The Register® — Biting the hand that feeds IT

Feeds

Don't download that app: US presidential candidates will STALK you with it

Romney mobe application even requests permission to record audio ...

Customer Success Testimonial: Recovery is Everything

Security researchers have uncovered privacy shortcomings in the mobile applications offered by both the Barack Obama and Mitt Romney presidential campaigns.

The campaign teams of the incumbent US President and his Republican challenger have each released apps for both iOS and Android, in good time for the election on November 6.

Experts at GFI Software looked at the Android versions of both apps, discovering both to be surprisingly invasive.

Obama for America and Mitt’s VP request permissions, access to services and data and capabilities beyond their core mandate.

For example, each of the apps features the ability to cross-post on users' behalf and report back to base. One app even has a tool to encourage users to go canvassing on behalf of the candidate, which in GFI's test directed Obama supporters to an unsafe part of a US town – just north of downtown Clearwater, Florida.

Both Android apps slurp the details of users' contacts and log location data, as a rundown by GFI on both apps and the permissions they seek explains. The Romney app even requests permission to record audio for unspecified (and so-far unactivated) purposes.

The GOP app gives users the option to either sign up to create a “MyMitt” account or connect with Facebook. Information such as your name, email address, password, home address with zip code, and an optional mobile phone number will be requested in the first scenario.

The Facebook version grants permission for the app to post on the user's behalf – as well as to collect data available from their Facebook friends. The app also collects other information (device ID, carrier, phone number, GPS location, cell location and package info on other installed apps). Much of this is covered in the terms of service fine-print, if users choose to read it.

The Obama for America app obliges users to consent to an agreement allowing the app to gather information, such as GPS and mobile cell location. The app bundles the ability to access a user’s phone contact list (names and numbers), call and message logs, data on currently installed apps, and contents of the SD card. In addition, the app logs user location information.

Users of Obama for America gain the ability to access information on registered voters near them via a feature called Canvass Neighborhood. Data such as registered voter’s first name and last initial, age and home addresses can be viewed.

With smartphone apps playing such a key role in voter engagement in the US, the way that both campaigns are using apps to collect data and deep dive into users' devices and data is quite concerning from a privacy perspective, GFI Software concludes.

"The lesson here for users is that it’s their responsibility to know what the apps on their mobile devices are doing and what personal information they are divulging about themselves and potentially their contacts and social network connections," Randall Griffith, junior threat researcher at GFI Software writes.

"Even reputable sources like the official presidential campaigns may encroach on what many of us consider a reasonable expectation of privacy and limitations on data collection. Read the fine print before installing any app.

"Ultimately, it comes down to this: If you value your privacy, be careful what you download to your mobile device, and do what you can to educate yourself about how your publicly available information (in this case your voter registration) is being used," she added. ®

Magic Quadrant for Enterprise Backup/Recovery

"Even reputable sources like the official presidential campaigns"

I'm not quite sure, does that really count as a 'reputable source'? I mean, /really/?

23
0

Which highlights the most important issue here

that being, your privacy is only as good as the least privacy-concerned person you are in contact with.

I loathe Facebook with a vengeance, and only joined at the insistence of my family and out of a need to observe and control what information was placed there about me; I went to great lengths to minimise the information about myself that was put on there. However, thanks to my Facebook-loving mother, bless her heart, they know almost as much about my private life, interests, hobbies, job and contact network as she does.

This is invasiveness of a scale even Orwell could never have imagined. A 1984 analogy would perhaps be people voluntarily demanding portable telescreens so Big Brother could watch them even on community hikes, and personal microphones that broadcast even a whisper from you to all in the vicinity.

If you know anyone who is on Facebook, or uses the sorts of apps mentioned in the article, you may as well have gone to the police yourself and voluntarily told them your whole life story. But hey, if you have nothing to hide you have nothing to fear, right?

When even my own family - the people I love most in the world and would gladly die for - are effectively made into informants, without even realising it, by the fundamental invasiveness of social networking, the future is a horror to make the worst imaginings of Orwell, Huxley and Bradbury seem like libertarian paradises in comparison.

14
0

Re: Protect users from themselves

What's the name of the app?

4
0

More from The Register

Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
Nuke plants to rely on PDP-11 code UNTIL 2050!
Programmers and their walking sticks converge in Canada
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry