Earlier quoted context omitted.
From the article: > The 1,325 apps that violated permissions on Android used workarounds hidden in its code that would take personal data from sources like Wi-Fi connections and metadata stored in photos. > Researchers found that Shutterfly, a photo-editing app, had been gathering GPS coordinates from photos and sending that data to its own servers, even when users declined to give the app permission to access locati…
> Researchers found that Shutterfly, a photo-editing app, had been gathering GPS coordinates from photos and sending that data to its own servers, even when users declined to give the app permission to access location data. One of the first things I disable when I have a new phone is geolocation being added to photos. I just don't want my location randomly being shared from an image without my consent. If I wanted yo…
More than 1k Android apps harvest data even after you deny permissions
111–120 of 146 posts
Re: More than 1k Android apps harvest data even after you deny permissions
#112Sandboxes are never safe. But man some of these bypasses are getting into evil genius level of shady cleverness.
Think old Windows that people always ridicule, the publicity was rare on calling out bad practice/intentions, it has always been the fault of the OS.
Re: More than 1k Android apps harvest data even after you deny permissions
#113Earlier quoted context omitted.
If the app can get around the permission system - it’s a vulnerability in Android itself that Google needs to correct.
To be fair, denying application knowledge of _device own_ MAC address is beyond absurd. If Google really wants that, they should buy their own MAC block, and regularly rotate the addresses within it when network is off. A lot of Android own APIs (such as Wi-Fi P2P and Bluetooth) are built on implicit assumption, that application developer knows MAC address of device it is running on. Instead of fixing those APIs, Goo…
Re: More than 1k Android apps harvest data even after you deny permissions
#114> The update will address the issue by hiding location information in photos from apps and requiring any apps that access Wi-Fi to also have permission for location data, according to Google. The great minds at Google have done it again!! This craziness (Bluetooth requires location) was the reason I never bought a smartwatch. I guess now I should stop using internet too.
Re: More than 1k Android apps harvest data even after you deny permissions
#115Earlier quoted context omitted.
Even Unity? Their CEO says half of all games are built on that. I imagine users would riot if most games were to simply disappear tomorrow. Or more likely, since it’s Android, the first thing everybody would do is switch to the App store that has all the software they want, even though they know it’s bad.
There's something a lot of people don't know about Unity the company - they are awful. Difficult to work with, constant rumors about managerial scapegoating, questionable sales tactics.. the recent news about the allegations against the CEO didn't surprise me in the slightest. I don't work with them closely, but I work with them closely enough that I've recommended that my employer cease all interaction with them, in…
Re: More than 1k Android apps harvest data even after you deny permissions
#116Earlier quoted context omitted.
Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".
Yes. These are malware. It's disgusting.
Re: More than 1k Android apps harvest data even after you deny permissions
#117Earlier quoted context omitted.
Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".
Yes. These are malware. It's disgusting.
Re: More than 1k Android apps harvest data even after you deny permissions
#118It is problematic that it is nearly impossible to go unidentified and untracked, constantly. IoT makes this so much worse because now nearly everything around you is constantly harvesting data, I am somewhat personally embarrassed about how little attention I have paid.
Re: More than 1k Android apps harvest data even after you deny permissions
#119Earlier quoted context omitted.
To be fair, denying application knowledge of _device own_ MAC address is beyond absurd. If Google really wants that, they should buy their own MAC block, and regularly rotate the addresses within it when network is off. A lot of Android own APIs (such as Wi-Fi P2P and Bluetooth) are built on implicit assumption, that application developer knows MAC address of device it is running on. Instead of fixing those APIs, Goo…
An app developer being able to uniquely identify a device across applications has been considered a privacy violation for well over a decade. Even Microsoft in the Windows CE days made it hard for an app to uniquely identify a device.
If Google does not improve their P2P networking APIs, everyone may end up eventually integrating some Chinese spyware library, because it is the only approach that does not suck (and there is apparently no penalty for doing so).
Re: More than 1k Android apps harvest data even after you deny permissions
#120[0] from the researchers pdf: • We designed a pipeline for automatically discovering vulnerabilities in the Android permissions system through a combination of dynamic and static analysis, in effect creating a scalable honeypot environment. • We tested our pipeline on more than 88,000 apps and discovered a number of vulnerabilities, which we responsibly disclosed. These apps were downloaded from the U.S. Google Play…
Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".