False Sense of Security: A Study on the Effectivity of Jailbreak Detection in Banking Apps

被引:11
作者
Kellner, Ansgar [1 ]
Horlboge, Micha [1 ]
Rieck, Konrad [1 ]
Wressnegger, Christian [1 ]
机构
[1] TU Braunschweig, Inst Syst Secur, Braunschweig, Germany
来源
2019 4TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P) | 2019年
关键词
D O I
10.1109/EuroSP.2019.00011
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
People increasingly rely on mobile devices for banking transactions or two-factor authentication (2FA) and thus trust in the security provided by the underlying operating system. Simultaneously, jailbreaks gain tremendous popularity among regular users for customizing their devices. In this paper, we show that both do not go well together: Jailbreaks remove vital security mechanisms, which are necessary to ensure a trusted environment that allows to protect sensitive data, such as login credentials and transaction numbers (TANs). We find that all but one banking app, available in the iOS App Store, can be fully compromised by trivial means without reverse-engineering, manipulating the app, or other sophisticated attacks. Even worse, 44 % of the banking apps do not even try to detect jailbreaks, revealing the prevalent, errant trust in the operating system's security. This study assesses the current state of security of banking apps and pleads for more advanced defensive measures for protecting user data.
引用
收藏
页码:1 / 14
页数:14
相关论文
共 80 条
[1]  
Abadi Martin, 2005, P 12 ACM C COMPUTER, P340
[2]  
[Anonymous], 2013, P ACM C DAT APPL SEC
[3]  
[Anonymous], 2018, IPHONE WIK
[4]  
[Anonymous], 2014, P NETW DISTR SYST SE
[5]  
[Anonymous], 2018, TSPROT 8 IOS 8
[6]  
[Anonymous], 2017, IEEE T DEPENDABLE SE
[7]  
[Anonymous], 2011, PIOS DETECTING PRIVA
[8]  
Apple Inc, 2018, FDN APPL DEV DOC
[9]  
Apple Inc, 2004, DYLD CPP
[10]  
Apple Inc, 2018, APP STOR REV GUID