The Members Forum

Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Citi Discloses Security Flaw in Its iPhone Mobile Banking App


Administrator / Manager

Status: Offline
Posts: 2499
Date:
Citi Discloses Security Flaw in Its iPhone Mobile Banking App
Permalink   


Citigroup Inc. told its U.S. mobile banking customers they should upgrade to a new application designed for Apple Inc.'s iPhone after the bank's original version was found to have a security flaw.

In an incident that highlights the growing security challenges around wireless apps, Citi said its iPhone app accidentally saved personal account information in a hidden file on users' iPhones. Information that may have been stored includes their account numbers, bill payments and security access codes.

The information may also have been saved to a user's computer if they synced their iPhone with a PC.

It wasn't immediately clear whether the information was stored in an area that could have been accessed by a hacker, but Citi said it doesn't believe the data was breached and said its new app corrects the problem.

"We have no reason to believe that our customers' personal information has been accessed or used inappropriately by anyone," Citi said. An Apple spokeswoman didn't immediately reply to a request for comment.

Security experts worry about "leakage" when confidential data gets logged by wireless apps. Citi said its new application, released July 19, deletes any information that may have been saved to a user's iPhone or computer.

 

Citi said the problem was discovered in a routine security review. Citi notified customers of the problem in a letter dated July 20. Other Citi iPhone apps such as the app for credit card customers weren't affected, said Citi in a statement.

Citi launched the iPhone app in March 2009 in conjunction with mobile financial services provider mFoundry. MFoundry, a private company based in Larkspur, Calif., didn't respond to a request for comment.

The WSJ has the details HERE!



__________________

http://www.mycomputerplayground.com
http://www.digitaldrama.net
http://www.thisrules.net


Administrator / Manager

Status: Offline
Posts: 2410
Date:
Permalink   

Got this 'heads-up' from our bank.
Ya gotta be very cautious these days!



__________________

Vindicated th_Worm.gif

Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard