Beware the apps you download

It irks me when you download something like a calculator app or a simple game that requires permissions to almost everything on the phone. Usually end up declining it and looking for something else if possible.
Don’t download apps from third party sites – stick to Apple, Google Play or the device manufacturer – Samsung’s app store for instance.
And XDA-DEVELOPERS.com :p
 
Don’t download apps from third party sites – stick to Apple, Google Play or the device manufacturer – Samsung’s app store for instance.

In the December holidays I wrote a few apps to see how the Play Store publishing works. You can submit anything, nothing is checked by Google. To assume everything is safe there is a mistake.
 
Sorry to burst your bubble this was already revealed nearly a year ago at ZaCon V, I was there and I was a speaker too.
 
The users of the Windows Phone/Apple OS at least have the protection of the Windows Store/Apple Store vetting of apps before being published, contrary to the Android Store which is "open source" without any vetting controls. This fact is so often forgotten when the sales boys fool their customers in buying Android OS devices.
 
Last edited:
The users of the Windows Phone/Apple OS at least have the protection of the Windows Store/Apple Store vetting of apps before being published, contrary to the Android Store which is "open source" without any vetting controls. This fact is so often forgotten when the sales boys fool their customers in buying Android OS devices.

Some people prefer the unstructured environment of Android. I guess its the usual "it will never happen to me" or "I'm too smart to download a dodgy app".

Btw, its still possible that these apps which are designed to comprise your data can be placed on the Apple or Windows store. Less likely, but still possible.

This recent test was able to hack Gmail accounts on Android phones with 92% success rate. Although they did not try with iOS or Windows phones, they believe its possible. So much for java sandbox.
http://www.bbc.co.uk/news/technology-28895304
US researchers say they have been able to hack into Gmail accounts with a 92% success rate by exploiting a weakness in smartphone memory.

The researchers were able to gain access to a number of apps, including Gmail, by disguising malicious software as another downloaded app.

Gmail was among the easiest to access from the popular apps tested.

The hack was tested on an Android phone, but the researchers believe it could work on other operating systems.

A Google spokeswoman said the technology giant welcomed the research. "Third-party research is one of the ways Android is made stronger and more secure," she said.

The research is being presented later at a cybersecurity conference in San Diego by academics from the universities of Michigan and California.

Other apps hacked included H&R Block, Newegg, WebMD, Chase Bank, Hotels.com and Amazon.

Passwords stolen
The Amazon app was the hardest to access, with a 48% success rate.

The hack involves accessing the shared memory of a user's smartphone using malicious software disguised as an apparently harmless app, such as wallpaper.

This shared memory is used by all apps, and by analysing its use the researchers were able to tell when a user was logging into apps such as Gmail, giving them the opportunity to steal login details and passwords.

"The assumption has always been that these apps can't interfere with each other easily," said Zhiyun Qian, an assistant professor at the University of California and one of the researchers involved in the study.

"We show that assumption is not correct, and one app can in fact significantly impact another and result in harmful consequences for the user."

In another example the researchers were able to take advantage of a feature of the Chase Bank app which allows customers to pay in cheques by taking pictures of them with their device's camera.

The researchers were able to access the camera to steal the pictures as they were being taken, giving them access to personal information including signatures and bank details.

The tests were carried out on Android phones, but the researchers believe the attacks could be successful on other operating systems, including Windows and the iOS system developed by Apple.
 
The users of the Windows Phone/Apple OS at least have the protection of the Windows Store/Apple Store vetting of apps before being published, contrary to the Android Store which is "open source" without any vetting controls. This fact is so often forgotten when the sales boys fool their customers in buying Android OS devices.

The dodgy apps are extremely easy to spot, and are seldom top ranked when searching for stuff.
 
I just scan the app before loading it. Plasystore has an option to check the app before loading it as well. If humans made it, humans can cracking it.
 
So many apps nowadays ask for so many permissions that are not relevant to their intended purpose. Even apps from legit publishers sometimes ask for puzzling permissions. I like the Apple way of keeping things in check, eg if an app requires certain permissions like access to photos, the app still has to ask for your permission even after installation
 
So many apps nowadays ask for so many permissions that are not relevant to their intended purpose. Even apps from legit publishers sometimes ask for puzzling permissions. I like the Apple way of keeping things in check, eg if an app requires certain permissions like access to photos, the app still has to ask for your permission even after installation

If a less than popular app needs too many permissions then it's best not to install. For popular 'legit' apps, publishers often explain the permissions in the description.
 
xposed > xprivacy

This is really an amazing module! :)
 
I don't trust having a banking app on my primary smartphone which also receives OTPs.
All your eggs are in one basket for a hacker/keylogger.

A second smartphone with just the banking app is a much better idea. OTPs go to one device and banking app runs on the other.
 
Top
Sign up to the MyBroadband newsletter
X