Digital Media Net - Your Gateway To Digital media Creation. News and information on Digital Video, VR, Animation, Visual Effects, Mac Based media. Post Production, CAD, Sound and Music

95% of Fintech Apps Across Africa Immediately Expose Valuable, Exploitable Secrets

Approov-sponsored survey of 224 Android apps finds exposed secrets that can be used to reveal personal and financial data


PALO ALTO, Calif.–(BUSINESS WIRE)–#AfricaApproov, the end-to-end mobile security provider, released a report today showing that 95 percent of the most popular African banking and financial services apps contain easy-to-extract secrets, which could be used in scripts and bots to attack application programming interfaces (APIs) and steal data, devastating consumers and the institutions they trust.

This report describes research by a team from the CyLab-Africa and Upanzi Open Digital Technologies Network initiatives in August 2023, sponsored by Approov: 224 financial Android applications were selected from countries in North, Central, Eastern, Western and Southern Africa and were downloaded and investigated.

CyLab-Africa, located in Kigali, Rwanda, is a collaboration between Carnegie Mellon University’s CyLab Security and Privacy Institute and Carnegie Mellon University Africa. Upanzi is an Africa-based network of research labs that focuses on creating, testing, innovating and assisting in implementing digital technologies at scale, such as identity, payments, cybersecurity, cloud computing, data governance, artificial intelligence and machine learning, and influencing technology policy recommendations to support the digital transformation of low- and middle-income countries (LMICs).

The study draws comparisons between other regions and Africa, pinpointing trends, commonalities, and disparities pertaining to the exposure of secret keys in a mobile application’s binary package.

“This research clearly shows that as financial services become more digitized and accessible through mobile platforms across the world, the potential risks associated with the exposure of confidential information have escalated,” says Ted Miracco, CEO of Approov. “Developers can no longer depend on ‘official’ app stores or on native client OS security and must ensure that end-to-end security is built into the app itself.”

Notably, 18% of the apps investigated revealed high severity secrets. A high severity classification was used for vulnerabilities that could potentially lead to unauthorized access, data breaches, and compromised user privacy. These apps together constitute a total of 272 million downloads across the continent with 72% of the apps revealing medium severity secrets that encompass sensitive data. If exposed, they could potentially compromise the confidentiality of user data and application functionality.

“In order to improve financial inclusion in Africa, big improvements need to be made to the security and resilience of financial technologies and infrastructure across the continent,” remarks Assane Gueye, associate teaching professor at CMU-Africa and co-director of CyLab-Africa and the Upanzi Network. “A comprehensive survey like this one can help us to better understand the vulnerabilities that exist in order to inform policymakers, developers, and security professionals.”

The keys found in the reverse engineered Android Application Packages (APKs) include:

  • encryption keys for securing sensitive data
  • authentication keys for accessing services
  • signing keys for verifying data authenticity
  • database credentials
  • OAuth client secrets
  • push notification keys
  • code push keys
  • payment gateway secrets
  • encryption initialization vectors
  • license keys
  • sensitive configuration setting

Key findings:

  • 95% of fintech apps across Africa immediately expose valuable, exploitable secrets.
  • Approximately 272 million users have downloaded apps that inadvertently reveal sensitive, high-risk secret keys.
  • Crypto was the most exposed type of app, with 33% of crypto apps found to expose high severity secrets.
  • Apps deployed in West Africa were the most exposed in terms of high severity secret exposure and Southern Africa the least: 20% of apps in West Africa exposed such secrets versus only 6% in Southern Africa.
  • Google Cloud API keys were identified in 86% of the examined applications. Such exposure can lead directly to accounts being compromised.
  • Approximately 15.3% of the apps exposed various authentication tokens, including Facebook authentication tokens.

The full report can be downloaded from the Approov website (https://approov.io/info/security-challenges-of-financial-mobile-apps-in-africa)

About Approov

Approov is considered a cornerstone of mobile application security for leading global organizations whose consumer and B2B applications are used by millions annually, including eCommerce, financial services, healthcare, connected cars and retail sector organizations.

Approov provides a comprehensive runtime security solution (RASP) for mobile apps and their APIs, unified across iOS and Android. Mobile apps have become a critical element for every business and unfortunately can expose organizations to breaches, fraud, denial of service, and other forms of API abuse. Approov immediately stops any automated tools or compromised apps from manipulating any part of the end-to-end mobile platform, turning away unauthorized access attempts by scripts, bots and fake or tampered apps.

By eliminating false positives and providing runtime application self-protection (RASP) as well as just-in-time-management of API keys, secrets and certificates, Approov delivers both exceptional operational convenience and highly robust security at scale.

Engage with Approov:

Website: https://www.approov.io/
Linkedin: https://www.linkedin.com/company/136990/
Twitter: @approov_io

Contacts

Media Contact (Approov):
Dan Chmielewski

Madison Alexander PR, Inc.

+1 949-231-2965

dchm@madisonalexanderpr.com

Staff

Recent Posts

Gopuff Invites the World to “Bring The Magic” to Everyday Experiences with the Launch of Its Largest-Ever Brand Campaign

The imaginative, 360° campaign designed to capture the magic of the Gopuff experience debuts during…

3 days ago

Metals Acquisition Limited Provides Notice of Release of First Quarter 2024 Results and Conference Call Details

ST. HELIER, Jersey--(BUSINESS WIRE)--Metals Acquisition Limited ARBN 671 963 198 (NYSE: MTAL; ASX: MAC), a…

3 days ago

New UFC FIGHT CARD RUMMY to Feature Live Tournament, Fan Favorite UFC Athletes and More

UFC Partners With Magmic and Skillz on Launch/Kicks Off a 2-week Live Tournament April 19th…

3 days ago

Vaunt Marks First Cash-Positive Month, With Rapid Growth Highlighting Success in Tackling Empty-leg Flights

 - Launched in Q4 2023, Vaunt has reached $500K in annual recurring revenue, and 25,000+…

3 days ago

Nex and Hasbro Expand Collaboration to Transform Beloved Family Board Games Into Active Play Experiences

Three New Games Based on Classic Hasbro Titles Are Set to Launch Exclusively on Nex…

3 days ago

Franklin Templeton Announces Availability of Peer-to-Peer Transfers for Franklin OnChain U.S. Government Money Fund

The first U.S.-registered mutual fund to process transactions and record share ownership on a public…

3 days ago