Feeds

How many mobile apps collect data on users? Oh ... nearly all of them

Free or paid, Android or iOS, your apps are spying on YOU – report

The Essential Guide to IT Transformation

Could the apps you have installed on your mobile phone be snooping on you? Based on the latest data from app security analytics firm Appthority, it's not merely possible; it's actually more than likely, particularly if you downloaded those apps for free.

According to Appthority's Winter 2014 App Reputation Report, released this week, 95 per cent of the top 200 free apps for iOS and Android exhibited at least one risky behavior. But so did 80 per cent of the top 200 paid apps, meaning pretty much all apps should be considered suspect.

The so-called risky behaviors Appthority identified in its study included location tracking, accessing the device's address book or contact list, single sign-on via social networks, identifying the user or the phone's unique identifier (UDID), in-app purchases, and sharing data with ad networks and analytics companies.

After analyzing the code of the top 200 free and paid apps on iOS and Android, Appthority concluded that all of these categories were commonplace, but the riskiest ones were particularly prevalent among free apps.

For example, 70 per cent of free apps tracked the user's location, compared to just 44 per cent of the paid apps studied. Similarly, more than half of all of the free apps used social network sign-ons, identified the user, offered in-app purchasing, or shared user data with ad networks – any of which could easily be abused by malicious apps. Less than half of paid apps displayed each of these behaviors.

The study did show variation between the two platforms. Notably, free Android apps were more likely to exhibit risky behaviors across every category than were free iOS apps.

One surprising finding, however, was that iOS apps were actually more likely to do suspect things overall. The survey found that 91 per cent of all iOS apps, free and paid, exhibited at least one risky behavior. The figure was only 83 per cent for Android apps as a whole. But that doesn't mean Android apps are generally safer, as the report explains:

What's important to note here is that although more iOS apps collect user data than Android apps, the Android apps that do collect data capture more information than their iOS counterparts. In other words, a larger percentage of iOS apps collect some data but the data collected by these apps is less than the data collected by Android apps when they do collect data.

Still, some iOS developers are doing sneaky things. While Apple forbids iOS apps from directly accessing UDIDs, for example, Appthority identified a number of apps that have managed to get around this restriction by implementing new ways of uniquely identifying and tracking users.

And while there's a persistent myth that games are generally more risky than non-game apps, Appthority's study showed that this isn't really the case, with non-game and business apps just as likely to do dodgy things.

Paid apps were generally safer than free ones, but even these demonstrated enough suspect behaviors that IT departments shouldn't consider an app safe just because it costs money.

So how do companies stay safe, particularly in today's "mobile first," "bring your own device" world? Tricky, that. Unsurprisingly, Appthority sells a service that allows companies to compare what's on their workers mobes with a database of analyzed apps. But preventing users from installing any risky apps is going to be a tall order.

"Gone are the days where software came into the enterprise from a few, trusted developers," the report observes. The full report is available for download here. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Tor attack nodes RIPPED MASKS off users for 6 MONTHS
Traffic confirmation attack bared users' privates - but to whom?
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.