Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 11,2020

New Delhi, May 11: Shares of Indian Railway Catering And Tourism Corporation (IRCTC) jumped 5 per cent in early trade on Monday after the Indian Railways said it will gradually resume passenger train services from May 12.

The company's shares gained 5 per cent to Rs 1,302.85 -- its highest trading permissible limit for the day -- on the BSE. At the National Stock Exchange (NSE), it rose 5 per cent to Rs 1,303.55 -- its upper circuit limit.

Booking for reservation in these trains will start at 4pm on May 11 and will be available only on the IRCTC website.

The Indian Railways will gradually resume passenger train services from May 12 and will ask passengers to arrive at the station at least an hour before departure, the national transporter said on Sunday.

Initially, the all air-conditioned services will begin on 15 Rajdhani routes and the fare would be equivalent to that of the super-fast train, it said.

The special trains will run from New Delhi to Dibrugarh, Agartala, Howrah, Patna, Bilaspur, Ranchi, Bhubaneswar, Secunderabad, Bengaluru, Chennai, Thiruvananthapuram, Madgaon, Mumbai Central, Ahmedabad and Jammu Tawi.

All passenger services were suspended due to a lockdown announced on March 25 and the railways later started the on-demand Shramik Specials to ferry migrants stranded across the country. It, however, has been running freight and parcel services.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 8,2020

Aurangabad, May 8: At least 15 migrant workers, who were sleeping on the railway tracks while going back to their native places, were run over by a goods train between Maharashtra's Jalna and Aurangabad, officials said on Friday.

A senior railway official confirmed that 15 migrant labourers were run over by a goods train between Jalna and Aurangabad of Nanded Divison of South Central Railway.

The official said that the incident happened around 5.30 am on Friday when the migrant workers, who were on way back to their homes and sleeping on the railway tracks.

However, it is yet not clear from where this group hailed and where they were going.

Amid the nationwide lockdown, thousands of migrant workers stranded in several other cities have started their journey to return to their native places on foot.

The interstate bus service, passenger, mail and express train services have been suspended since March 24.

The railways has started running Shramik Special trains to transport the stranded migrants to their native places since May 1.

Till Thursday railways has run 201 Shramik Special trains.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 19,2020

New Delhi, Jul 19: With the highest single-day spike of 38,902 cases reported in the last 24 hours, India's total COVID-19 tally on Sunday reached 10,77,618, informed the Union Health and Family Welfare Ministry on Sunday.

The death toll has gone up to 26,816 with 543 fatalities reported in the last 24 hours.

The Health Ministry said the total number of cases includes 3,73,379 active cases and 6,77,423 patients have been cured/discharged/migrated.

Maharashtra remains the worst affected state with 3,00,937 cases reported until Saturday.
Meanwhile, as per the information provided by the Indian Council of Medical Research (ICMR), 1,34,33,742 samples have been tested for COVID-19 till July 18, of these 3,61,024 samples were tested yesterday.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.