Risk
4/5/2011
02:41 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Feds Probe Mobile App Privacy

Pandora, an online music service, got hit with a subpoena that appears to be part of an investigation into the information sharing processes of apps that run on Apple and Android mobile platforms.

Best Mobile Apps For Busy Professionals
(click image for larger view)
Slideshow: Best Mobile Apps For Busy Professionals
Federal prosecutors in New Jersey are investigating how mobile apps use personal data, according to an unnamed source cited in a story by the Wall Street Journal.

A spokesperson for the Office of the U.S. Attorney in New Jersey declined to comment, citing a policy of not discussing any ongoing investigation.

But on Monday, Pandora, an online music service that distributes mobile music apps, confirmed that earlier this year it had been "served with a subpoena to produce documents in connection with a federal grand jury, which we believe was convened to investigate the information sharing processes of certain popular applications that run on the Apple and Android mobile platforms."

Pandora revealed that it had received the subpoena in a financial filing with the SEC. The company noted that while it was not a specific target in the investigation, it could nonetheless incur costs to comply with the subpoena and might be dragged into litigation.

The revelation follows a series of reports by the Wall Street Journal about online privacy. In October, the paper found that the 10 most popular Facebook apps were sending Facebook UIDs (user IDs) to at least 25 data collection and advertising firms. In December, it found that 56 out of 101 popular smartphone apps transmitted the phone's unique device ID number without consent and that almost as many transmitted location data.

These findings have piqued the interested of regulators at the Federal Trade Commission and the Department of Justice and have prompted at least one lawsuit already.

The Federal Trade Commission has been backing a do-not-track proposal and legislators like Senator Jay Rockefeller say that basic privacy rules are necessary. In all likelihood, the era of self-regulation for mobile and online apps will soon end.

While privacy rules may provide a framework to punish those acting in bad faith, they're not likely to ensure individual privacy. Without a complete source code review by a third-party -- something that's not likely to happen -- it's relatively easy for an ill-intentioned developer to spirit information out of a user's phone. A simple method would be to cache sensitive data and transmit it, perhaps in encrypted or obfuscated form, a month or two after installation.

Even with a mobile operating system like Android, which requires users to authorize network access in apps, the fundamental problem is that personal and financial data be used both legitimately and illegitimately and it's not always possible to divine intent from raw data.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?