Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 13,2020

New Delhi, Jan 13: The Delhi High Court on Monday sought response of the city police, Delhi government, WhatsApp Inc, Google Inc and Apple Inc on a plea of three JNU professors to preserve data, CCTV footage and other evidence relating to the January 5 violence on the varsity campus.

The Delhi Police informed the court that it has asked the JNU administration to preserve and hand over CCTV footage of the violence.

Justice Brijesh Sethi listed the matter for further hearing on Tuesday.

The court was told by Delhi government Standing Counsel (criminal) Rahul Mehra that the police has not yet received any response from the university administration.

The counsel said police has also written to WhatsApp to preserve data of two groups "Unity Against Left" and "Friends of RSS" including messages, pictures and videos and phone numbers of members, related to JNU violence incident.

The petition was filed by JNU professors Ameet Parameswaran, Atul Sood and Shukla Vinayak Sawant seeking necessary directions to the Delhi Police Commissioner and Delhi government.

The petition also sought direction to the Delhi Police to retrieve all CCTV footage of JNU campus.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 16,2020

New Delhi, Jan 16: In trouble brewing for the Gautam Adani-led M/S Adani Enterprises, the Central Bureau of Investigation (CBI) on Thursday said that it has registered a case against former officials of the National Co-operative Consumer Federation (NCCF) and others over alleged irregularities in supply of coal to the Andhra Pradesh Power Generation Corporation (APGENCO) in 2010.

The CBI in its FIR has named Virendra Singh, the then Chairman of the NCCF, G P Gupta, the then MD of the NCCF, S C Singhal, the then Senior Advisor of NCCF, Adani Enterprises Ltd and other unknown public servants and others for criminal conspiracy, cheating and criminal misconduct by public servants.

According to CBI, the case was filed on Wednesday after the preliminary enquiry revealed the crime by the officials named in the FIR and the Adani Enterprises was found to be true.

The FIR alleged that on June 26, 2010, APGENCO floated a tender enquiry for supply of six lakh metric tonnes of imported coal "on free on rail destination" basis to Dr Narla Tata Rao Thermal Station (NTTPS), Vijaywada and Rayalasaleema Thermal Power Plant (RTTP), Kadapa, Andhra Pradesh/RTPP via Kakinada-Vizag-Chennai-Krishnapatnam or any other ports

The same was forwarded by the Chief Engineer, APGENCO to seven PSUs -- PEC Limited, STC Limited, MSTC Limited, NCCF, MMTC, Coal India Limited and SCCL Limited.

The FIR alleged that during the probe, the Adani Enterprises used a proxy company to get the supply contract. It said, "NCCF received bids from six companies -- Adani Enterprises Ltd, Maheshwari Brothers Coal Limited (MBCL), Vyom Trade Links Pvt. Ltd, Swarana Projects Pvt. Ltd, Gupta Coal India Ltd and Kyori Oremen Ltd.

During investigation it was found that Gupta Coal India Ltd had quoted the NCCF margin of 11.3 percent, while the MBCL quoted the margin of 2.25 percent and rest did not quote any margin to the NCCF.

The FIR said the quotes of the Gupta Coal India Ltd, Kyori Oremen Ltd and Swarana Projects Pvt. Ltd were rejected by the NCCF as they were not found to be fulfilling the tender conditions.

"Post tender negotiation was done by senior officials of NCCF to give undue favour to Adani Enterprises Ltd despite it not qualifing the tender (terms)," the FIR said, adding instead of cancelling the bid of Adani Enterprise Ltd, senior management of NCCF conveyed the offer margin to the company through one of its representative -- Munish Sehgal, who was sitting in the NCCF head office. It is prima facie evident that when the bids were being processed at NCCF head office in Delhi, a representative of Adani Enterprises Ltd. was informed regarding their imminent rejection due to non-submission of NCCF margin and also that MBCL was eligible bidder quoted 2.25 percent margin," it alleged.

The CBI in its FIR, further alleged that Adani Enterprises Ltd. had given an unsecured loan of Rs 16.81 crore to Vyom Trade Links Ltd in 2008-09. "And further it was revealed that the bank guarantees of the Adani Enterprises Ltd. and Vyom Trade Links Ltd. were issues by the same branch of the State Bank of India and at the same time," it said.

"It was clear that Adani Enterprises Ltd. presented Vyom Trade Links Ltd. as a proxy company in this particular tender and Vyom Trade Links Ltd. later withdrew its offer on flimsy ground," the CBI FIR said.

"The aforesaid acts of commissions and omissions on the part of the senior management of the NCCF disclose that during their tenure, they acted in a manner unbecoming of public servants and committed irregularities by way of manipulation in the selection of bidders, thereby giving undue favours to Adani Enterprises Ltd. in award of work for supply of coal to APGENCO despite its disqualification," it added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 5,2020

Mumbai, Feb 5: Maharashtra Chief Minister Uddhav Thackeray on Wednesday said there was no need to fear the Citizenship Amendment Act, but asserted his government will not allow the proposed National Register of Citizens to be implemented as it would "impact people of all religions".

Throwing out Bangladeshi and Pakistani migrants out of the country was an old demand of the Shiv Sena, the chief minister said in the third and concluding part of his interview to party mouthpiece 'Saamana'.

"I can confidentally say the Citizenship (Amendment) Act (CAA) is not meant to throw Indian citizens out of the country. But, the National Register of Citizens (NRC) is going to impact Hindus as well," the Sena president said.

India has the right to know the number of minorities from neighbouring nations who applied for Indian citizenship after being persecuted in their home countries, he said.

"When they come here, will they get homes under the 'Pradhan Mantri Awas Yojana'? What about employment and education of their children? All these issues are important and we have the right to know," hesaid in the interview to Saamana's executive editor and Sena MP Sanjay Raut.

"As chief minister, I should know where will these people be relocated in my state. Our own people don't have adequate housing. Will these people go to Delhi, Bengaluru or Kashmir, since Article 370 is now scrapped?" he wondered.

Several Kashmiri Pandit families are staying like refugees in their own country. The CAA is not to throw citizens out of the country, Thackeray said.

"However, the NRC will impact Hindus and Muslims and the state government will not allow it to be implemented," he asserted.

Under the NRC, all citizens will have to prove their citizenship. In Assam, 19 lakh people could not prove their citizenship. Of these, 14 lakh are Hindus, Thackeray claimed.

In a veiled attack on his cousin and MNS chief Raj Thackeray, who will lead a rally in support of the CAA and NRC in Mumbai on February 9, the chief minister said the NRC is not yet a reality and there is no need for a 'morcha' in support of or against it.

"If the NRC is enforced, those who are supporting it will also be affected," he said.

Under the NRC, even Hindus will have to prove their citizenship. "I will not allow the law to be enacted. Whether I am chief minister or not, I will not allow injustice to anybody," he said.

The chief minister also took a veiled dig at the Centre's decision to give the Padma Shri award to Pakistani-origin musician Adnan Sami.

"A migrant is a migrant. You can't honour him with the Padma award. Throwing out illegal migrants was the stand of (late Shiv Sena supremo) Balasaheb Thackeray," he said without naming anyone.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.