;
  • Report:  #1143051

Complaint Review: CreditKarma.com - Nationwide

Reported By:
Jalus - Princeton, Massachusetts,
Submitted:
Updated:

CreditKarma.com
Nationwide, USA
Web:
N/A
Categories:
Tell us has your experience with this business or person been good? What's this?

"FOR RELEASE:

March 28, 2014FOR RELEASEF

Credit Karma Settle FTC Charges that They Deceived Consumers By Failing to Securely Transmit Sensitive Personal Information

The FTC alleged that, despite their security promises Credit Karma failed to take reasonable steps to secure their mobile apps, leaving consumers’ sensitive personal information at risk. Among other things, the complaints charge that Credit Karma disabled a critical default process, known as SSL certificate validation, which would have verified that the apps’ communications were secure.

As a result, the companies’ applications were vulnerable to “man-in-the-middle” attacks, which would allow an attacker to intercept any of the information the apps sent or received.
 
By overriding the default validation process, Credit Karma’s apps for iOS and Android disabled the default validation process, exposing consumers’ Social Security Numbers, names, dates of birth, home addresses, phone numbers, email addresses and passwords, credit scores, and other credit report details such as account names and balances. "

 



Reports & Rebuttal
Respond to this report!
Also a victim?
Repair Your Reputation!
//