{"id":2852,"date":"2020-05-13T22:23:38","date_gmt":"2020-05-13T22:23:38","guid":{"rendered":"https:\/\/www.affinite.fr\/index.php\/2020\/05\/13\/des-milliers-dapplis-android-laissent-fuiter-des-donnees-dutilisateurs\/"},"modified":"2020-05-13T22:23:38","modified_gmt":"2020-05-13T22:23:38","slug":"des-milliers-dapplis-android-laissent-fuiter-des-donnees-dutilisateurs","status":"publish","type":"post","link":"http:\/\/www.affinite.fr\/index.php\/2020\/05\/13\/des-milliers-dapplis-android-laissent-fuiter-des-donnees-dutilisateurs\/","title":{"rendered":"Des milliers d\u2019applis Android laissent fuiter des donn\u00e9es d\u2019utilisateurs"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/img.bfmtv.com\/i\/0\/0\/f38\/293442d16e9d1b3a956a4a285ce74.jpg\" \/><\/p>\n<div itemprop=\"articleBody\">\n<p>Selon les chercheurs en s\u00e9curit\u00e9 de Comparitech, beaucoup de d\u00e9veloppeurs d\u2019applis Android s\u2019appuient sur la plate-forme de d\u00e9veloppement Firebase sans toutefois ma\u00eetriser les configurations des bases de donn\u00e9es sous-jacentes. Apr\u00e8s avoir analys\u00e9 515\u00a0735\u00a0applis Android sur Google Play, ils ont identifi\u00e9 4\u00a0282\u00a0applis dont les bases de donn\u00e9es Firebase \u00e9taient en libre acc\u00e8s. Il s\u2019agit principalement d\u2019applications de jeux et d\u2019\u00e9ducation.<\/p>\n<h3 style=\"color:#333; font-family:arial,helvetica,sans-serif; font-size:23px; font-weight:700\">4 milliards d&rsquo;installations<\/h3>\n<p>Cette fuite de donn\u00e9es porte sur\u00a0des millions d\u2019adresses e-mail, de noms d\u2019utilisateur, de mots de passe, de num\u00e9ros de t\u00e9l\u00e9phone, etc. M\u00eame des num\u00e9ros de cartes bancaires sont accessibles par cet interm\u00e9diaire. Ces 4\u00a0282\u00a0applications repr\u00e9sentent plus de 4\u00a0milliards d\u2019installations, ce qui permet d\u2019appr\u00e9cier l\u2019\u00e9tendue du d\u00e9sastre. Et la r\u00e9alit\u00e9 est sans doute pire. En extrapolant sur l\u2019ensemble du catalogue de Google Play, les chercheurs estiment qu\u2019environ 24\u00a0000\u00a0applications Android seraient vuln\u00e9rables de la m\u00eame mani\u00e8re, soit cinq fois plus.<\/p>\n<aside class=\"bg-color-0 padding-inside-all-s bloc border-s\">\n<h4 class=\"box-txt-normal\">\n<p><b>A d\u00e9couvrir aussi en vid\u00e9o<\/b><\/p>\n<\/h4>\n<\/aside>\n<p>Les fuites d\u2019informations ne constituent pas le seul risque. Parmi les applications analys\u00e9es, plus de 9\u00a0000 donnaient un acc\u00e8s libre en \u00e9criture aux bases de donn\u00e9es. Des pirates pourraient donc injecter des donn\u00e9es pour, par exemple, diffuser de fausses informations, ins\u00e9rer un malware ou \u00e9laborer des attaques de phishing. Alert\u00e9 par Comparitech, Google a promis qu\u2019il allait contacter les d\u00e9veloppeurs de toutes ces applications vuln\u00e9rables. Esp\u00e9rons que les auteurs corrigeront ces erreurs.<\/p>\n<p><strong>Source\u00a0<\/strong>: <a href=\"https:\/\/www.comparitech.com\/blog\/information-security\/firebase-misconfiguration-report\/#What_data_is_exposed\" target=\"_blank\" rel=\"noopener noreferrer\">Comparitech<\/a><\/p>\n<\/p><\/div>\n<p><script>\n         !function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function()\n         {n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)}\n         ;if(!f._fbq)f._fbq=n;\n             n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0;\n             t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window,\n                 document,'script','https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n         fbq('init', '1065890633454496');\n         fbq('track', 'PageView');\n     <\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.01net.com\/actualites\/des-milliers-d-applis-android-laissent-fuiter-des-donnees-d-utilisateurs-1913216.html\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] Selon les chercheurs en s\u00e9curit\u00e9 de Comparitech, beaucoup de d\u00e9veloppeurs d\u2019applis Android s\u2019appuient sur la plate-forme de d\u00e9veloppement Firebase &hellip; <a href=\"http:\/\/www.affinite.fr\/index.php\/2020\/05\/13\/des-milliers-dapplis-android-laissent-fuiter-des-donnees-dutilisateurs\/\" class=\"more-link\">Plus <span class=\"screen-reader-text\">Des milliers d\u2019applis Android laissent fuiter des donn\u00e9es d\u2019utilisateurs<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":2853,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-2852","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tous"],"_links":{"self":[{"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/posts\/2852"}],"collection":[{"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/comments?post=2852"}],"version-history":[{"count":0,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/posts\/2852\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/media\/2853"}],"wp:attachment":[{"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/media?parent=2852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/categories?post=2852"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.affinite.fr\/index.php\/wp-json\/wp\/v2\/tags?post=2852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}