Skip to main content

ViaForensics: 10 pct of iOS, Android apps store clear text passwords

ViaForensis app data (Aug 2011)
Image used with permission by copyright holder

Almost everyone with a smartphone knows there’s some risk to carrying around apps that handle passwords, email, photos, personal info, and access to financial information on a device that you can easily leave unattended on a desk or sitting on a counter in a coffee shop. But just how many apps put users at risk? According to Chicago-based digital forensics company ViaForensics, a lot: their new Mobile App Security study finds that a full 10 percent of Android and iOS apps tested store passwords as clear text, completely unprotected if anyone should get ahold of a device. Furthermore, some 76 percent of apps tested store usernames in plain text—and while usernames might not seem terribly important to secure, sometimes they’re just the info a criminal or stalker needs to get to more-important info.

“Based on the results of this study, there is a serious potential threat for identity or financial theft if a lost smartphone should fall into the wrong hands,” ViaForensics wrote. “For instance, if a cybercriminal is able to steal one password, coupled with all of the usernames recovered, would pose a serious threat for someone who uses the same password on many accounts.”

ViaForensics rated apps on a three-stage Pass-Warn-Fail system. A “Pass” rating meant that the company couldn’t find sensitive data it was looking for, or if the data was successfully encrypted. ViaForensics gate an app a “Warn” rating if they were able to uncover data but didn’t believe the exposed information put the user at significant risk, while a “Fail” rating meant ViaForensics was able to pull information like passwords and accounts numbers.

Of the 100 apps tested, 39 received a failing grade. Some 44 apps rated a warning, and only 17 got a “pass” rating.

Broken down by category, some 32 financial applications faired relatively well, with 14 passing and 10 receiving a warning: that means eight failed, including Mint for iPhone and Android, along with Wikiinvest and Square for the iPhone. Social networking apps, however, failed miserably, with none receiving a passing mark and a stunning 14 out of 19 failing. Retail apps also faired badly: of 14 apps tested, none passed, 12 for a warning, and 2 failed.

Overall, ViaForensics noted Apple made significant headway with iOS security with iOS 4.0, but notes that iOS users can’t afford to sit back and ignore potential risks from apps.

ViaForensics’ ratings for individual apps are available via their appWatchdog site.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
How to find your phone number on iPhone or Android
Someone holding up an iPhone 14 to their ear.

Let's face it: Most of us don't call our own phones very often. If you're like most people, this means you probably don't know your own phone number off-hand, especially if you rarely give it out to people or haven't had it for long, such as after setting up a new account or changing your number after moving to a new town.

To make things even more complicated, many modern smartphones let you set up more than one line using an eSIM, which gives you more than one number to remember.

Read more
How to turn off call forwarding on iPhone and Android
A person holding the Apple iPhone 15 Plus, showing the camera.

If you’re mysteriously missing calls on your iPhone or Android smartphone, it may be because call forwarding is activated on your line. In that case, all your incoming calls could be going somewhere else.

Call forwarding shouldn’t typically be active unless you’ve specifically turned it on, but another person or app may have done so without your knowledge. And since call forwarding is a carrier feature, it could still be enabled on a line you inherited from someone else, even if you’ve swapped their SIM card into your phone or transferred it to a new account.

Read more
An Apple insider just revealed how iOS 18’s AI features will work
An iPhone 15 Pro Max laying face-down outside, showing the Natural Titanium color.

As Apple’s Worldwide Developers Conference (WWDC) inches closer, the chatter around the company’s AI work has taken a feverish turn. In a year when smartphone and computing brands have focused solely on AI niceties, Apple has been uncharacteristically silent around the AI hype — eliciting concern about the brand missing the train.

However, a new report has given us a closer look at how Apple's AI dreams may come to fruition with its iOS 18 update later this year.
New details on Apple's AI plans

Read more