{"id":7801,"date":"2015-02-12T10:16:11","date_gmt":"2015-02-12T02:16:11","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=7801"},"modified":"2015-02-12T10:24:02","modified_gmt":"2015-02-12T02:24:02","slug":"steps-protect-dating-app-hacks","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2015\/02\/12\/steps-protect-dating-app-hacks\/","title":{"rendered":"Steps to protect against dating app hacks"},"content":{"rendered":"<p>Over 60 percent of leading dating mobile apps studied, on the Android mobile platform, are potentially vulnerable to a variety of cyber-attacks that put personal user information and corporate data at risk, finds an analysis conducted by IBM Security.<\/p>\n<p>The IBM study reveals that many of these dating applications have access to additional features on mobile devices such as the camera, microphone, storage, GPS location and mobile wallet billing information, which in combination with the vulnerabilities may make them exploitable to hackers.<\/p>\n<p>IBM also found that nearly 50 percent of organizations have at least one of these employee-installed popular dating apps on mobile devices used to access confidential business information.<\/p>\n<p>In today\u2019s connected culture, dating apps are a common and convenient way for singles of all ages to meet new love interests. In fact, a Pew Research study revealed one in 10 Americans have used a dating site or app and the number of people who dated someone they met online grew to 66 percent over the past eight years.<\/p>\n<p>\u201cMany consumers use and trust their mobile phones for a variety of applications. It is this trust that gives hackers the opportunity to exploit vulnerabilities like the ones we found in these dating apps,\u201d said Caleb Barlow, Vice President, IBM Security. \u201cConsumers need to be careful not to reveal too much personal information on these sites as they look to build a relationship with another user on these dating apps. Our research demonstrates that some users may be engaged in a dangerous tradeoff \u2013 with increased accessibility resulting in decreased personal security and privacy.\u201d<\/p>\n<p>Security researchers from IBM Security identified that 26 of the 41 dating apps they analyzed on the Android mobile platform had either medium or high severity vulnerabilities. The analysis was done based on apps available in the Google Play app store in October 2014.<\/p>\n<p>The vulnerabilities discovered by IBM Security make it possible for a hacker to gather valuable personal information about a user. While some apps have privacy measures in place, IBM found many are vulnerable to attacks that could lead to the following scenarios:<\/p>\n<p>\u00b7 Dating App Used for Malware: The anticipation of receiving interest from a potential new date is just the sort of moment, when users let their guard down, that hackers thrive on. Some of the vulnerable apps could be reprogrammed by hackers to send what seems like a message that asks users to click for an update or to retrieve a message that, in reality, is just a ploy to download malware onto their device.<\/p>\n<p>\u00b7 GPS Information Used to Track Movements: IBM found 73% of the 41 popular dating apps analyzed have access to current and past GPS location information. Hackers can capture a user\u2019s current and past GPS location information to find out where a user lives, works, or spends most of their time.<\/p>\n<p>\u00b7 Steal Credit Card Numbers From App: 48% of the 41 popular dating apps analyzed have access to a user\u2019s billing information saved on their device. Through poor coding, an attacker could gain access to billing information saved on the device\u2019s mobile wallet through a vulnerability in the dating app and steal the information to make unauthorized purchases.<\/p>\n<p>\u00b7 Take Control of a Phone\u2019s Camera or Microphone: All vulnerabilities identified can allow a hacker to gain access to a phone\u2019s camera or microphone even if the user is not logged into the app. This means, an attacker can spy and eavesdrop on users or tap into confidential business meetings.<\/p>\n<p>\u00b7 Hacker Can Hijack Your Dating Profile: A hacker can change content and images on the dating profile, impersonate the user and communicate with other app users, or leak personal information externally to affect the reputation of a user\u2019s identity. This poses a risk to other users, as well, since a hijacked account can be used by an attacker to trick other users into sharing personal and potentially compromising information.<\/p>\n<p>Some of the specific vulnerabilities identified on the at-risk dating apps include cross site scripting via man in the middle, debug flag enabled, weak random number generator and phishing via man in the middle. When these vulnerabilities are exploited an attacker can potentially use the mobile device to conduct attacks.<\/p>\n<p>For example, hackers could intercept cookies from the app via a Wi-Fi connection or rogue access point, and then tap into other device features such as the camera, GPS, and microphone that the app has permission to access. They also could create a fake login screen via the dating app to capture the user\u2019s credentials, so when they try to log into a website, the information is also shared with the attacker<\/p>\n<p><strong>Steps to protect against dating app hacks<\/strong><\/p>\n<p>While IBM discovered a number of vulnerabilities in over 60 percent of popular Android dating apps, both consumers and businesses can take steps to protect themselves against potential threats.<\/p>\n<p>What can consumers do?<\/p>\n<p>\u00b7\u00a0 Be Mysterious: Don&#8217;t divulge too much personal information on these sites such as where you work, birthday or social media profiles until you&#8217;re comfortable with the person you are engaging with via the app.<\/p>\n<p>\u00b7\u00a0 Permission Fitness: Figure out if you want to use an app by checking the permissions it asks for by viewing the settings on your mobile device. When updating, apps often automatically reset the permissions determining what phone features they have access to, like your address book or GPS data.<\/p>\n<p>\u00b7 Keep it Unique: Use unique passwords for every online account you have. If you use the same password for all your accounts it can leave you open to multiple attacks if one account is compromised.<\/p>\n<p>\u00b7 Punctual Patching: Always apply the latest patches and updates to your apps and your device when they become available. This will fix any identified bugs in your device and applications, resulting in a more secure experience.<\/p>\n<p>\u00b7 Trusted Connections: Use only trusted Wi-Fi connections when on your dating app. Hackers love using fake Wi-Fi access points that directly connect you to their device instead to execute these types of attacks. Many of the vulnerabilities found in this research can be exploited via Wi-Fi.<\/p>\n<p><strong>What can enterprises do?<\/strong><\/p>\n<p>Businesses also need to be prepared to protect themselves from vulnerable dating apps active inside their infrastructure. IBM found that nearly 50 organizations, sampled for this research, have at least one popular dating app installed on either both corporate-owned and Bring Your Own Devices (BYOD). To protect confidential corporate assets, businesses should:<\/p>\n<p>\u00b7 Adopt the Right Protection: Leverage Enterprise Mobility Management (EMM) offerings with mobile threat management (MTM) capabilities to enable employees to utilize their own devices while still maintaining the security of the organization.<\/p>\n<p>\u00b7 Define Downloadable Apps: Allow employees to only download applications from authorized app stores such as Google Play, iTunes, and the corporate app store.<\/p>\n<p>\u00b7 Education is Key: Educate employees to know the dangers of downloading third party applications and what it means when they grant that app specific device permissions.<\/p>\n<p>\u00b7 Immediately Communicate Potential Threats: Set automated policies on smartphones and tablets, which take immediate action if a device is found compromised or malicious apps are discovered. This enables protection to corporate resources while the issue is remediated.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over 60 percent of leading dating mobile apps studied, on the Android mobile platform, are potentially vulnerable to a variety of cyber-attacks that put personal user information and corporate data at risk, finds an analysis conducted by IBM Security. The IBM study reveals that many of these dating applications have access to additional features on [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":6725,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,19],"tags":[598,2552,214,103],"class_list":["post-7801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apps","category-headlines","tag-byod","tag-hacks","tag-ibm","tag-malware"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/7801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=7801"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/7801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/6725"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=7801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=7801"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=7801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}