Mobile apps sharing usernames, passwords, credit card details with third parties: Study

Agencies
July 8, 2018

Washington, Jul 8: Some popular smartphone apps may be secretly taking screenshots of your activity and sending them to third parties, a study has found. This is particularly disturbing because these screenshots - and videos of your activity on the screen - could include usernames, passwords, credit card numbers, and other important personal information, researchers said.

"We found that thousands of popular apps have the ability to record your screen and anything you type," said David Choffnes, a professor at Northeastern University in the US.

"That includes your username and password, because it can record the characters you type before they turn into those little black dots," said Choffnes.

The study was designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.

While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.

"We knew we were looking for a needle in a haystack, and we were surprised to find several needles," said Choffnes.

What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasised how easily a phone's privacy window could be exploited for profit.

"This opening will almost certainly be used for malicious purposes," said Christo Wilson, a professor at Northeastern.

"It's simple to install and collect this information. And what's most disturbing is that this occurs with no notification to or permission by users," said Wilson.

"In the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers," he said.

The researchers analysed over 17,000 of the most popular apps on the Android operating system, using an automated test programme written by the students.

Although the study was conducted on Android phones, researchers said there is no reason to believe that other phone operating systems would be less vulnerable.

In all, 9,000 of the 17,000 apps had the potential to take screenshots.

"In one case, the app took video of the screen activity and sent that information to a third party," said Wilson.

That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.

Researchers emphasised that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.

However, that does not mean a malicious company could not use this privacy window to steal personal information for profit.

"That has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations. There is no easy way to close this privacy opening," said Choffnes.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 5,2024

karkare.jpg

Maharashtra Leader of Opposition Vijay Namdevrao Wadettiwar waded into controversy after he alleged that an RSS-affiliated cop, and not terrorist Ajmal Kasab, killed former state anti-terrorism squad (ATS) chief Hemant Karkare during the 26/11 Mumbai terror attack.

In a video statement released on Saturday, the Congress leader alleged that the bullet that killed IPS officer Hemant Karkare did not come from the gun of Ajmal Kasab or any of the other nine Pakistani terrorists involved in the attacks.

Instead, he claimed it came from the weapon of a police officer allegedly "dedicated to" the Rashtriya Swayamsevak Sangh (RSS).

Wadettiwar also accused Ujjwal Nikam, the special public prosecutor in the case and a BJP Lok Sabha candidate from Mumbai North Central, of suppressing this information, labeling him a "traitor."

He questioned the BJP's decision to nominate Nikam for the Lok Sabha polls, accusing the party of protecting traitors.

“During the probe, key information was out. However, it was suppressed by Ujjwal Nikam, who is a traitor. My question is, why is BJP protecting a traitor and nominating such a person for Lok Sabha polls? By doing this, BJP is protecting traitors," Wadettiwar alleged, Times of India reported.

These allegations drew strong responses from Nikam and Deputy Chief Minister Devendra Fadnavis.

Nikam condemned Wadettiwar's statement as "baseless and irresponsible," expressing pain at the doubts raised over his integrity.

He emphasized the legal steps taken to convict Kasab, calling Wadettiwar's remarks an insult to the victims of the 26/11 attacks.

“What a reckless statement is being made. I am pained by such baseless allegations, raising doubts over my integrity. It clearly reflects the level of electoral politics. I never thought politicians will stoop to such low levels. For political gain? He (Wadettiwar) is insulting not me, but the 166 departed souls and all persons injured in the 26/11 attacks," Nikam said.

He added, “They (Congress) hold Kasab as innocent. Even Pakistan had accepted that Kasab was involved in the conspiracy and in the terror attack on India and was guilty".

He said Indians very well know the legal steps he had taken to ensure Kasab’s conviction.

Nikam said citizens of the nation would on 4 June, the day of results for Lok Sabha polls, give their reply to such allegations, adding he wished not to dignify the “desperate disinformation” with a further response.

Meanwhile, BJP leader and Deputy CM Fadnavis said, “Our alliance is with Nikam, while Congress has joined hands with Kasab".

Shiv Sena spokesperson Kiran Pawaskar said NIA should arrest Wadettiwar and ask him why he was defending Kasab.

Pawaskar criticized the Congress for allegedly supporting terrorists and expressed surprise at the silence of Shiv Sena chief Uddhav Thackeray on the matter.

