20% of Android apps use private data
readwriteweb.com
readwriteweb.com
!!! The article makes a big deal out of a specific spyware application. This wouldn't be very much of a problem if the application weren't openly described by its authors as one whose sole purpose is spying on the phone's user. So why make a big deal out of it!?
!! The article makes a big deal of the fact that some applications have requested the same set of permission that some spyware apps have. I can think of no conceivable specific combination of permissions that alone would give much information at all about whether or not an app is spyware. It also makes a big deal of how nine applications can brick the phone without going into any detail about the nominal purpose of these apps (i.e. does it make sense that such an app behaving as described in the market entry for this app should need to brick the phone).
! This article seems to imply that one would need any of these permissions to harm the user. From my understanding of Android development, I believe that any application can raise an intent to open a webpage in the browser, and the url of that page could easily be used to transmit sensitive information even with no permission at all. (I could be wrong on this one.)
!!! Any app that requests two of the permissions they label as sensitive is marked as suspicious. This means that any app wanting to both access the internet and do any of the following is considered suspicious according to this study:
- Access coarse location.
- Write to the external storage.
- Send an SMS.
! The company behind this paper is trying to sell something that you would be more likely to buy if you believed its results.
I do think there are issues to be addressed, and the article mentions apps which can send premium text messages, an exploit vector which is more concerning.
The only functional forces pushing in that direction at present are patronage amd pride. Patronage from the audience and pride from the performers.
One of their conclusions appears to be that "one must look at the permissions it has requested to determine what the application's true capabilities might be". Very heuristic.
Quotes from http://threatcenter.smobilesystems.com/wp-content/uploads/20... (PDF)
It is almost impossible to get data from another app if the author doesn't expose it somehow (place it on SD Card, expose Content Providers).
Could an independent Android developer comment on whether this is in fact true?