UPI en Español  |   UPI Asia  |   About UPI  |   My Account
Search:
Go

Study: Most mobile Web browsers unsafe

|
 
This graphic shows the inconsistency with which three of the major mobile browser platforms display security indicators. Credit: Georgia Tech
This graphic shows the inconsistency with which three of the major mobile browser platforms display security indicators. Credit: Georgia Tech
Published: Dec. 5, 2012 at 4:35 PM

ATLANTA, Dec. 5 (UPI) -- Smartphone Web browsers are unsafe and even cybersecurity experts can't detect when they've have landed on potentially dangerous websites, a U.S. study found.

In a critical area that informs user decisions -- the incorporation of tiny graphical indicators in a browser's URL address field -- all of the leading mobile browsers fail to meet security guidelines recommended by the World Wide Web Consortium for browser safety, researchers at the Georgia Institute of Technology reported Wednesday.

The graphic icons are called either SSL (secure sockets layer) or TLS (transport layer security) indicators and serve to alert users when their connection to the destination website is secure and the website they see is actually the site they intended to visit.

Without that graphical confirmation of a secure site, even expert users have no way to determine if the websites they visit are real or impostor sites phishing for personal data, the researchers said.

"We found vulnerabilities in all 10 of the mobile browsers we tested, which together account for more than 90 percent of the mobile browsers in use today in the United States," computer science Professor Patrick Traynor said.

"The basic question we asked was, 'Does this browser provide enough information for even an information-security expert to determine security standing?' With all 10 of the leading browsers on the market today, the answer was no."

The Web consortium has recommended how SSL indicators should be built into a browser's user interface and desktop browsers do a good job of following those recommendations, researchers said, but in mobile browsers the guidelines are followed inconsistently at best and often not at all.

"Research has shown that mobile browser users are three times more likely to access phishing sites than users of desktop browsers," Georgia Tech doctoral student Chaitrali Amrutkar said. "Is that all due to the lack of these SSL indicators? Probably not, but giving these tools a consistent and complete presence in mobile browsers would definitely help."

Recommended Stories
© 2012 United Press International, Inc. All Rights Reserved. Any reproduction, republication, redistribution and/or modification of any UPI content is expressly prohibited without UPI's prior written consent.

Order reprints
Join the conversation
Most Popular Collections
'Star Trek Into Darkness' screening NBC upfronts Met Ball 2013
'Great Gatsby' premieres in New York Spire raised on top of One WTC 2013: Celebrity break ups and divorces
Additional Technology Stories
1 of 16
Flags-In Ceremony at Arlington National Cemetery
View Caption
Staff Sgt. Jeffrey Roskos with the 3rd U.S. Infantry Regiment, "The Old Guard," participates in the annual Flags-In ceremony, May 23, 2013, at Arlington National Cemetery in Arlington, Virginia. Soldiers place American flags in front of more than 260,000 gravestones in the cemetery in honor of Memorial Day. UPI/Kevin Dietsch
fark
Deaf Chinese orphan adopted by American audiologist scheduled to get new type of cochlear implant....
Zookeeper goes in to feed tiger. Succeeds
NJ Transit shuts down train line based on a sighting of a man armed with "a long barrel assault...
On this week's episode of Some People are Capable of Amazing Feats: 17-year-old homeless girl becomes...
Photoshop this intrepid photographer
FARK PART'EH June 8 in Toronto, Canada. Baseball, Beer, Beavers, we have it all