Companies scramble to fix lack of encryption on mobile apps

Their mobile apps were transmitting payment card information without encryption

Several companies have moved quickly to add encryption to their mobile apps after it was discovered they failied to encrypt payment card information in transit, putting users at risk.

The apps were not using SSL/TLS (Secure Sockets Layer/Transport Layer Security), an encryption protocol that scrambles data as it's sent across the Internet, according to Wandera, a cloud and mobile security vendor.

"With so many breaches and costly data loss incidents in the news, it's hard to believe that any business would fail to take such a basic precaution as to encrypt sensitive traffic as it's transmitted to or from a website," said Michael J. Covington, senior product manager, in a video posted Wednesday.

Data breaches can be costly for companies, and how to better protect payment card information has been a big question after major breaches at retailers including Target, Home Depot and many others.

Five of the 16 companies named by Wandera in a blog post have now fixed their problems, including easyJet, Chiltern Railways, San Diego Zoo, CN Tower and Aer Lingus, a Wandera spokeswoman said Wednesday. All of the companies were notified of the issue by Wandera, which estimates they collectively serve 500,000 customers a day.

The company detected the problems while analyzing traffic flows of customers that use its mobile security app and gateway technology.

Using SSL/TLS when transmitting information such as login credentials, personal information and payment card data is considered standard practice to guard against breaches. Encrypted connections are typically signified in the browser URL bar by a padlock icon and "https."

If the data is not encrypted, someone on the same network -- such as a public Wi-Fi hotspot -- could collect the traffic and see the information in plain text.

Covington said in some cases the primary websites did use encryption, but the same services were not protected when using mobile browsers or apps.

Mobile apps often have multiple connections to backend services, and all need to be treated with the same protection, Covington said.

In January, Wandera found that the National Football League's mobile app leaked usernames and passwords due to an unencrypted API (application programming interface) call, according to an advisory. The problem was later fixed.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?