[FSec] Scary Copycat Apps on Google Play

Newsfeed

Nachrichtenbote
All Hallows' Eve was yesterday — a.k.a. Halloween. And so naturally, there's an app for that. Or many apps as the case may be.

Here's a series of apps designed to "scare your friends".

scare_your_friends_01.png


This one has more than 10 million downloads.

scare_your_friends_02.png


Even these copycats have several hundred thousand downloads.

scare_your_friends_03.png
scare_your_friends_04.png


Android doesn't really help differentiate between them.

scare_your_friends_05.png


But if we use our permissions dashboard (App Permissions in Google Play) then we can see some big differences.

scare_your_friends_06.png
scare_your_friends_07.png


The most popular app only wants three permissions while the copycats want 21! And worse yet, those permissions include the ability to see your personal information. That's what the copycat apps are after — your personal details.

Scary.

Given that the "legit" version of the app is "borrowing" images from Hollywood films… there's nobody with an incentive to police the copycats. And Google, an advertising company, doesn't appear to have much incentive to police them either.

And so several hundred thousand people shared their personal details.

Scare you friends, indeed.

—————

Analysis provided by — Jose
On 01/11/13 At 02:15 PM

Weiterlesen...
 
Zurück
Oben