Currently, in the Android market, 86 percent of the top 20 most downloaded apps in 10 diverse categories use WebView. With the goal of creating dynamic apps, WebView has enabled developers to embed browsers in their apps allowing users to have a more customized experience that provides opportunities to interact with social media, personal email and other app users. However, Du has discovered that the use of WebView opens app developers and users to potential risks.
Dealing with losing the protection of the sandbox. Internet browsers on computers have safeguards, known as the sandbox, that protect user information and prevent personal information from unknowingly being shared throughout the web. As apps have become more dynamic, those safeguards can often impede some of the desired functionality a developer wishes to create. As a result, app developers have slowly begun opening up holes in the protective sandbox to provide a better user experience but as a result user information is no longer as secure.
“In industry, developers are usually carried away by the fancy features they create for their products; they often forget about or underestimate the security problems caused by those features,” says Du. “This has happened many times in the history of computing. The design of WebView in Android is just another example of this.”
Du has submitted a proposal to Google to explore whether there are ways to preserve the nice features of WebView and at the same time make it secure. He and his graduate students are also planning on exploring whether this issue may also affect other smartphone and tablet platforms.
A PhD student, Tongbo Luo, who is currently working with Du on an NSF cybersecurity research grant, had the initial idea to explore weaknesses in the Android system. Luo had taken Du’s courses in computer security and Internet security where students explored both how to identify weaknesses in operating systems and applications as well as how hackers might take advantage of these weaknesses.
Du is passionate about preparing his students to apply the right amount of skepticism to new product introductions. “The goal of both of my security courses is for students to learn take a look at a system or new technology and ask themselves, ‘Is this risky?’”
In spring 2011 both Du and Luo participated in a course on the Android system taught by another LCS professor Heng Yin. As part of this course, Luo chose to explore weaknesses in Android apps that use WebView. Applying lessons from Du’s security courses both Luo and Du were able to uncover the potential risks of this rapidly expanding technology.
Ariel DuChene | EurekAlert!
Shaping nanoparticles for improved quantum information technology
15.10.2019 | DOE/Argonne National Laboratory
Controlling superconducting regions within an exotic metal
11.10.2019 | Ecole Polytechnique Fédérale de Lausanne
A very special kind of light is emitted by tungsten diselenide layers. The reason for this has been unclear. Now an explanation has been found at TU Wien (Vienna)
It is an exotic phenomenon that nobody was able to explain for years: when energy is supplied to a thin layer of the material tungsten diselenide, it begins to...
Researchers at Ludwig-Maximilians-Universitaet (LMU) in Munich have explored the initial consequences of the interaction of light with molecules on the surface of nanoscopic aerosols.
The nanocosmos is constantly in motion. All natural processes are ultimately determined by the interplay between radiation and matter. Light strikes particles...
Particles that are mere nanometers in size are at the forefront of scientific research today. They come in many different shapes: rods, spheres, cubes, vesicles, S-shaped worms and even donut-like rings. What makes them worthy of scientific study is that, being so tiny, they exhibit quantum mechanical properties not possible with larger objects.
Researchers at the Center for Nanoscale Materials (CNM), a U.S. Department of Energy (DOE) Office of Science User Facility located at DOE's Argonne National...
A new research project at the TH Mittelhessen focusses on the development of a novel light weight design concept for leisure boats and yachts. Professor Stephan Marzi from the THM Institute of Mechanics and Materials collaborates with Krake Catamarane, which is a shipyard located in Apolda, Thuringia.
The project is set up in an international cooperation with Professor Anders Biel from Karlstad University in Sweden and the Swedish company Lamera from...
Superconductivity has fascinated scientists for many years since it offers the potential to revolutionize current technologies. Materials only become superconductors - meaning that electrons can travel in them with no resistance - at very low temperatures. These days, this unique zero resistance superconductivity is commonly found in a number of technologies, such as magnetic resonance imaging (MRI).
Future technologies, however, will harness the total synchrony of electronic behavior in superconductors - a property called the phase. There is currently a...
02.10.2019 | Event News
02.10.2019 | Event News
19.09.2019 | Event News
18.10.2019 | Power and Electrical Engineering
18.10.2019 | Medical Engineering
18.10.2019 | Physics and Astronomy