Other nomination
Password mining from AWS/Parse Tokens
Developers embed backend-as-a-service secret keys for Facebook Parse and Amazon AWS directly in shipped mobile and web apps instead of configuring access control lists. A scan of about 750,000 Play Store and App Store apps found thousands where decompiling the binary yields the key and hands an attacker the same full read and write access to the cloud database as the real app.
Record
- Researcher
- Jai Vijayan
- Published by
- Dark Reading
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jai Vijayan, first published at the original source. Preserved copies are kept so the citation survives its host.