Live data from Hacker News

More than 1k Android apps harvest data even after you deny permissions

cnet.com

111–120 of 146 posts

Re: More than 1k Android apps harvest data even after you deny permissions

#111
post #4

Earlier quoted context omitted.

From the article: > The 1,325 apps that violated permissions on Android used workarounds hidden in its code that would take personal data from sources like Wi-Fi connections and metadata stored in photos. > Researchers found that Shutterfly, a photo-editing app, had been gathering GPS coordinates from photos and sending that data to its own servers, even when users declined to give the app permission to access locati…

> Researchers found that Shutterfly, a photo-editing app, had been gathering GPS coordinates from photos and sending that data to its own servers, even when users declined to give the app permission to access location data. One of the first things I disable when I have a new phone is geolocation being added to photos. I just don't want my location randomly being shared from an image without my consent. If I wanted yo…

It should be disabled by default, data that doesn't exist is data that can't stolen. Most people are also surprised that an image contains GPS co-ordinates and do not consider that something as simple as sharing a photo on the internet is giving away there home address.

Re: More than 1k Android apps harvest data even after you deny permissions

#112

Sandboxes are never safe. But man some of these bypasses are getting into evil genius level of shady cleverness.

Is it tho? or is the OS just too relaxed on security?

Think old Windows that people always ridicule, the publicity was rare on calling out bad practice/intentions, it has always been the fault of the OS.

Re: More than 1k Android apps harvest data even after you deny permissions

#113

Earlier quoted context omitted.

If the app can get around the permission system - it’s a vulnerability in Android itself that Google needs to correct.

To be fair, denying application knowledge of _device own_ MAC address is beyond absurd. If Google really wants that, they should buy their own MAC block, and regularly rotate the addresses within it when network is off. A lot of Android own APIs (such as Wi-Fi P2P and Bluetooth) are built on implicit assumption, that application developer knows MAC address of device it is running on. Instead of fixing those APIs, Goo…

An app developer being able to uniquely identify a device across applications has been considered a privacy violation for well over a decade. Even Microsoft in the Windows CE days made it hard for an app to uniquely identify a device.

Re: More than 1k Android apps harvest data even after you deny permissions

#114
post #5

> The update will address the issue by hiding location information in photos from apps and requiring any apps that access Wi-Fi to also have permission for location data, according to Google. The great minds at Google have done it again!! This craziness (Bluetooth requires location) was the reason I never bought a smartwatch. I guess now I should stop using internet too.

No, just stop using products made by shitty companies, but you won't do that, right ?

Re: More than 1k Android apps harvest data even after you deny permissions

#115
post #95

Earlier quoted context omitted.

Even Unity? Their CEO says half of all games are built on that. I imagine users would riot if most games were to simply disappear tomorrow. Or more likely, since it’s Android, the first thing everybody would do is switch to the App store that has all the software they want, even though they know it’s bad.

There's something a lot of people don't know about Unity the company - they are awful. Difficult to work with, constant rumors about managerial scapegoating, questionable sales tactics.. the recent news about the allegations against the CEO didn't surprise me in the slightest. I don't work with them closely, but I work with them closely enough that I've recommended that my employer cease all interaction with them, in…

I absolutely agree, and in my experience your list hardly scratches the surface. And awful not in the normal way that many large companies are awful.

Re: More than 1k Android apps harvest data even after you deny permissions

#116
post #93

Earlier quoted context omitted.

Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".

Yes. These are malware. It's disgusting.

Android and all google properties are malware, we just don't have a lot of good alternatives at the moment.

Re: More than 1k Android apps harvest data even after you deny permissions

#117
post #93

Earlier quoted context omitted.

Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".

Yes. These are malware. It's disgusting.

Belated edit: Anything that does something that you don't want, while pretending to be something that you do want, is malware. Especially if it goes out of the way to do that, evading limits, and hides what it's doing.

Re: More than 1k Android apps harvest data even after you deny permissions

#118
Phones and web browsers are not secure, not even a little tiny bit.

It is problematic that it is nearly impossible to go unidentified and untracked, constantly. IoT makes this so much worse because now nearly everything around you is constantly harvesting data, I am somewhat personally embarrassed about how little attention I have paid.

Re: More than 1k Android apps harvest data even after you deny permissions

#119

Earlier quoted context omitted.

To be fair, denying application knowledge of _device own_ MAC address is beyond absurd. If Google really wants that, they should buy their own MAC block, and regularly rotate the addresses within it when network is off. A lot of Android own APIs (such as Wi-Fi P2P and Bluetooth) are built on implicit assumption, that application developer knows MAC address of device it is running on. Instead of fixing those APIs, Goo…

An app developer being able to uniquely identify a device across applications has been considered a privacy violation for well over a decade. Even Microsoft in the Windows CE days made it hard for an app to uniquely identify a device.

The idea itself isn't bad, but Google's implementation of it is terrible. Good actors are forced to show security prompts, that literally scream "this application is malware!!". Bad actors enjoy ability to share MAC/IMEI/whatever with each other and skip whole "prompt for irrelevant permission" nonsense. They don't even particularly care about reading hardware addresses — why bother, when you can embed something like fingerprint.js and automatically identify every single device in existence!

If Google does not improve their P2P networking APIs, everyone may end up eventually integrating some Chinese spyware library, because it is the only approach that does not suck (and there is apparently no penalty for doing so).

Re: More than 1k Android apps harvest data even after you deny permissions

#120
post #26

[0] from the researchers pdf: • We designed a pipeline for automatically discovering vulnerabilities in the Android permissions system through a combination of dynamic and static analysis, in effect creating a scalable honeypot environment. • We tested our pipeline on more than 88,000 apps and discovered a number of vulnerabilities, which we responsibly disclosed. These apps were downloaded from the U.S. Google Play…

Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".

They don't have the will and the courage to ban Facebook/WhatsApp/Instagram from App Store.
Post reply on HN