Feeds

Japanese govt: Use operator-run app stores, not Google Play

Info-stealing sexy wallpaper app was downloaded 500,000 times on official site

Securing Web Applications Made Simple and Scalable

Google’s security credentials have taken another hit after the Japanese government warned local Android users to download their apps from third party operator-run stores, and not Google's own Play, following the discovery of a prolific info-stealing app on the official site.

The Tokyo-based Information Technology Promotion Agency (IPA) alerted domestic Android users last Friday that a rogue app named “sexy porn model wallpaper” had already been downloaded 500,000 times from Google Play before being spotted and removed.

The app, which promises “sexy fresh girls wallpaper”, works like many others of its kind by requesting user permission to access phone information including location details, email address and terminal information before sending it on to a third party server.

While not containing any malware, the app has no good reason to request access to such info, and effectively uses the “sexy girl” content to distract users while lifting this data in the background, said IPA.

The government-backed body warned users off Google Play and instead urged them to visit third party app stores run by mobile operators – such as KDDI’s “au Smart Path”, Docomo’s “D Market” and Softbank’s “Yahoo! Market” – saying that, “in these markets, operators carry out their own checks of the app”.

Google’s Android ecosystem has long been criticised for its lack of in-built security checks, although the Chocolate Factory responded to concerns by launching an app verification service for Google Play recently.

That said, its efficacy has been called into question by researchers, and the security vendor community is claiming threats will continue to snowball on the platform.

Trend Micro, for example, predicted recently that the number of malicious and high-risk Android apps would reach the one million mark this year. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
MPs wave through Blighty's 'EMERGENCY' surveillance laws
Only 49 politcos voted against DRIP bill
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.