Citigroup issued a warning today noting that there were some security loopholes in its mobile banking iPhone app, and also released an update that patches the hole.
Citi said that the app saved personal information about users, such as security codes, account imformation, and transaction details, to a remote file on the iPhone’s internal memory. That data could then have been accessed by any third party that had access to the phone.
That data was also transferred to the user’s PC every time the iPhone was synced up.
Jordan Sturm was probably stunned when her iPhone was suddenly snatched away by a bike-riding thief. I know I was when the exact same thing happened to me—except unlike Jordan, I wasn’t testing a live GPS-tracking app.