Thousands of apps found with hardcoded API creds

By
Follow google news

Leaking secrets for popular services.

Sloppy developers are creating security risks by hardcoding in credentials for application programming interface (API) access to popular services in thousands of apps, researchers have found.

Thousands of apps found with hardcoded API creds

Security vendor Fallible scanned around 16,000 apps on Google Play for API keys and secrets to assess how safe they were. It discovered that some 2500 had either the key or secret providing access to a third-party service hardcoded into them.

Fallible said some keys were harmless and necessary, but found another 304 API secrets that should not have been in apps.

Among the services that apps leaked secrets for were Twitter, Uber, Flickr, Wechat, Dropbox, Instagram and Slack. 

Ten apps had the secrets to Amazon Web Services hardcoded into them. Some had full administrator privilege on AWS, and could create and delete cloud instances.

In the case of Uber, the secret Fallible found could be used to send bogus in-app notifications via the ride-sharing company's API.

Fallible warned developers to think twice about whether or not they actually needed to hardcode API credentials into their apps. The researchers also advised developers to understand how the API is used, and the scope of the access rights the credentials provide for third-party services.

Third-party service providers should also clearly warn and instruct developers not to put secrets in apps, and create multiple API credentials with different scopes if required to limit security risks, the researchers said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

Researchers uncover 'Darksword' iPhone spyware

Researchers uncover 'Darksword' iPhone spyware

Stryker contains cyber attack on its Microsoft environment

Stryker contains cyber attack on its Microsoft environment

Exploited Google Chrome zero-days added to US must-patch list

Exploited Google Chrome zero-days added to US must-patch list

Log In

  |  Forgot your password?