{"id":58655,"date":"2014-01-17T01:44:13","date_gmt":"2014-01-16T23:44:13","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=58655"},"modified":"2025-07-02T00:56:31","modified_gmt":"2025-07-02T07:56:31","slug":"starbucks-app-vulnerable-to-hacking","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/starbucks-app-vulnerable-to-hacking\/","title":{"rendered":"Starbucks app vulnerable to hacking"},"content":{"rendered":"<p>The Starbucks app for <a title=\"Starbucks for Android\" href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.starbucks.mobilecard\" target=\"_self\" rel=\"noopener noreferrer\">Android<\/a> and <a title=\"Starbucks for iOS\" href=\"https:\/\/itunes.apple.com\/us\/app\/starbucks\/id331177714?mt=8\" target=\"_self\" rel=\"noopener noreferrer\">iOS<\/a> is vulnerable to hacking, according to security researcher <a title=\"Daniel Wood LinkedIn\" href=\"https:\/\/www.linkedin.com\/in\/danielewood\" target=\"_blank\" rel=\"noopener noreferrer\">Daniel Wood<\/a>. The app apparently stores user information in unencrypted clear-text, which makes that information extremely easy to decipher if a hacker can get his or her hands on it. &#8220;Within session.clslog there are multiple instances of the storage of clear-text credentials that can be recovered and leveraged for unauthorized usage of a users account on the malicious users\u2019 own device or online at <a title=\"Starbucks login page\" href=\"https:\/\/www.starbucks.com\/account\/signin\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.starbucks.com\/account\/signin<\/a>,&#8221; writes Wood.<\/p>\n<p>Still, the security flaw cannot be exploited unless someone has physical access to a victim&#8217;s phone. If a victim&#8217;s phone is stolen, the user information like name, address, email, and Starbucks password can easily be obtained. This is why it&#8217;s a good idea to enable Android Device Manager and Find My iPhone \u00a0so you can remotely wipe your phone if it is lost or stolen.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-58664\" title=\"Starbucks iOS app\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/01\/screen568x568.jpg\" alt=\"Starbucks iOS app\" width=\"332\" height=\"568\" \/><\/p>\n<p>Starbucks has responded and verified that the vulnerability exists but also notes that it is unlikely that a hacker will have physical access to a victim&#8217;s phone. The broader security issue is if a person uses the same password for other sites, especially for banking. To protect yourself from data breaches, it&#8217;s best to use a password manager to create and store different passwords for each site.<\/p>\n<p>The recent data breach at <a title=\"Target data breach FAQ\" href=\"https:\/\/corporate.target.com\/about\/shopping-experience\/payment-card-issue-FAQ\" target=\"_blank\" rel=\"noopener noreferrer\">Target<\/a> and a string of high-profile hacks at companies like <a title=\"Letmein! Adobe password crosswords reveal the worst and most popular passwords\" href=\"http:\/\/news.en.softonic.com\/letmein-adobe-password-crosswords-reveal-the-worst-and-most-popular-passwords\" target=\"_self\" rel=\"noopener noreferrer\">Adobe<\/a> should be enough to pressure Starbucks into rewriting the app so that it doesn&#8217;t store user information in clear-text. Starbucks has not yet promised to fix the vulnerability, though it&#8217;s difficult to see why they wouldn&#8217;t.<\/p>\n<p>Source: <a title=\"ReadWrite\" href=\"http:\/\/readwrite.com\/2014\/01\/16\/starbucks-app-exposed-10-million-customers-at-risk#awesm=~ot9uPKx6tQuz2W\" target=\"_blank\" rel=\"noopener noreferrer\">ReadWrite<\/a><\/p>\n<h4>RELATED STORIES<\/p>\n<ul>\n<li><a href=\"http:\/\/news.en.softonic.com\/microsoft-will-provide-windows-xp-security-updates-until-july-14-2015\">Microsoft will provide Windows XP security updates until July 14, 2015<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/snapchat-update-gives-option-to-opt-out-of-find-friends\">Snapchat update gives option to opt-out of Find Friends<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/avg-privacyfix-family-web-tuneup\">AVG announces PrivacyFix Family and Web TuneUp to protect your privacy online<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>The Starbucks app for Android and iOS is vulnerable to hacking, according to security researcher Daniel Wood. The app apparently stores user information in unencrypted clear-text, which makes that information extremely easy to decipher if a hacker can get his or her hands on it. &#8220;Within session.clslog there are multiple instances of the storage of &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/starbucks-app-vulnerable-to-hacking\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Starbucks app vulnerable to hacking&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":58663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-58655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/58655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=58655"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/58655\/revisions"}],"predecessor-version":[{"id":331531,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/58655\/revisions\/331531"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/58663"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=58655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=58655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=58655"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=58655"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=58655"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=58655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}