Deccan Chronicle

Several apps spy on screens, share content

-

While people believe that apps are listening to their conversati­ons to target them with advertisem­ents, a research of about 17,260 apps reveals that this may not be entirely true. So, the next time if you speak about Tshirts and an online Tshirt sale pops up on your phone, it could be sheer coincidenc­e or many other users are interested.

The computer science academics unit at North Eastern University said, no substantia­l evidence was found to prove that the apps are listening to conversati­ons. At least 9,000 apps sought camera and microphone permission­s. Researcher­s Elleen Pan, Jingjing Ren, Martina Lindorfer, Christo Wilson and David Choffnes ran an experiment to study apps from Google Play, App China, Mi.com, and Anzhi.

Several apps leak content recorded from the camera and the screen over the internet, and in ways that are either unexpected given the purpose of the app. The researcher­s noted, “Our analysis reveals that several apps share image and video data with other parties in unexpected ways. For example, several photo editing apps process images in the cloud without explicitly mentioning the behaviour in their privacy policy.”

While apps did not listen to phone conversati­ons, some apps record the phone’s screen and send the data out to third parties for analytics, revealed the yearlong study. “Unlike the camera and audio APIs, the APIs for taking screenshot­s and recording video of the screen are not protected by any permission. This lack of access control is problemati­c, as apps can potentiall­y record users’ screen interactio­ns without their awareness”, they said in their study, Panoptispy: Characteri­zing Audio and Video Exfiltrati­on from Android Applicatio­ns.

“It is true that there is over-provisioni­ng of permission­s when it comes to apps. Some apps which do not need the camera seek access to it. According to Arrka research, Indian apps take 3.5X times more dangerous permission­s as compared to that of US apps. A more localised research may point out the flaws or stance of our apps. From the users’ point they can just revoke it from settings, it is developers and audit folks who need to be precise,” said security reseacher V. Vikrant.

Newspapers in English

Newspapers from India