Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
February 5,2020

New Delhi, Feb 5: AIMIM chief Asaduddin Owaisi on Wednesday expressed his suspicion over the government using force to clear the Shaheen Bagh stretch where an agitation has been ongoing for over 50 days against Citizenship Amendment Act (CAA).

While speaking to ANI over the phone, Owaisi was asked that there are indications from the government that after February 8, Shaheen Bagh will be cleared.

In reply, he said, "Might be they will shoot them, they might turn Shaheen Bagh into Jallianwala Bagh. This might happen. BJP minister gave a statement to 'shoot a bullet'. The government must give an answer as (to) who is radicalising."

Further speaking about NPR and NRC, Owaisi said, "Government must give a clear cut answer that till 2024 NRC will not be implemented. Why are they spending Rs 3900 crore for NPR? I feel this way because I was a History student. Hitler during his reign conducted census twice and after that, he pushed the jews in a gas chamber. I don't want our country (to) go in that way."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 5,2020

New Delhi, Feb 5: Kapil Baisala who opened fired at the Shaheen Bagh protest site last week is a member of the Aam Aadmi Party, police said on Tuesday, sparking a war of words between the BJP and the AAP.

While the BJP accused Chief Minister Arvind Kejriwal of "playing" with the security of the country, the AAP hit back, stating the saffron party was indulging "dirty politics".

Deputy Commissioner of Police (Crime Branch) Rajesh Deo said that Baisala and his father joined the AAP in early 2019.

Baisala's family, however, refuted the police's claim.

Kapil Baisala's uncle Fatesh Singh told PTI, "I have no idea where these photographs are circulating from. My nephew Kapil had no association with any political party nor does any other member from the family. My brother, Gaje Singh, (Baisala's father) fought assembly elections in 2008 on a Bahujan Samaj Party ticket and lost. After that no one from our family had any links with any political party."

Singh added that Baisala also doesn't have friends associated with the AAP or any other political party.

Gaje had also contested the 2012 civic body polls from the BSP, the police said.

The police officer said they seized Baisala's mobile phone and retrieved WhatsApp data.

On Saturday, Baisala fired two rounds in air at Shaheen Bagh. According to eyewitnesses, the man shouted "Hindu Rashtra Zindabad" and fired two rounds.

He was overpowered by the police and later arrested.

In the pictures, it was seen that he and his father joined the party in the presence of Atishi Marlena, Sanjay Singh and other leaders, sources said.

The police said on Thursday, Baisala, along with his friend Sarthak Larolla, went to Shaheen Bagh from his village on a bike.

Through CCTV footage, it was found they took the DND flyover, Maharani Bagh, Sarai Jullena and reached Holy Family hospital, a senior police officer said.

"Baisala was not comfortable on the bike as he had hidden the pistol near his waist. They entered the hospital's parking where he adjusted the pistol, used the washroom and headed towards Shaheen Bagh," the senior official added.

When they reached the protest site, Larolla left the spot with the motorcycle and Baisala's mobile phone. Later, Baisala fired two rounds in the air and was apprehended. The weapon was recovered from near the spot, the police said.

Larolla joined the investigation and the mobile phone was seized from his residence.

Baisala has been remanded to police remand for two days.

He had bought the pistol around seven years ago for his brother's marriage. The source of the weapon from where he procured it is yet to identified, police said.

The sources said Baisala was previously also involved in firing incident but was never caught nor was a case registered against him.

Hitting out at the AAP, BJP president J P Nadda accused Kejriwal of playing with the security of the country and said that the people will give the party a befitting reply.

"I want to make clear to Kejriwal that this country is bigger than any election, any government, and the country will not forgive those who play with its security. The people of Delhi will give a befitting reply," Nadda tweeted.

Senior AAP leader Sanjay Singh asked on whose directions was the Delhi Police accusing his party.

"Before the police revealed it (Baisala being an AAP member), how did BJP's Delhi president Manoj Tiwari come to know about it," Singh asked and accused the police of maligning the party.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 3,2020

Chennai, Mar 3: The Madras High Court has ruled that if a working woman gives birth to a child in the second delivery after twins in the first, she is not entitled to maternity benefits as it should be treated as third child.

"As per existing rules, a woman can avail such benefits only for her first two deliveries. Even otherwise it is debatable as to whether the delivery is not a second delivery but a third one, in as much as ordinarily when twins are born they are delivered one after another, and their age and their inter-se elderly status is also determined by virtue of the gap of time between their arrivals, which amounts to two deliveries and not one simultaneous act," the court said.

The first bench, comprising Chief Justice A P Sahi and Justice Subramonium Prasad stated this while allowing the appeal from Ministry of Home Affairs.

It set aside the order June 18 2019 order of a single Judge, who extended 180 days of maternity leave and other benefits to a woman member of the Central Industrial Security Force (CISF) under the rules governing the Tamil Nadu government servants.

The issue pertains to an appeal moved by the ministry, which contended that the leave claim is by a member of CISF to whom the maternity rules of Tamil Nadu would not apply.

She would be covered by the maternity benefits as provided under the Central Civil Services (Leave) Rules, the ministry said.

When the appeal came up for hearing, the bench said it found that a second delivery, which, in the present case, resulted in a third child, cannot be interpreted so as to add to the mathematical precision that is defined in the rules.

The admissibility of benefits would be limited if the claimant has not more than two children, the bench said "This fact therefore changes the entire nature of the relief which is sought for by the woman petitioner, which aspect has been completely overlooked by the single judge", the bench said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.