Affiliate links on Android Authority may earn us a commission. Learn more.

The cloud has been a revolutionary change in app development that allows just about anybody to create a new app. Unfortunately, ājust about anybodyā probably isnāt qualified to handle your private data.
A study by mobile security firm Zimperium (via Wired) found that tens of thousands of Android and iOS apps have misconfigurations in their cloud infrastructure that allow hackers to gain access to private data.
Hereās how those leaks work:
- For developers, using public cloud servers like Amazon Web Services, Google Cloud, or Microsoft Azure is a popular alternative to setting up their own servers.
- But if cloud permissions are not set up correctly by the developer, bad actors can get access to their cloud storage and more.
- This kind of āhackingā is nothing new for ecommerce sites, but the increasing reliance on public cloud servers for apps makes this particularly dangerous.
- Of the 1.3 million apps tested by Zimperium, nearly 20,000 were āexposing usersā personal information, passwords, and even medical information.ā
- No apps are called out by name in the report, but some apparently have millions of users:
- āOne of the apps in question is a mobile wallet from a Fortune 500 company thatās exposing some user session information and financial data. Another is a transportation app from a large city thatās exposing payment data. The researchers also found medical apps with test results and even usersā profile images out in the open.ā
Does that mean you should be concerned? Absolutely:
- So why arenāt any apps named? Because there are so many apps exposing information that Zimperium couldnāt possibly warn them all.
- And those that they did warn often didnāt bother to respond.
- Leaving these vulnerabilities open can have other implications, since āsome of the misconfigurations would allow bad actors to change or overwrite data, creating additional potential for fraud and disruption.ā
- All because someone forgot to check a few boxes.
- Think about that next time you struggle to reset your microwave clock.
- (and if youāre a developer, please double check your cloud configuration)
š± The latest from Xiaomi sub-brand Redmi is a solid upper-budget-tier device. Redmi Note 10 Pro review: Revved up specs for a great price (Android Authority).
š³ The worldās first phone with a 165Hz AMOLED display was announced in China, although itās not from a brand youāll probably like (Android Authority).
ā» What do you do with your old phone when you get a new one? Apparently less than a third trade it in (Android Authority).
š Sonos announced a new portable speaker called the Sonos Roam. It ships in April, but be warned: it isnāt cheap (The Verge).
šØ Good news for US consumers: Senators have called on the FCC to increase base speeds for āhigh speedā internet. Itās been stuck at 25Mbps down 3Mbps up since 2015 (The Verge).
š And now some bad news for US drivers: US roads got more dangerous in 2020 even though we stayed at home (Ars Technica).
š Apple clarified that no, you will not be able to choose a default music player in iOS 14.5. Will this take the heat off of antitrust litigation? Probably not (TechCrunch).
ā Valve has ceased development on its Dota card game Artifact. You can still play it for free with no microtransactions, if thatās your thing. Surely this will free up plenty of resources for Half Life 3, right? (Ars Technica).Ā
š Matthew Cederquist, Game Producer for Diablo II: Resurrected, confirmed that players will be able to import 20-year-old game saves from the original title. Howās that for backwards compatibility? (IGN Middle East)
š« āHow would you be expelled from Willy Wonkaās chocolate factory?ā So many OSHA violations (r/askreddit).

This weekās Friday Fun is a bit of a blast from the internet past. In certain circles of YouTube, removing music from music videos was all the rage back in 2014/2015. Mario Wienerroither was an early pioneer, with hugely popular videos like a musicless version of Elvis Presley performing Blue Suede Shoes.
Other channels like Without Music (watch their Greased Lightning video, itās great) have continued the trend well into 2021.
Check them out but be careful not to fall too deep down the rabbit hole.
Until next time,
Nick Fernandez, Editor

