UPI en Español  |   UPI Asia  |   About UPI  |   My Account
Search:
Go

Study: Most mobile Web browsers unsafe

|
 
This graphic shows the inconsistency with which three of the major mobile browser platforms display security indicators. Credit: Georgia Tech
This graphic shows the inconsistency with which three of the major mobile browser platforms display security indicators. Credit: Georgia Tech
Published: Dec. 5, 2012 at 4:35 PM

ATLANTA, Dec. 5 (UPI) -- Smartphone Web browsers are unsafe and even cybersecurity experts can't detect when they've have landed on potentially dangerous websites, a U.S. study found.

In a critical area that informs user decisions -- the incorporation of tiny graphical indicators in a browser's URL address field -- all of the leading mobile browsers fail to meet security guidelines recommended by the World Wide Web Consortium for browser safety, researchers at the Georgia Institute of Technology reported Wednesday.

The graphic icons are called either SSL (secure sockets layer) or TLS (transport layer security) indicators and serve to alert users when their connection to the destination website is secure and the website they see is actually the site they intended to visit.

Without that graphical confirmation of a secure site, even expert users have no way to determine if the websites they visit are real or impostor sites phishing for personal data, the researchers said.

"We found vulnerabilities in all 10 of the mobile browsers we tested, which together account for more than 90 percent of the mobile browsers in use today in the United States," computer science Professor Patrick Traynor said.

"The basic question we asked was, 'Does this browser provide enough information for even an information-security expert to determine security standing?' With all 10 of the leading browsers on the market today, the answer was no."

The Web consortium has recommended how SSL indicators should be built into a browser's user interface and desktop browsers do a good job of following those recommendations, researchers said, but in mobile browsers the guidelines are followed inconsistently at best and often not at all.

"Research has shown that mobile browser users are three times more likely to access phishing sites than users of desktop browsers," Georgia Tech doctoral student Chaitrali Amrutkar said. "Is that all due to the lack of these SSL indicators? Probably not, but giving these tools a consistent and complete presence in mobile browsers would definitely help."

Recommended Stories
© 2012 United Press International, Inc. All Rights Reserved. Any reproduction, republication, redistribution and/or modification of any UPI content is expressly prohibited without UPI's prior written consent.

Order reprints
Join the conversation
Most Popular Collections
'Star Trek Into Darkness' screening NBC upfronts Met Ball 2013
'Great Gatsby' premieres in New York Spire raised on top of One WTC 2013: Celebrity break ups and divorces
Additional Technology Stories
1 of 14
The 2013 Billboard Music Awards
View Caption
Singer Miley Cyrus arrives at the 2013 Billboard Music Awards held at the MGM Grand Hotel in Las Vegas, Nevada on May 19, 2013. UPI/Jim Ruymen
fark
It doesn't make math any easier, but Barbie is trading in her Mailbu home for a more sophisticated...
Nigerian forces hunting Islamist rebels kill seventeen members of Boko Haram. You'll never hear...
Three people figure out a way around those pesky background checks at the gun store
CBS' Bob Schieffer to administration, "This isn't Watergate, so why are you acting exactly like...
A restraining order against a crazy ex-girlfriend doesn't do you any good if she still has the key...
Couple flying to Dakar learn what it's like to be airline baggage