178 mln phones at security risk in Middle East, Africa: report

Image
Press Trust of India Dubai
Last Updated : Aug 20 2014 | 2:05 PM IST
Over 94 per cent of popular Android applications used in the Middle East and Africa are potentially vulnerable, according to a report.
Enterprise security player Palo Alto Networks says Android Internal Storage is a protected area that Android- based applications use to store private information, including user names and passwords.
According to Palo Alto Networks research, an attacker may be able to steal sensitive information from most of the applications on an Android device using the Android Debug Bridge (ADB) backup/restore function.
In addition, most of the security enhancements added by Google to prevent this type of attack can be bypassed.
In the Middle East & Africa, Android has the largest market share of all platforms, at 40 per cent.
Anyone using a device running version 4.0 of Android - about 85 per cent of Android systems in use today in the Middle East - is potentially vulnerable.
Of the estimated 525.8 million mobile phone owners is the Middle East and Africa, this equates to over 178 million phones at risk in the Middle East and Africa, the report said.
Over 94 per cent of popular Android applications, including pre-installed email and browser applications, use the backup system, meaning users are vulnerable.
Many Android applications will store user passwords in plain text in Android Internal Storage, meaning almost all popular e-mail clients, FTP clients and SSH client applications are vulnerable.
"We encourage users to be aware and Google to take a closer look at this storage weakness in Android. Given Android's place as the region's most popular mobile operating system, millions of users are potentially at risk here in the Middle East and Africa," said Saeed Agha, GeneralManager, Middle East, Palo Alto Networks.
Palo Alto Networks recommends Android users disable USB debugging when not needed, and application developers to protect Android users by setting android:allowBackup to false in each Android application's AndroidManifest.Xml file or restricting backups from including sensitive information using a BackupAgent.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Aug 20 2014 | 2:05 PM IST

Next Story