Risk
7/8/2013
05:00 PM
50%
50%

Google Android Vs. Apple iOS: The Mobile App Privacy War

Ever wonder which smartphone has the most apps with the least respect for your privacy? The answer may surprise you

New research from BitDefender shows that applications for Apple iOS and Google Android may have their digital eyes and hands on more user data than you think.

Using their Clueful app, researchers at BitDefender examined how apps for Android and Apple's iOS treated private data, such as location information and contact lists. What they found may seem startling -- of the 207,843 free applications for iOS, 45.41 percent have location-tracking capabilities, whether they used them or not. Of the 314,474 free applications for Android, the percentage was 34.55.

When it comes to having the ability to read contact lists, the numbers were 7.69 percent for Android and 18.92 percent for apps designed for iOS. An iOS app called "3D Badminton II" (v. 2.026), for example, reads contacts' emails and sends them to a server in Hong Kong.

"Among the most interesting pieces of information for an advertising network are e-mail addresses and unique device IDs/IMEI," according to the report. "This data also may be shared with third parties to, for example, send consumers behaviorally targeted advertisements, according to a recent Federal Trade Commission report."

"About 14.58% of the Android applications may leak your Device ID and 5.73% of the total number of apps may leak your e-mail," the researchers note. "Again, iOS applications appear to be more focused on harvesting private data than those designed for Android."

Some examples for iOS include Ringtone Maker version 1.7, which sends the device ID to "adfonic.net," and 'aradise Island: Exotic (v. 1.3.14), which sends the device ID to a number of third-party websites. Meanwhile, an Android app called Logo Quiz Car Choices (v. 1.8.2.9) shares email addresses, the researchers found.

"Most people do not pay attention to the permissions required by the application they are about to install for a variety of reasons," observes Bogdan Botezatu, senior e-threat analyst at BitDefender. "They may not realize that those permissions are important in any way for the security of their device. They may not understand what each permission means and how it impacts the security of the terminal, or may not have other options but to accept the permissions if they want that application to run on their device. This is actually one of the most important shortcomings of Android -- the fixed permission model that asks you to go all in with the permissions or else you're not going to be able to run that application."

Android security has been in the spotlight during the past few days, as vendor Bluebox Security announced plans to release details of a serious Android vulnerability exploit at the upcoming Black Hat security conference in Las Vegas. According to Bluebox Security, the vulnerability involves discrepancies in how Android applications are cryptographically verified and installed, enabling a bad actor to modify APK code without breaking the cryptographic signature. The vulnerability only comes into play, however, in the case of applications downloaded from third-party app markets.

"Although this loophole has been present in Android devices since 2009 and is yet to be exploited by cyberthieves, the 'master key' is a major concern for consumers and also businesses, which are increasingly reliant on mobile devices for work and, moreover, accessing company data," says Grayson Milbourne, security intelligence director at Webroot. "An attacker being able to steal data or eavesdrop on calls or emails is clearly a major problem."

Judging by the extremely small number of malware incidents in the past years, most people would probably consider iOS much safer than Android, says Botezatu. However, this does not appear to be the case when it comes to privacy issues.

"We have two distinct operating systems that work differently and are built differently, and, yet, they attempt to get to the same kind of user information, as long as access to it is permitted by the application market," he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
bgarlock
50%
50%
bgarlock,
User Rank: Apprentice
8/6/2013 | 10:05:27 PM
re: Google Android Vs. Apple iOS: The Mobile App Privacy War
Interesting article, comparing the cathedral and the bazaar development styles from each company :-) I would have thought the opposite.
anon7279680700
50%
50%
anon7279680700,
User Rank: Apprentice
7/9/2013 | 11:52:28 PM
re: Google Android Vs. Apple iOS: The Mobile App Privacy War
Losing privacy for convenience is fine now but is going to be short-term and soon there will be more privacy policies am sure (world is waiting for few major privacy invasion issues) and then normal world order returns where privacy and security both matter and not just one :-)

Manjunath M Gowda, CEO i7 networks, agentless BYOD discovery and control
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Why Security Leaders Can't Afford to Be Just 'Left-Brained'
Bill Bradley, SVP, Cyber Engineering and Technical Services, CenturyLink,  10/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.