Risk

7/8/2013
05:00 PM
50%
50%

Google Android Vs. Apple iOS: The Mobile App Privacy War

Ever wonder which smartphone has the most apps with the least respect for your privacy? The answer may surprise you

New research from BitDefender shows that applications for Apple iOS and Google Android may have their digital eyes and hands on more user data than you think.

Using their Clueful app, researchers at BitDefender examined how apps for Android and Apple's iOS treated private data, such as location information and contact lists. What they found may seem startling -- of the 207,843 free applications for iOS, 45.41 percent have location-tracking capabilities, whether they used them or not. Of the 314,474 free applications for Android, the percentage was 34.55.

When it comes to having the ability to read contact lists, the numbers were 7.69 percent for Android and 18.92 percent for apps designed for iOS. An iOS app called "3D Badminton II" (v. 2.026), for example, reads contacts' emails and sends them to a server in Hong Kong.

"Among the most interesting pieces of information for an advertising network are e-mail addresses and unique device IDs/IMEI," according to the report. "This data also may be shared with third parties to, for example, send consumers behaviorally targeted advertisements, according to a recent Federal Trade Commission report."

"About 14.58% of the Android applications may leak your Device ID and 5.73% of the total number of apps may leak your e-mail," the researchers note. "Again, iOS applications appear to be more focused on harvesting private data than those designed for Android."

Some examples for iOS include Ringtone Maker version 1.7, which sends the device ID to "adfonic.net," and 'aradise Island: Exotic (v. 1.3.14), which sends the device ID to a number of third-party websites. Meanwhile, an Android app called Logo Quiz Car Choices (v. 1.8.2.9) shares email addresses, the researchers found.

"Most people do not pay attention to the permissions required by the application they are about to install for a variety of reasons," observes Bogdan Botezatu, senior e-threat analyst at BitDefender. "They may not realize that those permissions are important in any way for the security of their device. They may not understand what each permission means and how it impacts the security of the terminal, or may not have other options but to accept the permissions if they want that application to run on their device. This is actually one of the most important shortcomings of Android -- the fixed permission model that asks you to go all in with the permissions or else you're not going to be able to run that application."

Android security has been in the spotlight during the past few days, as vendor Bluebox Security announced plans to release details of a serious Android vulnerability exploit at the upcoming Black Hat security conference in Las Vegas. According to Bluebox Security, the vulnerability involves discrepancies in how Android applications are cryptographically verified and installed, enabling a bad actor to modify APK code without breaking the cryptographic signature. The vulnerability only comes into play, however, in the case of applications downloaded from third-party app markets.

"Although this loophole has been present in Android devices since 2009 and is yet to be exploited by cyberthieves, the 'master key' is a major concern for consumers and also businesses, which are increasingly reliant on mobile devices for work and, moreover, accessing company data," says Grayson Milbourne, security intelligence director at Webroot. "An attacker being able to steal data or eavesdrop on calls or emails is clearly a major problem."

Judging by the extremely small number of malware incidents in the past years, most people would probably consider iOS much safer than Android, says Botezatu. However, this does not appear to be the case when it comes to privacy issues.

"We have two distinct operating systems that work differently and are built differently, and, yet, they attempt to get to the same kind of user information, as long as access to it is permitted by the application market," he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
bgarlock
50%
50%
bgarlock,
User Rank: Apprentice
8/6/2013 | 10:05:27 PM
re: Google Android Vs. Apple iOS: The Mobile App Privacy War
Interesting article, comparing the cathedral and the bazaar development styles from each company :-) I would have thought the opposite.
anon7279680700
50%
50%
anon7279680700,
User Rank: Apprentice
7/9/2013 | 11:52:28 PM
re: Google Android Vs. Apple iOS: The Mobile App Privacy War
Losing privacy for convenience is fine now but is going to be short-term and soon there will be more privacy policies am sure (world is waiting for few major privacy invasion issues) and then normal world order returns where privacy and security both matter and not just one :-)

Manjunath M Gowda, CEO i7 networks, agentless BYOD discovery and control
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.