Researchers identify banking app flaw

Mobile app users could start feeling a little more secure in future. A  team fromthe University of Birmingham have developed a tool to perform semi-automated security testing of these apps.

In particular, the tool can identify critical vulnerabilities in banking apps – the researchers identified issues in HSBC, NatWest,  and the Co-op bank apps.

This allowed attackers, connected to the same network as the victims (eg on a public WiFi or corporate), to perform a so-called “Man in the Middle Attack” and retrieve credentials such as usernames and passwords/pin codes.

 Although banks had expended a great deal of effort in maintaining stringent security, a technology called certificate pinning was proving to be vulnerable. The Birmingham tests found that apps from major global banks contained this flaw, which if exploited, could have enabled an attacker to decrypt, view and modify network traffic from users of the app. An attacker with this capability could thereby perform any operation which is normally possible on the app.

This wasn’t the only vulnerability identified. The researchers also found in-app phishing attacks against Santander and Allied Irish bank. These  would have let an attacker take over part of the screen to phish for the victim’s login credentials.  

Fixing the flaw

The researchers worked with the banks involved, and the UK government's National Cyber Security Centre to fix all the vulnerabilities, and the current versions of all the apps affected by this pinning vulnerability are now secure.

The research was carried out by Dr Tom Chothia, Dr Flavio Garcia and PhD candidate Chris McMahon Stone, all members of the Security and Privacy Group at the University of Birmingham

 Dr Tom Chothia said, “In general the security of the apps we examined was very good, the vulnerabilities we found were hard to detect, and we could only find so many weaknesses due to the new tool we developed” he added “It’s impossible to tell if these vulnerabilities were exploited but if they were attackers could have got access to the banking app of anyone connected to a compromised network”.

 

 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)