Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 15,2020

New Delhi, Jun 15: With an increase of 11,502 cases in the past 24 hours, the COVID-19 count in India reached 3,32,424 on Monday, according to the Union Health and Family Welfare Ministry.

The spike is marginally lower than the highest-ever spike of 11,929 new cases the country registered a day earlier.

With 325 deaths being reported from across the country, the toll due to COVID-19 has now reached 9,520.

The COVID-19 count includes 1,53,106 active cases while 1,69,798 patients have been cured and discharged or migrated so far.

Maharashtra with 1,07,958 cases continues to be the worst-affected state in the country with 53,030 active cases while 50,978 patients have been cured and discharged in the state so far. 3,950 deaths have been reported due to the infection so far from Maharashtra.

It is followed by Tamil Nadu with 44,661 cases and the national capital with 41,182 confirmed cases.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 21,2020

New Delhi, Feb 21: Global terror financing watchdog FATF on Friday decided continuation of Pakistan in the "Grey List" and warned the country that stern action will be taken if it fails to check flow of money to terror groups like the LeT and the JeM, sources said.

The decision has been taken at the Financial Action Task Force's plenary in Paris.

The FATF decided to continue Pakistani in the "Grey List". The FATF also warned Pakistan that if it doesn't complete a full action plan by June, it could lead to consequences on its businesses, a source said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 22,2020

New Delhi, Jun 22: Defence Minister Rajnath Singh on Monday left for a three-day visit to Russia. Singh is likely to discuss the India-Russia defence and strategic partnership during the visit and also attend a military parade in Moscow to mark the 75th anniversary of the Soviet victory over Nazi Germany in the Second World War.

The visit comes days after the violent face-off with China in which 20 Indian Armymen were killed in Galwan valley in Ladakh.

"Leaving for Moscow on a three day visit. The visit to Russia will give me an opportunity to hold talks on ways to further deepen the India-Russia defence and strategic partnership. I shall also be attending the 75th Victory Day Parade in Moscow," the Defence Minister tweeted.

Defence Secretary Ajay Kumar is also accompanying the minister.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.