“From Wadettiwar’s statement, it appears Congress is supporting terrorists who attacked Mumbai. More shocking is the fact that Sena (UBT) chief Uddhav Thackeray has maintained silence over the episode,” he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 24,2024

modiliar.jpg

Ambikapur (Chhattisgarh): Prime Minister Narendra Modi on Wednesday hit out at the Congress, saying the 'vote bank hungry' party wanted to implement reservation on the basis of religion.

Addressing a poll rally in Ambikapur, the headquarters of Surguja district in Chhattisgarh, PM Modi also said the Congress wanted to impose inheritance tax in the country and snatch the rights of people's children.

Some forces want a "weak" government of the Congress and "I.N.D.I." alliance in the country as they thought that if India becomes 'atmanirbhar' (self-reliant), their shops will be shut, he said.

"Today when I have come to Surguja, I want to present the Muslim League thinking of the Congress in front of the country. When their manifesto was released, on the same day I had said, and saying today also that the Congress manifesto has the imprint of Muslim League," Modi said.

When the Constitution was being drafted, it was decided under the leadership of Babasaheb Ambedkar that there would be no reservation on the basis of religion in India, he said.

"If there will be reservation then it will be for by Dalit brothers and sisters and tribal brothers and sisters," he said.

"But the vote bank hungry Congress never cared about the words of the great personalities, sanctity of the Constitution and the words of Babasaheb Ambedkar. Years ago, the Congress made an attempt to implement reservation on the basis of religion in Andhra Pradesh. Then Congress has planned to implement it in the entire country," Modi said.

They talked about implementing 15 per cent reservation on the basis of religion and said it will be done after curtailing the quota of the Scheduled Castes, Scheduled Tribes and Other Backward Classes, he added.

In its 2009 manifesto, Congress's intention was the same and in the 2014 manifesto, it clearly said it will not leave this issue, the prime minister said.

The Congress wanted to change the Constitution and hand over rights of the SCs, STs and OBCs to its vote bank, he said.

The intention of the Congress is not good, it is not according to the Constitution, social justice and secularism. If anyone can protect your reservation, it is the BJP, Modi said.

"The Congress's eyes are not only on your reservation, but also on your earnings, your houses, shops and farms. The 'shehzada' of Congress (apparently referring to Rahul Gandhi) says they will conduct an X-ray of the property of every house and every family in the country. The Congress will snatch all these from you and they say that they will equally distribute them," he said.

Do you know to whom they will distribute it after 'looting' it from you? Modi asked, to which the people replied in affirmative.

"I need not to tell you to whom they will distribute," he added.

Modi further said the 'dangerous intentions' of Congress are coming to forth one by one and now it says it will impose inheritance tax.

"The advisor of shehzada of the shahi parivar, who was also the advisor to the shehzada's father, had said that more tax should be imposed on the middle class and those who earn by toiling hard. Now the Congress says it will impose inheritance tax. It will impose tax on the assets inherited by people from their parents. Now, the panja (Congress poll symbol) will snatch the assets from your children," he said without taking any name.

The Congress' mantra is 'loot of Congress zindagi ke sath bhi, zindagi ke baad bhi', he said.

"They (Congress) want to snatch your assets and rights of your children," Modi added.

The PM also said he had come to seek people's blessings for a developed Chhattisgarh and a developed India.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 4,2024

Mangaluru, May 4: The Mangaluru International Airport was besieged with a harrowing message of terror recently, when an email, purportedly from malevolent elements, menacingly declared the planting of bombs within the airport premises. 

Addressed to the office of the airport authority, the missive, steeped in ominous overtones, bore the ominous signature of a terrorist faction, ominously named 'Terrorizers 111'.

The communication, disseminated in English, ominously detailed the clandestine emplacement of explosives in areas eluding facile detection, accompanied by a chilling warning of their imminent detonation. The threat, ominously looming over not only the infrastructure but also the airborne vessels, portended a catastrophic deluge of bloodshed and loss.

In response to this dire communiqué, airport authorities swiftly engaged the apparatus of law enforcement, dispatching urgent alerts to the vigilant guardians of public safety. Acting upon the dictates of higher echelons, a formal dossier of this menacing correspondence was meticulously compiled, cloaked in the veil of confidentiality to thwart any premature dissemination.

Mangaluru International Airport found itself in grim camaraderie with more than 30 counterparts under the aegis of the Airport Authority of India (AAI) and private domains, all recipients of this chilling electronic diatribe. A comprehensive net of precautionary measures was swiftly cast, fortifying the bastions of security in anticipation of any nefarious designs lurking within the shadows.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.