medium_8207774627
LifeLock, the identity theft protection company pulled the rug on one of their mobile apps and deleted all the user data within those systems in response to very significant security concerns. Company CEO and Chairman Todd Davis disclosed in a blog post, “We have determined that certain aspects of the mobile app may not be fully compliant with payment card industry (PCI) security standards.” There has been no further information on what components of the PCI security standards were violated by the popular app, known as LifeLock Wallet. Davis adds, “For that reason, we are removing the LifeLock Wallet application from the App Store, Amazon Apps, and Google Play, and when users open the LifeLock Wallet, their information will be deleted in the app.”
The LifeLock Wallet app came about after the company purchased mobile wallet innovator Lemon for approximately $42.6 million in cash in December of 2013. Like the Lemon wallet app, LifeLock Wallet contained digitized copies of credit cards, ID, insurance, and debit cards. The app also tracked card purchases, categorized spending and updated credit card balances. The collection of credit card and other personal information in one location is bound to PCI standards, this applies in a mobile applications as much as any other applications. Under PCI rules, any stored data must be encrypted at all times and the keys that are utilized for this encryption must be protected. It is not clear in Davis’s disclosure which of those pieces were violated, but the wiping of data is quite telling of the critical data issue.
We have taken steps to delete all stored information for the mobile app from our servers. Even though we have no reason to believe the data has been compromised, we believe this is the right thing to do.
LifeLock is planning to relaunch the application after the issues are addressed. The company is under an intense amount of scrutiny and has taken a number of public blows. In 2010, the company settled for $12 million with the Federal Trade Commission and 35 state attorney generals on charges that the company’s service didn’t work as advertised. Davis has also famously put his social security number on the website as a show of confidence in the service. That hasn’t worked out all that well for him, as according to various reports Davis may have had his identity stolen thirteen times, by a count in 2010. The company has taken a pounding on Wall St, after several ratings downgrades.