Downed Clueful app reveals encryption woes

Powered by SC Magazine
 

Clueful app finds 41 per cent of apps able to access user location.

Bitdefender's Clueful security app pulled last month from the Apple App Store has found 41 per cent of iOS applications are able to access a user's location and a third store unencrypted data.

A study of more than 65,000 applications on the Apple App Store revealed tens of thousands tap contact information and access data without explicit user permission. The research also found that 18 per cent of the apps can access a user's address book.

The research was derived from analysis of the company's Clueful app, which was taken down by Apple from its App Store on 30 June. The app determined what information applications had sought and compiled its database from user-submitted apps.

Bitdefender chief security researcher Catalin Cosoi said while many apps use these privileges to function, others have no obvious use for the data they may be collecting.

"It is worrying that stored data encryption on iOS apps is low and location tracking is so prevalent," he said.

"Without notification of what an app accesses, it is difficult to control what information users give up. We see a worrying landscape of poor user data encryption, prevalent location tracking and silent unjustified address book access."

Apple did not say why the app was taken down and gagged Bitdefender under a non-disclosure agreement from doing the same, Security Week reported.

BitDefender's Clueful analysis service was still active for users and the security vendor was working on getting the application back online.

SC has found duplicates of the app mirrored online which can be installed on jailbroken Apple devices, however the security of those files cannot be verified and users are warned they could be laced with malicious code.

- With Darren Pauli

Copyright © SC Magazine, Australia


Downed Clueful app reveals encryption woes
 
 
 
Top Stories
AGL restructure sees CIO depart
Owen Coppage to leave after ten years.
 
Data: Advertising's best frenemy
STW Group's Tom Ceglarek faces a digital conundrum: he must feed his client's demand for performance insights while his industry is being undermined by data analysis.
 
Inside Telstra's multi-faceted cloud strategy
An overview of its own cloud and deals with Cisco, VMware, IBM and NextDC.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Small business win in a budget with 'fair' savings: Abbott
Apr 17, 2015
Tony Abbott has reaffirmed that the government’s aim is “always to get taxes ...
Xero now includes an inventory function built-in
Mar 26, 2015
Xero has added inventory and other major new features to the latest release of its cloud ...
Apple reveals its new MacBook
Mar 13, 2015
Replacing the MacBook Air as Apple's thinnest laptop, the new MacBook comes packed with features.
Xero has released a new version of its app for the iPad
Mar 6, 2015
iPad-wielding Xero users can now take advantage of a new version of the iOS app for the cloud ...
Microsoft is offering Azure for Disaster Recovery to Australian SMBs
Feb 10, 2015
If you haven't talked to your IT provider about disaster recovery, it might be worth discussing ...
Latest Comments
Polls
Do you support the Government's data retention scheme?

   |   View results
Yes
  11%
 
No
  89%
TOTAL VOTES: 2121

Vote