FTC Approves Final Orders with Fandango and Credit Karma: Mobile Apps were Deceptive
The Federal Trade Commission (“FTC”) announced recently that it has approved final orders settling charges against movie ticket company Fandango, LLC and consumer credit information company Credit Karma, Inc.Although neither Fandango nor Credit Karma were charged due to actual security breaches, both companies were charged with failing to take reasonable steps to properly secure data that consumers imputed on their mobile apps, leaving them at risk of being hacked.
The FTC said both Fandango and Credit Karma disabled the SSL certificate validation on their apps, leaving consumers’ sensitive personal information, including credit card information and Social Security numbers, vulnerable to interception by third parties.
The FTC alleged that Credit Karma’s app developers disabled certificate validation during the testing of Credit Karma’s iOS app and then failed to remove the override function when releasing it into Apple's App Store. Months later, a consumer notified the company of the vulnerability and the default iOS settings were restored. However, the same override error was made again when releasing the Android version of Credit Karma in February 2013.
Similarly, Fandango allowed its app for iOS to skip verifications from March 2009 to February 2013. The FTC also said that Fandango lacked a good process for responding to vulnerability reports from security researchers. This led to the company missing an advisory from a researcher who had discovered the SSL vulnerability.
The FTC complaint charged that the company’s in-app statements such as “You don’t need an account to securely purchase tickets” were false and misleading. Fandango was charged under Section 5 of the FTC act for deceptive acts and practices.
Choose Your Plan and Start Your Compliance Journey
CLIClaw Subscription
Unlock Your Compliance Solutions Now
Here you will find access to a collection of proven materials used to design compliance programs for some of the largest marketers including online education, simplified guides, and checklists, as well as public resources, programs and outlines which are designed to assist you in creating your community of compliance.
$279
per year
- Educational Resources. Gain insights into designing robust compliance programs used by leading marketers. Simplified guides, checklists, and public resources are at your fingertips.
- Customizable Policies. Empower your team to create personalized policies, procedures, and contracts tailored to your business needs. Learn negotiation strategies to handle contracts effectively and mitigate risks.
- Practical Solutions. Navigate seemingly intricate compliance challenges with practical, actionable solutions.
- Knowledge Empowerment. Understand legal requirements to transform complex forms into actionable insights and strategic advantages.
And More! Continuous updates and additional resources to keep you ahead in compliance.
CLICEnterprise
Tailored Compliance Solutions for Your Business.
CLICEnterprise offers customized compliance solutions designed to meet your business needs, including tailored guides, checklists, and expert-led training. Gain secure access to a private web portal for centralized compliance management and stay up-to-date with real-time alerts on regulatory changes. Additional resources are available to streamline your compliance processes and ensure your business stays fully compliant.
Let's Build Your Custom Compliance Solution - Contact Us Today
- Tailored Guides & Checklists. Customized compliance guides and checklists specific to your industry and operational requirements.
- Company Private Web Portal. Secure access to a dedicated web portal for centralized compliance management, training, and documentation.
- Certified Personal Training. Expert-led training programs tailored to your company’s practices and compliance requirements.
- Compliance Alerts. Stay informed with timely alerts on regulatory changes and updates impacting your industry.
And More! Additional resources and support to streamline your compliance processes.