming trend: Some widely used apps include hard-coded and unencrypted cloud service credentials within their codebases. ,” Symantec explains.

“This dangerous activity allows anyone with access to the app’s binaries or source code to extract these credentials and misuse them to manipulate or steal data, potentially leading to major security breaches. “This means that,” the researchers said.

Symantec says its researchers discovered credentials to cloud services in the following apps on Google Play:

  1. photo stitch – Over 5 million downloads – Amazon hardcoded credentials
  2. Mercabs – Over 5 million downloads – Hardcoded credentials for Microsoft Azure Blob Storage
  3. Sureka businesss – 500,000+ downloads – Microsoft Azure Blob Storage Hardcoded Credentials
  4. resound tinnitus relief – 500,000+ downloads – Microsoft Azure Blob Storage Hardcoded Credentials
  5. Salusa – 100,000+ downloads – Microsoft Azure Blob Storage Hardcoded Credentials
  6. Chola Ms Breakin – 100,000+ downloads – Microsoft Azure Blob Storage Hardcoded Credentials
  7. EatSleepRIDE Motorcycle GPS – 100,000+ downloads – Twilio hardcoded credentials
  8. Beltone relieves tinnitus – 100,000+ downloads – Microsoft Azure Blob Storage Hardcoded Credentials
Pic Stitch Cord Key Exposure
Pic Stitch Cord Key Exposure
Source: Symantec

They also discovered credentials for several popular apps listed in Apple’s App Store.

  1. crumble – 3.9 million+ ratings – Amazon hardcoded credentials
  2. Eureka: Make Money with Surveys – 402.1K+ Rating – Amazon Hardcoded Credentials
  3. Videoshop – Video Editor – 357.9K+ Ratings – Amazon Hardcoded Credentials
  4. Solitaire Clash: Earn Real Cash – 244.8K+ Ratings – Amazon Hardcoded Credentials
  5. Zap Surveys – Make Money Easy – 235,000+ ratings – Amazon Hardcoded Credentials
AWS credentials for Crumbl's codebase
AWS credentials for Crumbl’s codebase
Source: Symantec

The App Store does not report download numbers, but those numbers are usually much higher than the number of ratings listed.

Note that Google displays the total number of downloads over an app’s lifetime in the Play Store, and does not reflect active installs.

The presence of the above-mentioned apps on your phone does not mean that your personal data has been stolen, but unless the developer takes action and eliminates the risk, your personal data can be accessed and hackers can steal your data. This means that there is a possibility that it may be extracted.

In September 2022, Symantec sounded the alarm about this risk, saying its researchers discovered more than 1,800 iOS and Android apps containing AWS credentials, and 77% of those apps had valid access tokens in their codebase. I emphasized that.

Researchers recommend that developers follow best practices for protecting sensitive information in mobile apps.

This includes using environment variables to store credentials, using secret management tools (AWS Secrets Manager, Azure Key Vault, etc.), data encryption, regular code reviews and audits, and sensitive data. and integrating automated security scanning early in the development process to detect security issues. .



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Muse Dash, Hyperforma, Tower of Fortune 4, etc.

March 28, 2025

New Android spyware warning – don’t install these apps

October 31, 2024

Google Apps Finally Adds Material 3 Bottom Bar to Android

October 31, 2024
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Will Google’s new anti-theft feature be a game-changer for Android users?

October 13, 2024

Huawei’s Android replacement HarmonyOS Next launches next week, permanently discontinuing Google’s operating system on existing devices

October 11, 2024

Android 15 lets you turn your phone into a useful smart home dashboard – here’s how

October 11, 2024

Google ordered to open Android app store to competition

October 10, 2024
Top Reviews
Wtf Android
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 wtfandroid. Designed by wtfandroid.

Type above and press Enter to search. Press Esc to cancel.