首页> 外文会议>IEEE European Symposium on Security and Privacy >False Sense of Security: A Study on the Effectivity of Jailbreak Detection in Banking Apps
【24h】

False Sense of Security: A Study on the Effectivity of Jailbreak Detection in Banking Apps

机译:错误的安全感:银行应用中越狱检测的有效性研究

获取原文

摘要

People increasingly rely on mobile devices for banking transactions or two-factor authentication (2FA) and thus trust in the security provided by the underlying operating system. Simultaneously, jailbreaks gain tremendous popularity among regular users for customizing their devices. In this paper, we show that both do not go well together: Jailbreaks remove vital security mechanisms, which are necessary to ensure a trusted environment that allows to protect sensitive data, such as login credentials and transaction numbers (TANs). We find that all but one banking app, available in the iOS App Store, can be fully compromised by trivial means without reverse-engineering, manipulating the app, or other sophisticated attacks. Even worse, 44% of the banking apps do not even try to detect jailbreaks, revealing the prevalent, errant trust in the operating system's security. This study assesses the current state of security of banking apps and pleads for more advanced defensive measures for protecting user data.
机译:人们越来越依赖于移动设备来进行银行交易或两因素身份验证(2FA),因此信任底层操作系统提供的安全性。同时,越狱由于其定制设备而在普通用户中获得了极大的欢迎。在本文中,我们展示了两者不能很好地结合在一起:越狱删除了重要的安全机制,这对于确保可信任的环境可以保护敏感数据(例如登录凭据和交易号(TAN))是必不可少的。我们发现,iOS应用程序商店中除了一个银行应用程序之外的所有应用程序都可以通过微不足道的方式完全受损,而无需进行反向工程,操纵该应用程序或其他复杂的攻击。更糟糕的是,有44%的银行应用程序甚至没有尝试检测越狱,从而显示出对操作系统安全性的普遍,错误的信任。这项研究评估了银行应用程序的当前安全状态,并提出了用于保护用户数据的更高级防御措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号