作者: Adam Bates , Kevin R. B. Butler , Bradley Reaves , Patrick Traynor , Nolen Scaife
DOI:
关键词: Financial services 、 Financial inclusion 、 Mobile payment 、 Payment 、 Unbanked 、 Computer science 、 Computer security 、 Cash 、 Branchless banking 、 Liability
摘要: Mobile money, also known as branchless banking, brings much-needed financial services to the unbanked in developing world. Leveraging ubiquitous cellular networks, these are now being deployed smart phone apps, providing an electronic payment infrastructure where alternatives such credit cards generally do not exist. Although widely marketed a more secure option cash, applications often subject traditional regulations applied sector, leaving doubt veracity of claims. In this paper, we evaluate claims and perform first in-depth measurement analysis banking applications. We automated all 46 Android mobile money apps across 246 providers demonstrate that fails provide reliable insights. subsequently comprehensive manual teardown registration, login, transaction procedures diverse 15% apps. uncover pervasive systemic vulnerabilities spanning botched certification validation, do-it-yourself cryptography, myriad other forms information leakage allow attacker impersonate legitimate users, modify transactions flight, steal records. These findings confirm majority fail protections needed by services. Finally, through inspection providers' terms service, discover liability for problems unfairly rests on shoulders customer, threatening erode trust hinder efforts global inclusion.