Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 29,2020

Karachi, May 29: Investigators and rescue officials have found around Rs 3 crore in cash in the wreckage of the Pakistan International Airlines' aircraft that crashed wth 99 people on board, killing 97 people, including nine children.

Flight PK-8303 from Lahore to Karachi crashed in a residential area near Karachi International Airport on Friday, with only two passengers miraculously surviving the crash.

Investigators and rescue officials have found currencies of different countries and denominations worth around Rs 30 million from the aircraft's wreckage, an official said on Thursday.

"An investigation has been ordered into how such a huge amount of cash got through airport security and baggage scanners and found its way into the ill-fated flight," the official said.

He said that the amount was recovered from two bags in the wreckage.

"The process of identifying the bodies and their luggage which will be handed over to their families and relatives is going on," he said.

A total of 97 people including the aircraft crew died in the crash, one of the most catastrophic aviation disasters in Pakistan's history.

A government official said on Thursday that the identification of 47 bodies had been completed, while 43 bodies were handed over for burial.

Friday's accident was the first major aircraft crash in Pakistan after December 7, 2016 when a PIA ATR-42 aircraft from Chitral to Islamabad crashed midway. The crash claimed the lives of all 48 passengers and crew, including singer-cum-evangelist Junaid Jamshed.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 12,2020

Bhopal, Mar 12: The Madhya Pradesh Congress on Thursday took a dig at Jyotiraditya Scindia, who broke ranks with the party and joined BJP on Wednesday, by pointing out that neither Prime Minister Narendra Modi nor Amit Shah had not even put out as much a tweet to welcome him in the party, and construed it as "humiliation" for the "maharaja".

"Not even a tweet by Narendra Modi-ji or Amit Shah-ji to welcome Scindia-ji! Modi-ji, Shah-ji, at least do not do it so soon. It has not even been 24 hours yet and you guys have already started humiliating him...!" Madya Pradesh Congress tweeted in Hindi.

Taking a jibe at Mr Scindia, a member of the erstwhile royal family of Gwalior who ended his 18-year-long association with the Congress party on a bitter note, the state Congress said: "He is a maharaja, the one whose history is often mentioned by Shivraj-ji (former Madhya Pradesh Chief Minister Shivraj Singh Chouhan)."

On Wednesday, Jyotiraditya  Scindia joined BJP in New Delhi in the presence of party president JP Nadda. He had resigned from Congress a day earlier after meeting Amit Shah and Prime Minister Narendra Modi.

Mr Scindia will file his nomination for the Rajya Sabha elections on March 13. He is expected to go to Bhopal today.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 7,2020

Srinagar, Mar 7: Two more accused, including a man who allegedly bought chemicals online for making improvised explosive device (IED) to be used in an attack on a convoy of the Central Reserve Police Force (CRPF) in Jammu and Kashmir's Pulwama last year, were arrested by the National Investigation Agency (NIA) on Friday, an official said.

The terror attack left 40 CRPF personnel dead in south Kashmir's Pulwama last year.

Waiz-ul-Islam, 19, from Srinagar and Mohammad Abbass Rather, 32, from Pulwama were arrested by the NIA, taking the number of those arrested in the case in the past week to five.

"During initial interrogation, Islam disclosed that he used his Amazon online shopping account to procure chemicals for making IEDs, batteries and other accessories on the directions of Pakistani Jaish-e-Mohammed (JeM) terrorists," the official said.

He said Islam personally delivered the items to the JeM terrorists after buying them online as a part of the conspiracy to carry out the attack.

"Rather is an old overground worker of the JeM. He has disclosed that he gave shelter at his home to Jaish terrorist and IED expert Mohd Umar after he came to Kashmir in April-May 2018," the official said.

Rather also sheltered other JeM terrorists - suicide bomber Adil Ahmad Dar, Sameer Ahmed Dar and Kamran, a Pakistani -- at his house before the Pulwama attack, the official said.

"He also facilitated safe shelter for the JeM terrorists, including Adil, at the house of accused Tariq Ahmed Shah and his daughter Insha Jan of Hakripora, who were arrested on March 3," the official said.

He said Islam and Rather will be produced before the NIA special court in Jammu on Saturday, while further investigation in the case continues. The NIA took over the case to probe the conspiracy behind the February 14, 2019, attack in Pulwama.

The last video of Adil, which was released by the JeM from Pakistan after the terror attack, was filmed at the home of Tariq Ahmed Shah. On February 28, the NIA achieved a major breakthrough in the case when it arrested 22-year-old Shakir Bashir Magrey, a furniture shop owner and resident of Pulwama.

Magrey had given shelter and other logistical assistance to suicide bomber Adil. He was introduced to Adil in mid-2018 by Pakistani terrorist Mohammad Umar Farooq and he became a full-time OGW of the JeM.

The explosives used in the attack were determined through forensic probe to be ammonium nitrate, nitro-glycerin and RDX. During investigation into the attack, the identity of the suicide bomber to be Adil Ahmad Dar was confirmed through DNA matching with that of his father.

The other key terrorists involved in the attack have been found to be JeM's south Kashmir divisional head Muddasir Ahmad Khan, killed in an operation by the security forces on March 11 last year; Pakistani terrorists Muhammad Umar Farooq and IED expert Kamran, both killed on March 29 last year; the owner of the car Sajjad Ahmad Bhat, a resident of Anantnag who was killed on June 16 last year, and Qari Yassir, JeM's commander for Kashmir who was killed on January 25 this year.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.