Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 8,2020

Meerut, Jan 8: Hangman Pawan Jallad, who officials say is being considered to carry out the execution of the four Nirbhaya gangrape case convicts, on Tuesday said he is ready for the job which will send out a strong message in the society.

He said executing those who were involved in the horrific crime will bring "great relief" to him, Nirbhaya's parents and everybody else.

Earlier in the day, a Delhi court issued death warrants against all the four convicts in the Nirbhaya gangrape-murder case and ordered that they are hanged on January 22 at 7 am in Tihar jail.

The death warrant, also known as a black warrant, addressed to the office of the Tihar jail chief, was issued by Additional Sessions Judge Satish Kumar Arora against Mukesh (32), Pawan Gupta (25), Vinay Sharma (26) and Akshay Kumar Singh (31).

"I do not have any information regarding the execution, nobody has spoken to me yet. If anyone approaches me, I am ready to do the job. Earlier, I was asked to be ready for the execution on December 16," Pawan Jallad told reporters here.

"Those who were involved in this brutal incident must be hanged, which will send out a strong message in the society," he said.

"Hanging the Nirbhaya gangrape case convicts will certainly bring great relief to me, her parents and everybody else," he added.

Nirbhaya, a 23-year-old paramedic student, was gang-raped and brutalised on the intervening night of December 16-17, 2012, inside a moving bus in south Delhi by the four men, along with two others, before being dumped on the road.

She died on December 29, 2012, at Mount Elizabeth Hospital in Singapore.

Of the six persons convicted, one allegedly committed suicide in jail and another, a juvenile, was released from a reformation home after serving a three-year term.

When contacted, Jail Superintendent of Meerut prison V P Pandey said he has not yet received any letter from Tihar authorities.

"Last month, we had received a letter asking us to keep Pawan Jallad ready but there is no fresh communication. The Delhi court warrants were issued this evening, maybe we will get the letter for sending him by tomorrow (Wednesday)," he said.

The gangrape of 23-year-old, who came to be known as 'Nirbhaya', the fearless one, sparked outrage across the country. Repulsed, people took to the streets across the country, demanding justice for her and better safety measures for women.

The case led to toughening of India's rape laws.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 7,2020

Jan 7: Body of the senior Iranian military commander, Qasem Soleimani killed in a U.S. drone strike in Iraq last week, has arrived in his home town of Kerman in southeast Iran for burial, the official IRNA news agency said on Tuesday.

State TV broadcast live images of thousands of people in the streets of the town, many of them dressed in black, to mourn Soleimani's death.

Soleimani was widely seen as Iran’s second most powerful figure behind Supreme Leader Ayatollah Ali Khamenei, 80, who wept in grief along with hundreds of thousands of mourners who thronged the streets of Tehran for Soleimani’s funeral on Monday.

Khamenei led prayers at the funeral in the Iranian capital, pausing as his voice cracked with emotion. Soleimani, 62, was a national hero even to many who do not consider themselves supporters of Iran’s clerical rulers.

He was killed while leaving Baghdad airport last Friday. Mourners packed the streets, chanting: “Death to America!” - a show of national unity after anti-government protests in November in which many demonstrators were killed.

The crowd, which state media said numbered in the millions, recalled the masses gathered in 1989 for the funeral of the Islamic Republic’s founder, Ayatollah Ruhollah Khomeini.

The killing of Soleimani has prompted fears around the world of a broader regional conflict, as well as calls in the U.S. Congress for legislation to keep President Donald Trump from going to war against Iran.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 18,2020

New Delhi, Jun 18: Vodafone Idea on Thursday told the Supreme Court that it has incurred Rs 1 lakh crore losses as it insisted it is not in a position to furnish bank guarantees.

A bench comprising Justices Arun Mishra, S. Abdul Nazeer, and M.R. Shah, taking up the adjusted gross revenue (AGR) matter through video conferencing, directed the telecom companies to submit their financial documents and books for the last 10 years.

Asking Vodafone if it was a foreign company, the bench said that how can the company say it would not furnish any bank guarantee.

"What if you fly away overnight in future without paying anything?" it asked.

Senior advocate Mukul Rohatgi, representing Vodafone Idea, denied his client is a completely foreign firm and cited before the bench its tie-ups and investments.

Vodafone owes over Rs 58,000 crore as AGR dues and so far, has paid close to Rs 7,000 crore.

Rohatgi contended before the court that the telecom company is in a tough situation, and cannot furnish any fresh bank guarantee, as profits have eluded the company in past many quarters. He submitted before the bench that Rs 15,000 crore bank guarantees are lying with the government, and his client's losses are over Rs 1 lakh crore.

"I cannot offer any more surety," he informed the bench.

Justice Mishra noted that this is public money and these dues should be recovered. "Do not tell us that you will pay if you were to make profits... the money must come," he noted.

Justice Shah observed that the telecom industry is the only industry which earned during the Covid-19 pandemic. "After all, this money will be used for public welfare", he said.

Rohatgi argued that his client would have to fold up if orders were issued to clear dues tomorrow. "11,000 employees will have to go without notice, as we cannot pay them," he added.

Senior advocate Abhishek Manu Singhvi, appearing for Bharti Airtel, contended before the court that out of Rs 21,000 crore AGR dues, the company has already deposited a sum of Rs 18,000 crore.

He argued that his client has given a bank guarantee, in excess of demand, to DoT, and supported the proposal for phased repayment of remaining AGR dues. He insisted that the company needs to sit down with the government and calculate the dues. Airtel owes Rs 25,976 crore after paying Rs 18,000 crore, as per the government.

Senior advocate Arvind Datar, representing Tata Telecom, informed the bench that his client has paid Rs 6,504 crore in AGR dues so far, and furnishing a bank guarantee may adversely impact investments in the sector.

The total AGR dues are close to Rs 1.5 lakh crore.

The top court will now take up the matter in the third week of July.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.