Follow Slashdot stories on Twitter


Forgot your password?
Privacy Android Security Software Your Rights Online

More Than 25% of Android Apps Know Too Much About You 277

CowboyRobot writes "A pair of reports by Juniper and Bit9 confirm the suspicion that many apps are spying on users. '26 percent of Android apps in Google Play can access personal data, such as contacts and email, and 42 percent, GPS location data... 31 percent of the apps access phone calls or phone numbers, and 9 percent employ permissions that could cost the user money, such as incurring premium SMS text message charges... nearly 7 percent of free apps can access address books, 2.6 percent, can send text messages without the user knowing, 6.4 percent can make calls, and 5.5 percent have access to the device's camera.' The main issue seems to be with poor development practices. Only in a minority of cases is there malicious intent. The Juniper report and the Bit9 report are both available online."
This discussion has been archived. No new comments can be posted.

More Than 25% of Android Apps Know Too Much About You

Comments Filter:
  • Re:If only! (Score:5, Interesting)

    by rvw ( 755107 ) on Friday November 02, 2012 @10:23AM (#41852705)

    If only there were some way for me to tell which permissions an app will use when I install it!

    I've created one Hello World app, just to see how it works. I've followed directions, didn't do anything to snoop around. The result is that it needs Phone ID somehow. I suspect that many app programmers do nothing to snoop around, but automatically request more permissions than actually needed, probably because the programming IDE does this automatically.

  • Re:If only! (Score:5, Interesting)

    by h4rr4r ( 612664 ) on Friday November 02, 2012 @10:25AM (#41852731)

    You don't. Torch, Done.

    What Google should do is let me search for apps by permissions. I also wish they would let me never see a freemium app again. I have zero interest in them.

  • by e065c8515d206cb0e190 ( 1785896 ) on Friday November 02, 2012 @10:27AM (#41852753)

    We need a website listing apps and what persmissions they require vs use.

    Developers will start paying attention when their apps are publicly shamed.

  • Yeah (Score:4, Interesting)

    by errandum ( 2014454 ) on Friday November 02, 2012 @10:36AM (#41852835)

    That study is irrelevant. Most of those apps don't know that because they need to, but because they are free and the averts do.

    Do the same study on payed apps. For example, GPS location access is not present on any of the games I bought so far.

  • Re:If only! (Score:5, Interesting)

    by TheGratefulNet ( 143330 ) on Friday November 02, 2012 @10:40AM (#41852887)

    permissions are vague. I can't know what the hell they plan to do!

    what I'd want is a watcher that gives pop-ups or some notification and STOPS THE APP until I let it thru. very very fine grained permit/deny and also a lot of all info that is captured and sent.

    until the apps are more transparent (they are anything but, now!) I refuse to run most android 'store' apps or anything else.

    the whole market is fucked up; the protection model is bullshit and there's no audit ability for users to feel confident that this or that app is not doing funny shit behind the owner's back.

    the permissions model is quite stupid by design. another google design failure, designed by engineers and not designed FOR users who are non-tech and simply want to know what the app is DOING.

    there also isn't a standard default firewall on unrooted android. again, I have no trust in android when I have to go around it and root it just to have a firewall and user filters or ACL's.

    the whole model needs a serious rewrite. not saying the apple model is any better, but android is quite immature in how it DOES NOT protect the user or give them any real info to go on. the only thing you have now is 'trust us' and, well, I just don't!

    vista annoyed users with the popups but I do think that some level of that is needed, here. WHEN an app tries to do things that fit some trigger, show me! show me what and when and where. keep logs of it. let me query the logs and study how good or bad this app is. let me run it in 'hobble mode' so that it, by default, does not get access to anything. let me trust it over time and relax restrictions as it gets my trust.

    the whole model is all wrong. sorry, but it seems no one was thinking of the users, here. and users are getting screwed by not having true visibility into the (often) evils that 'flashlight apps' do.

  • by TheGratefulNet ( 143330 ) on Friday November 02, 2012 @10:47AM (#41852987)

    one that is the smartphone (portable computer) and that will not have sms, cell service, address book, etc. rooted and firewalled and monitored.

    2nd phone would be a dumb phone that has no networking at all in it, simply just to send and receive voice calls.

    until there is a hard boundary (enforced, like a true barrier) between the soft apps and things that can cost you money (dialing out, stealing your contact list or local data), it just does not seem worth it to bundle all your stuff into one box.

    sure, its convenient but the trust model is not good enough.

    more and more, I just leave the smartphone home and use it as a wifi only device. at least I know that no sms BS is coming thru and no outgoing calls or wan connects could ever happen that would be costly or info-leaking.

    seriously, I'm demotivated to invest more of my personal info on a box that I have less and less control over.

  • Re:If only! (Score:3, Interesting)

    by Syphonius ( 11602 ) on Friday November 02, 2012 @10:58AM (#41853143) Homepage

    Then you may have done it wrong (or whatever example you followed was wrong). The default IDE (Eclipse with the ADK plugin) does not generate permissions into the manifest. They all go in manually. If your Hello, World required extra permissions then they were most likely added by accident or you are using some uncommon IDE/plugin.

"Ninety percent of baseball is half mental." -- Yogi Berra