Trading apps expose investors to cybercriminals, report finds

Some apps store subscribers' passwords or data on trading without encryption

Aug 10, 2018 @ 10:40 am

By Bloomberg News

Dozens of applications used for online trading by retail investors have cybersecurity vulnerabilities, some of which could lead to hackers siphoning funds from account holders, according to security consultant IOActive Inc.

Ten of the 80 applications tested over a one-year period store passwords of their subscribers without encryption, a flaw that could lead to funds being stolen, IOActive reported at the Black Hat cybersecurity conference Thursday in Las Vegas. Those included software by AvaTrade Ltd. and IQ Option, according to the report.

Software at ETrade Financial Corp. and TD Ameritrade Holding Corp. stores trading data without encryption, the report found.

The largest brokers offer the best security, yet still have weaknesses, said Alejandro Hernandez, a senior security consultant and author of the report. The biggest firms have been responsive to IOActive's findings and are fixing the issues, Mr. Hernandez said.

Rebecca Niiya, a TD Ameritrade spokeswoman, said the company investigates any reported vulnerabilities and has "already made progress in addressing the potential issues noted in the IOActive report."

Representatives for ETrade, AvaTrade and IQ Option didn't have any comment or didn't respond to emails seeking a response.

The analysis looked at desktop, mobile and website-based trading software and found the web platforms to be the most secure. Desktop applications were the least secure.

Using the same criteria, banking applications on all platforms are many times more secure than trading apps, Mr. Hernandez said. Retail investors could have a false sense of security because they probably equate their trading applications with their banking software, he said.

(More: Market pullback presents robo-advisers with biggest test yet)

0
Comments

What do you think?

View comments

Recommended for you

Featured video

INTV

What it took to win an Excellence in Diversity & Inclusion Award

Editor Fred Gabriel and special projects editor Liz Skinner explain how InvestmentNews chose the winners of our inaugural Excellence in Diversity & Inclusion Awards.

Latest news & opinion

Tax-credit investigation may trip up Wells Fargo

Justice Department is investigating bank's dealings in tax credits for low-income housing, sources say.

10 biggest boomtowns in America

These metro areas are seeing the biggest influx of people, work opportunities and business growth.

SEC ponders creating video to help investors decide between investment adviser and broker

Chairman Jay Clayton has suggested the host on the video would deliver similar information as conveyed on disclosure Form CRS.

Genworth raises long-term-care insurance costs an average 58%

The cost increases, approved by regulators in the second quarter, affect roughly $160 million of in-force premiums.

Registered reps, firms in brokerage industry decline: new Finra report

Regulator publishes first-ever snapshot of sector it oversees.

X

Hi! Glad you're here and we hope you like all the great work we do here at InvestmentNews. But what we do is expensive and is funded in part by our sponsors. So won't you show our sponsors a little love by whitelisting investmentnews.com? It'll help us continue to serve you.

Yes, show me how to whitelist investmentnews.com

Ad blocker detected. Please whitelist us or give premium a try.

X

Subscribe and Save 60%

Premium Access
Print + Digital

Learn more
Subscribe to Print