Menu
Mobile banking apps in developing nations have weak security

Mobile banking apps in developing nations have weak security

Attackers could already be using software vulnerabilities to steal money

Mobile banking apps in developing countries have a variety of software flaws that could pose risks to consumers, according to a new research paper.

Mobile banking apps in developing countries have a variety of software flaws that could pose risks to consumers, according to a new research paper.

The developing world is increasingly using mobile banking apps to move money, but new research shows those apps are often poorly coded and pose security risks.

Researchers with the University of Florida looked at dozens of apps used for mobile money systems but extensively analyzed seven that have millions of users in Brazil, India, Indonesia, Thailand, and the Philippines.

The problems they found represent a large attack surface, including SSL/TLS issues, botched cryptography, information leakage and opportunities to manipulate transactions and modify financial records.

The impact of the problems is unknown, but "it is possible that these apps are already being exploited in the wild, leaving consumers with no recourse to dispute financial transactions," according to their research paper, to be presented on Wednesday at the 24th USENIX Security Symposium in Washington, D.C.

So-called "branchless" banking systems using mobile apps have revolutionized banking in developing countries, where the poor have long suffered from difficult access to traditional banking systems, they wrote.

In some countries, branchless banking apps are used for 30 percent of some nations' GDP, relying on the near universal deployment of cellular network and mobile devices.

The apps can let people send money to others, pay their bills, check account balances and buy airtime credits.

While the convenience is unparalleled for the developing world, the research paper shows that security is often lagging. Complicating the problem is that the terms of service for many services shift the liability to customers if there's a problem, they wrote.

"Providers must not marry such vulnerable systems with a liability model that refuses to take responsibility for the technical flaws, and these realities could prevent sustained growth of branchless banking," they wrote.

One app in India called the Oxigen Wallet is vulnerable to a man-in-the-middle attack. Poor authentication and cryptography could allow an attacker to compromise an Oxigen account and conduct unauthorized transactions.

GCash, used in the Philippines, uses a static encryption key when communicating with a remote server. A user's PIN and session ID are encrypted with the key, which is public, before being sent.

"An attacker with this key can decrypt the user's PIN and session ID if the encrypted data is captured," they wrote. "This can subsequently give the attacker the ability to impersonate the user."

They also found problems with Airtel Money and MoneyOnMobile, both used in India, mPAY of Thailand, Zuum of Brazil and mCoin of Indonesia.

All of the services were notified of the vulnerabilities before the publication deadline of the research paper, they wrote.

"Most have not sent any response to our disclosures," the paper said. "We have chosen to publicly disclose these vulnerabilities in this paper out of an obligation to inform users of the risks they face in using these insecure services."

The paper was co-authored by Bradley Reaves, Nolen Scaife, Adam Bates, Patrick Traynor and Kevin R.B. Butler.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags mobile securityUSENIXUniversity of Florida

Events

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments