Black Hat: Android wallpaper apps could be stealing data

Jul 31, 2010 8:05 AM
Tags: android | applications | apps | cent | data | per

Too many apps access personal information.

A team of mobile security researchers has found that popular wallpaper programs are capable of harvesting large amounts of personal data.

The researchers at Lookout found that several Android wallpaper applications can gather the number, subscriber identifier (e.g. IMSI), and the currently entered voicemail number on the phone.

"While this sort of data collection from a wallpaper application is certainly suspicious, there's no evidence of malicious behaviour," said the company in a blog post.

"There have been cases in the past on other mobile platforms where well-intentioned developers are simply over-zealous in their data gathering, without having malicious intent."

The apps in question came from two developers: 'jackeey,wallpaper', whose developer name has changed to 'callmejack' since the research was released, and 'IceskYsl@1sters!'. The applications do send data back to a central server, but Lookout said that this is not necessarily suspicious.

Lookout has also provided more details about its App Genome Project, which will scan 300,000 pieces of software to build the biggest dataset on mobile applications.

The preliminary results show that 47 percent of free Android apps contain third-party code, compared to 23 percent on the iPhone. Some 29 percent of Android applications and a third of Apple applications can access a user's location.

Nearly twice as many free applications have the capability to access contact data on the iPhone (14 percent) compared to Android (eight percent).

Copyright ©v3.co.uk


  • Email a Friend
  • Print Page
Black Hat: Android wallpaper apps could be stealing data
 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
NBN3 Wireless plan needs 4G spectrum fast-track
Dark fibre and wireless coalition issues new proposal.
 
Server patch blamed for Westpac outage
Back-up processes keep business customers online.
 
iTnews asks: Can a caretaker Government sign ACTA?
How Australia's political uncertainty could impact global negotiations.
 

Latest VideosSee all videos »

Latest Comments
"No, just something for readers who are also AAPT customers and might have wondered what all ..."
by rycrozier Sep 3, 2010 7:52 AM
 
"the whole campaign is whack"
by nicko Sep 3, 2010 7:26 AM
 
"Where's the clause preventing them from surrendering information to police should… I don't know… ..."
by ITrant Sep 3, 2010 7:22 AM
 
"@RB Im sure we can squeeze in an investment which will actually return much greater benefits to ..."
by ptconsult Sep 2, 2010 10:00 PM
 
"Don't kid yourself - yesterday (1 Sept) a Western Australian judge made it legal for Wilson ..."
by frances Sep 2, 2010 7:18 PM
Polls
Was sacking four Victorian police officers for inappropriate email use too harsh?

   |   View results
Yes
  52%
 
No
  48%
TOTAL VOTES: 81

Vote