Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 25,2024

EVM.jpg

Electronics Corporation of India Ltd and Bharat Electronics Ltd have refused to disclose the names and contact details of the manufacturers and suppliers of various components of EVMs and VVPATs under the RTI Act citing "commercial confidence", according to RTI responses from the PSUs to an activist.

Activist Venkatesh Nayak had filed two identical Right To Information applications with the ECIL and BEL, seeking the details of the manufacturers and suppliers of various components used in the assembling of the electronic voting machines (EVMs) and voter-verifiable paper audit trail (VVPATs).

The VVPAT is an independent vote verification system which enables electors to see whether their votes have been cast correctly.

The ECIL and the BEL, public sector undertakings under the Ministry of Defence, manufacture EVMs and VVPATs for the Election Commission.

Nayak also sought a copy of the purchase orders for the components from both PSUs.

"Information sought is in commercial confidence. Hence details cannot be provided under Section 8(1)(d) of the RTI Act," BEL said in its response.

A similar response was sent by ECIL which said the details requested are related to a product which is being manufactured by ECIL, and third party in nature.

"Disclosing of details will affect the Competitive position of ECIL. Hence, Exemption is claimed under section 8(1) (d) of RTI ACT, 2005," it said.

In response to the purchase order copies, ECIL's central public information officer said the information is "voluminous" which would disproportionately divert the resources of the Public Authority.

"Further, the information will give away the design details of EVM components. The same may pose a danger to the machines produced. Hence, the exemption is claimed U/s 7(9) and under section 8(1)(d) of RTI Act, 2005," ECIL said.

Section 8(1)(d) of the RTI Act exempts from disclosure the information, including commercial confidence, trade secrets or intellectual property, the disclosure of which would harm the competitive position of a third party, unless the competent authority is satisfied that larger public interest warrants the disclosure of such information.

Section 7(9) of the Act says the information shall ordinarily be provided in the form in which it is sought unless it would disproportionately divert the resources of the public authority or would be detrimental to the safety or preservation of the record in question.

"I don't know whose interests they are trying to protect against the right to know of close to a billion-strong electorate. ECIL said that disclosure of the purchase orders will reveal the design details of the components and this may pose a danger to the machines produced. ECIL did not upload even a signed copy of its reply on the RTI Online Portal," Nayak said.

He said it is reasonable to infer that the two companies are not manufacturing every single item of the EVM-VVPAT combo or else the two companies would have replied that they are manufacturing all these components internally without any outsourcing being involved.

"But the electorate is expected to take everything about the voting machines based on what the ECI is claiming in its manuals and FAQs," Nayak said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 24,2024

columbia.jpg

Pro-Gaza US protesters in New York's Columbia University say they will stay put despite the university's harassment and police crackdown.

The protesters said they refuse to concede to "cowardly threats and blatant intimidation" by university administration, asserting that they will continue to peacefully protest.

Columbia University threatened the students with the national guard after refusing to bargain in good faith.

The university announced a midnight deadline for talks regarding the removal of pro-Palestine encampments on the varsity campus, warning that their campsite will be forcefully cleared by police if no agreement is reached.

The university campus is being used as a campsite for hundreds of pro-Palestine protesters and other activists, who have gathered and set up numerous tents.

Pro-Palestinian protests at colleges have demanded that their universities divest from corporations doing business with Israel or profiting off the war in Gaza. At Columbia, protesters have also asked the university to end a dual-degree program with Tel Aviv University.

The deadline was announced by Columbia University President Minouche Shafik late Tuesday, as authorities across major American universities have launched their repression campaigns against the pro-Palestinian protests on campuses, amid rising anger over US's support for Israel. 

Shafik has issued a midnight deadline to protesters and organizers, warning that failure to comply will result in the forcible clearance of the camp by the New York Police Department (NYPD).

The university has engaged in discussions with student leaders behind the protests, which are part of a series of protests taking place at various colleges nationwide and resulting in multiple arrests.

The purpose of these talks is to address the encampment on the west lawn of Columbia's Morningside Heights campus.

American universities are grappling with the challenge of maintaining a delicate balance between the right to protest and freedom of speech, while also ensuring campus rules and safety, as tensions surrounding the ongoing war in Gaza continue to permeate across campuses.

Meanwhile, Shafik underscored the importance of free speech and the right to demonstrate, but highlighted significant safety issues, disruptions to campus activities, and a strained environment due to the encampment. She firmly stated that any form of intimidation, harassment, or discrimination would not be accepted.

The arrest of more than 100 protesters at Columbia University last week led to more campus demonstrations, at New York University, Yale, and the University of California, Berkeley.

Palestinian university professor Sami al-Arian said what is happening across US university campuses is unprecedented.

Al-Arian said, "I lived four decades in the US, 28 years of which were in academic settings. During my time, it was a very challenging struggle to present an anti-Zionist narrative."

"But the passion, courage, humanity, creativity, and determination displayed these days by students across US campuses make me proud. The Zionist grip on US society is weakening and waning."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 5,2024

kangana.jpg

New Delhi, May 5: Actor-turned-politician Kangana Ranaut intended to target an opposition leader but mistakenly ended up attacking her BJP colleague instead. 

A similarity in names - Tejashwi and Tejasvi - was behind Ms Ranaut's fumble. "There's a party of spoilt princes... whether it's Rahul Gandhi who wants to grow potatoes on the Moon, or Tejasvi Surya who does hooliganism and eats fish," she had said.

RJD leader and former Bihar deputy Chief Minister Tejashwi Yadav was supposed to be the original target of her diatribe as one of his videos where he was seen eating fish became a major flashpoint between the BJP and the opposition recently.

Tejasvi Surya, incorrectly referred to by Ms Ranaut during an election rally yesterday, is BJP's Lok Sabha candidate from Bengaluru South constituency in Karnataka.

Meanwhile, Mr Yadav has responded to a clip of Kangana Ranaut's statement. "Ye mohtarma kaun hai?" (Who is this lady?), he posted on X.

Kangana Ranaut has been verbally bashing the Congress party since the BJP fielded her as their Lok Sabha candidate from Himachal Pradesh's Mandi. Congress leaders Vikramaditya Singh - her opponent in Mandi - and Rahul Gandhi have been the main targets on her dartboard.

While addressing a public rally in the Sundernagar area of Mandi Parliamentary Constituency yesterday, Ms Ranaut took a jibe at Mr Singh and Mr Gandhi over dynasty politics and said that both of them have a magic stick for development and talk only about non-practical things.

The Congress hit back saying the 37-year-old actor should first check the facts about her party leaders and speak about dynastic politics. National Media Coordinator for the Congress, Amrit Kaur, also questioned her qualifications on which she got a BJP ticket from Mandi.

The Mandi Lok Sabha constituency will go to polls on June 1, in the seventh phase of the 2024 Lok Sabha elections.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.