Mobile Payment Magazine

Featured

Consumers and Mobile Financial Services – Free Report

Mobile phones have increasingly become tools that consumers use for banking, payments, budgeting, and shopping. Given the rapid pace of developments in the area of mobile finance, the Federal Reserve Board began conducting annual surveys of consumers’ use of mobile financial services in 2011. This 78-page report, “Consumers and Mobile Financial Services” (March, 2015) examines trends in the adoption and use of mobile banking, payments, and shopping behavior and how the emergence of mobile financial services affects consumers’ interaction with financial institutions.

  • The Basics
  • News
  • Research
  • Events
  • Company Profiles
You are here: Home / Research / Many Mobile Banking App’s Not Secure, Says viaForensics

Many Mobile Banking App’s Not Secure, Says viaForensics

November 10, 2010 by Mobile Payment Magazine

On the heels of the news of PayPal’s vulnerable iPhone application, The Wall Street Journal broke news of additional vulnerabilities in other major financial institutions’ smart phone applications. These security flaws were uncovered by computer and mobile forensics firm, viaForensics, who tested smart phone applications from Bank Of America, Chase, TD Ameritrade, USAA, Wells Fargo and Vanguard, in addition to PayPal.

viaForensics has been communicating and coordinating with the financial institutions to address the flaws. Most of the institutions were able to quickly resolve the issues and release new versions of their applications.

According to American Banker 25% of the mobile banking programs analyzed received a poor rating: ” In most cases, these failures occurred because testers were able to recover a user password or other sensitive user data from a user’s mobile device. In some cases, the apps cached a security PIN or a user name and password. In other instances testers were able to recover payment history, partial credit card numbers and other transaction-related data. About a third (31%) of mobile banking apps received a “Warn” grade because a user name or app data was present, but not considered a significant risk to the user. The remaining 44% of mobile banking apps passed the test.”

viaForensics has retested the applications and released the results through appWatchdog, a free service which tests publicly available mobile applications for insecure transmissions or storage of sensitive user data. The service measures such factors as how securely the app handles user names and passwords. If not handled properly, security lapses can place the user at risk for data and financial theft. A deeper audit is offered through appSecure, which provides sophisticated security testing and recommendations for securing the app.

Sources: viaForensics, American Banker

Related

Filed Under: Research Tagged With: Bank of America, Chase, MobileBanking, PayPal, Security, TD Ameritrade, USAA, Vanguard, viaForensics, Wells Fargo

STAY INFORMED

Twitter: MobilePmnt

Tags

American Express android Apple Apple Pay AT&T Bank of America boku China Facebook Gemalto google Google Wallet Intuit iPhone Isis MasterCard mFoundry Microsoft mobile banking mobile commerce mobile conferences mobile conferences 2011 MobilePayment Mobile Payment Research 2015 MobilePayments mobile wallet NFC Nokia Obopay Orange PayPal Research and Markets Samsung SMS Sprint Square Starbucks T-Mobile Unbanked VeriFone Verizon Visa Vodafone Wells Fargo Zong

News

Visa “Tap to Phone” Adoption Grows Rapidly

Today, Visa announced that Tap to Phone has experienced a 200% increase over the past year.

Is Your Business PCI Compliant?

A simple guide answering some frequently asked questions as well as debunking a couple myths about PCI compliance.

Nets and Oberthur Technologies Offer Mobile Payments to Scandinavian Banks

Nets, a payments service provider in Northern Europe, and OT (Oberthur Technologies), a global provider of embedded security software products, services and solutions, are partnering to service banks with a financial platform to support future international mobile payment means in the Nordics.

Kohl’s to Launch Mobile Payments

Kohl’s (NYSE: KSS) announced today the nationwide launch of Kohl’s Pay, a mobile payment option which integrates the Kohl’s Charge private label credit card into Kohl’s mobile app. Kohl’s Pay allows more than 25 million active card holders across the country to pay for their in-store purchases with their Kohl’s Charge card directly from their mobile device. Kohl’s Pay also its customers to apply their Kohl’s offers, Kohl’s Cash and Yes2You Rewards with a single transaction right from the mobile device at checkout.

Apple in Talks with Banks to Develop Mobile Person-to-Person Payment Service – Update – NASDAQ.com

Apple Inc. is in discussions with U.S. banks to develop a mobile person-to-person payment service that would compete with PayPal Inc.’s popular Venmo platform, according to people familiar with the talks. The talks are ongoing, and it is unclear if any of the banks have struck an agreement with Apple, these people said. Key details […]

  • Home
  • About Us
  • Copyright & Terms
  • Contact