Starbucks Admits Its iPhone App Stores User Passwords, Location Data in Plain Text

Posted January 16, 2014 at 3:13pm by iClarified | Please help us and submit a translation by clicking here | 7009 views

The most used mobile-payment application in the United States has been storing usernames, email addresses, passwords, and even location data in plain text, Starbucks executives confirmed.

Since the information is not encrypted (and therefore stored in plain text) anyone can simply connect the phone to a computer and view the credentials. No jailbreak is requires since the folder is public.

"A company like Starbucks has to make the choice between usability to drive adoption and the potential for misuse or fraud," said Charlie Wiggs, general manager and senior vice president for U.S. markets at mobile vendor Mozido. "Starbucks has opted to make it very convenient. They just have to make sure that their comfort doesn't overexpose their consumers and their brand."

"Yes, it does surprise me," said Gartner security analyst Avivah Litan. "I would have expected more out of Starbucks. At least they should have informed consumers."

And apparently Starbucks could have done that. Two executives -- Starbucks CIO Curt Garner and Starbucks Chief Digital Officer Adam Brotman -- said in a telephone interview that they have known for an unspecified period of time that the credentials were being stored in clear text. "We were aware," Brotman said. "That was not something that was news to us."

Daniel Wood, the security researcher that found the unecryped information says he has tested this on the latest version of the app, which Starbucks claims includes 'adequate security measures.' Unfortunately, Wood found the information is still easily accessible, although, a thief would still need the phone to take advantage of it.

We're still unsure if Starbucks will fix this issue, since it does bring 'convenience' to users by not forcing them to enter a password every time.

Read More via Computer World

Starbucks App Download

Add Comment
Fukk hater - January 17, 2014 at 6:40pm
Bunch of hater or poor ass can't afford to buy Starbucks....
Bugged Out - January 17, 2014 at 6:04pm
Starbucks has bad coffee, hours old tastes like burned shit. They cover the shitty taste with 100s of calories of artificial flavors. Go to Peets or a local shop for good coffee.
Wtf!!! - January 16, 2014 at 9:55pm
Why are people still drinking there???? I thought that was a 90's fad?
Petr - January 16, 2014 at 7:23pm
I bought Breville expresso machine and it pays itself twice already. I know what coffee I use, organic milk, sugar. I feel sorry to see people in line waiting to pay 3-5 dollars for a cup of over burned coffee.
BritBrat - January 16, 2014 at 8:08pm
Absolutely agree!!! Black brewed coffee is the best! No sugar/creamer! Helps you lose weight esp if you drink it before you hit the gym!
Petr - January 16, 2014 at 10:34pm
You read my mind. This is what I usually do, a bit if black coffee before gym. And it works great without starbucks :-)
snickerbock fleaderhammer - January 16, 2014 at 7:20pm
Simply incorporate the 5s's fingerprint recognition for payment. Problem solved.
2 More Comments
Follow iClarified
FireCore Brings YouTube Back to the Apple TV 2
FireCore has announced that aTV Flash(black) ...
Apple Designates Original Apple TV and Other Devices Obsolete Ahead of September Event
Apple to Help Pentagon Develop High-Tech Sensors
Apple has joined an alliance of companies tha...
Senior Director of Apple Music Ian Rogers Leaves Apple
Ian Rogers, senior director of Apple Music an...
iPhone 6s Packaging Leak Confirms 16GB Model [Photo]
Another leak of packaging material for the iP...