Downed Clueful app reveals encryption woes

Powered by SC Magazine
 

Clueful app finds 41 per cent of apps able to access user location.

Bitdefender's Clueful security app pulled last month from the Apple App Store has found 41 per cent of iOS applications are able to access a user's location and a third store unencrypted data.

A study of more than 65,000 applications on the Apple App Store revealed tens of thousands tap contact information and access data without explicit user permission. The research also found that 18 per cent of the apps can access a user's address book.

The research was derived from analysis of the company's Clueful app, which was taken down by Apple from its App Store on 30 June. The app determined what information applications had sought and compiled its database from user-submitted apps.

Bitdefender chief security researcher Catalin Cosoi said while many apps use these privileges to function, others have no obvious use for the data they may be collecting.

"It is worrying that stored data encryption on iOS apps is low and location tracking is so prevalent," he said.

"Without notification of what an app accesses, it is difficult to control what information users give up. We see a worrying landscape of poor user data encryption, prevalent location tracking and silent unjustified address book access."

Apple did not say why the app was taken down and gagged Bitdefender under a non-disclosure agreement from doing the same, Security Week reported.

BitDefender's Clueful analysis service was still active for users and the security vendor was working on getting the application back online.

SC has found duplicates of the app mirrored online which can be installed on jailbroken Apple devices, however the security of those files cannot be verified and users are warned they could be laced with malicious code.

- With Darren Pauli

Copyright © SC Magazine, Australia


Downed Clueful app reveals encryption woes
 
 
 
Top Stories
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
More 4G from Optus in Darwin
Nov 21, 2014
Click to see where Optus has expanded coverage to the suburbs near Darwin.
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 875

Vote