Many Android apps pose privacy threat, says security vendor
IDG News Service - As many as 20% of applications on Android Market let third parties access private or sensitive information, according to a report from security vendor SMobile Systems.
SMobile, which develops software for protecting smartphones, has performed an analysis of over 48,000 applications available on Android Market, and looked at what permissions are granted to the application by the mobile operating system.
The permissions -- which allow applications to do a multitude of things, including initiating a phone call, reading SMS (Short Message Service) messages or identifying the phone's location -- are there to help people develop useful applications. But applications might also access those kinds of personal data for nefarious purposes, according to SMobile.
In addition, some 5% of Android apps can be used to place a call to any number, and 2% of applications can send an SMS to an unknown premium number, in both cases without user involvement.
A majority of these applications were developed with the best of intentions and the user data will likely not be compromised, according to SMobile. But there have been cases of the opposite: A bank phishing application that was published by an author by the name of Droid09 was found and removed from Android Market, it said.
Android's security model requires that applications declare the permissions they will be using prior to installation by the user. An informed user can use these declarations to decide if they want to install an application or not, according to SMobile. However, the fact remains that there is no means available for a user to know for sure that the application they just downloaded is doing only what the user sees it doing, it said.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- Data Protection and Disaster Recovery with iSCSI and VMware Get this on demand webcast now
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable... All Privacy White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!