Skip to main content

Hundreds Of Apps Banned From App Store For Accessing Users’ Personal Information


Hundreds of iOS applications have been pulled out of the App Store, following a report from analytics service SourceDNA, which uncovered a group of applications that were extracting users’ personally identifiable information, including email addresses associated with their Apple IDs, devices and peripheral serial numbers, as well as a list of apps installed on their phone. The applications in question had been using an SDK from a Chinese advertising company called Youmi which was accessing this information by way of private APIs, the report found.
Nearly all of the developers were located in China so, for now, this appears to be an isolated incident. However, the larger concern here has to do with how long this activity had been taking place – and what that means in terms of Apple’s App Store review process, given that it hadn’t caught this suspect activity until being alerted to it by a third party.
According to SourceDNA, Youmi had apparently been experimenting with what sort of information it could pull from users’ devices for some time. Nearly two years ago, for example, the firm began obfuscating a call to get the frontmost (currently running) app’s name – seemingly a small test of what it could sneak into the App Store. And when it realized that it was able to get this through Apple’s App Review process, it then began to use the same obfuscation technique to request other data, including the advertising ID.
The ad ID can be accessed for tracking ad clicks, but given that Youmi was surreptitiously collecting it, the firm may have been using it for other purposes, the report speculates.
In addition, SourceDNA noted that while Apple had been locking down private APIs in order to prevent apps from reading the platform serial number in iOS 8, Youmi worked around this by enumerating peripheral devices, like the battery system. It would then send those serial numbers as the hardware identifier.
SourceDNA, which helps app developers improve their code and address security flaws, says it found what Youmi was up to when it was updating its Searchlight product to check for use of private APIs – something that should get developers’ apps banned from the App Store. Surprisingly, it actually found quite a few apps that had gotten through.
In total, SourceDNA came across 256 apps with an estimated total of 1 million downloads that had been using a version of the Youmi SDK that was violating user privacy. However, the company adds it’s possible that the developers themselves didn’t realize what the SDK was doing, as the user data is uploaded to Youmi’s server.
What’s more concerning here is the implication of SourceDNA’s findings. The obfuscation method is fairly simple, the company says, and the apps have been using it for a long period of time. In fact, SourceDNA’s founder Nate Lawson tells us this has been going on for about a year-and-a-half.
“We’re concerned other published apps may be using different but related approaches to hide their malicious behavior,” a SourceDNA blog post states. “We’re continuing to add new features to our engine to discover anomalous behavior in app code and find out if this is the case.”
SourceDNA submitted its report to Apple, and Apple replied by offering the company a statement (see below) indicating the apps in question had been banned. Apple says it’s now working with developers who were using Youmi’s SDK to get their apps updated to be in compliance with Apple’s guidelines so they can return to the App Store.
Apple’s statement:
“We’ve identified a group of apps that are using a third-party advertising SDK, developed by Youmi, a mobile advertising provider, that uses private APIs to gather private information, such as user email addresses and device identifiers, and route data to its company server. This is a violation of our security and privacy guidelines. The apps using Youmi’s SDK have been removed from the App Store and any new apps submitted to the App Store using this SDK will be rejected. We are working closely with developers to help them get updated versions of their apps that are safe for customers and in compliance with our guidelines back in the App Store quickly.”

Comments

Popular posts from this blog

Laser gun is deployed and operational on U.S. Navy warship

After several years of research and testing, the U.S. Navy has introduced a new laser gun designed to protect ships without using ammunition.   Another entry on our  timeline  is now a reality as the U.S. Navy has authorised the first operational use of a laser weapon. This new hi-tech system – known as the Laser Weapon System (LaWS) – is designed to serve as a form of defence against drones and other small flying vehicles or small-boat enemies including suicide attackers. It is highly accurate, able to hit objects moving at up to 300 mph (480 km/h). The LaWS fires a solid-state infrared beam with two modes: high output to destroy a target, and low output for optical "dazzling", warning shots or to cripple a potential attacker. Among the advantages of this device versus projectile weapons is the low cost per shot, as each firing of the weapon requires only minimal cost for generating the energetic pulse; by contrast ordnance for projectile weapons must be des...

Intel announces the first 14 nanometre processor

At the Computex conference in Taipei, chipmaker Intel has revealed a fanless mobile PC reference design using the first of its next-generation 14nm "Broadwell" processors. The 2 in 1 pictured here is a 12.5" screen that is just 7.2 mm thick with keyboard detached and weighs 670 grams.  The Surface Pro 3  – for comparison – is 9.1 mm thick and weighs 800 grams. It includes a media dock that provides additional cooling for a burst of performance. The next-generation chip is purpose-built for 2 in 1s and will hit the market later in  2014 . Called the Intel Core M, it will be the most energy-efficient Intel Core processor in the company's history with power usage cut by up to 45 percent, resulting in 60 percent less heat. The majority of designs based on this new chip are expected to be fanless, with up to  32 hours of battery life,  offering both a lightning-fast tablet and razor-thin laptop. Intel is also delivering innovation and performance for the ...

How to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10?

BitLocker is an encryption method that enables users to lock the different drives in  Windows . The drives which are protected by BitLocker are accessed by passwords. Windows has provided opportunity for users to choose and configure the  cipher  strength and algorithm used by BitLocker Drive Encryption. This can be achieved via the Local Group Policy editor. The Local Policy Editor will let you configure and select the cipher method for BitLocker encryption. By default it is not configured but you can choose your choiceable encryption method by enabling the Policy Setting. If the drive is already encrypted or if encryption is in progress, the encyption method will have no effect. If you leave the policy unconfigured, then BitLocker will use the default encryption method of AES 128-bit with Diffuser or the encryption method specified by the setup script. Steps to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10 1.  ...

Facebook Now Supports PGP To Send You Encrypted Emails

You can now instruct Facebook to encrypt every email it sends to you so nobody — not even the NSA — is likely to be able to read your messages anytime soon. All you have to do is import your public PGP key into your Facebook settings and you’re good to go. The problem here, of course, is that most people have no idea how public/private key email encryption works and how to even get started with it. In the wake of Edward Snowden’s leaks, a number of organizations, including Google, promised to completely hide the complexities of end-to-end email encryption from regular users. Very few of these products have materialized so far, however — not for lack of trying, but because this is actually a very complex problem, both from a technical and user experience perspective. Facebook uses the well-established PGP scheme (the GNU Privacy Guard implementation of  OpenPGP, to be precise) to encrypt messages and tools lik...

How to prevent Recent and Phone Favorite contacts from showing in your iOS task switcher

When you double-click your iPhone's home button, you will be greeted with the task switching screen, which presents you with card deck-style snapshots of your active apps to freely browse and switch to. With iOS 8, however, where most iPhones are at the moment, Apple introduced a Favorites row there, with circular pictures of your most recently used contacts. Most people aren't bothered by their recent contacts appearing there, but for some this means easy snooping on who they've called or texted last, or simply unnecessary clutter. If you don't want to wait until  iOS 9  hits and gets rid of these circular shenanigans in your task switcher, here's what you need to do to get rid of them: 1. Go to the Settings app, and scroll down to the Mail, Contacts, Calendars section; 2. From Mail, Contacts, Calendars, look for the Contacts section, which will be hosting the Show in App Switcher options; 3. Tap on Show in App Switche...