ICT Security + Privacy + Piracy + Data Protection - Censorship
November 24, 2017

Des mouchards cachés dans vos applications pour smartphones | #Privacy #Tracking #Apps

Des dizaines de sociétés s’insèrent dans des applications banales pour collecter des données, amassant des informations sur des millions de Français.

Par dizaines, ils se nichent dans des applications mobiles utilisées quotidiennement par des millions de Français. Ils capturent discrètement des données, souvent personnelles, sans que les utilisateurs n’en soient nécessairement conscients, alimentant au passage une industrie opaque et méconnue. Certains de ses acteurs disposent de données sur des millions de Français.

Il s’agit de trackers, de petits logiciels incorporés dans des applications mobiles du quotidien (réseaux sociaux, médias, banques, sites de rencontre). Chaque application en compte 2,5 en moyenne, selon une analyse de plus de 350 applications, réalisée par un groupe d’activistes, rassemblés depuis octobre en association, et publiée vendredi 24 novembre sur leur plate-forme baptisée Exodus. Rares sont les applications qui en sont dépourvues et certaines vont jusqu’à en intégrer une quinzaine. Ce paysage n’est pas exhaustif : la plate-forme ne cherche que les trackers qu’elle a préalablement identifiés, soit une quarantaine.


Des dizaines de sociétés s’insèrent dans des applications banales pour collecter des données, amassant des informations sur des millions de Français.

Par dizaines, ils se nichent dans des applications mobiles utilisées quotidiennement par des millions de Français. Ils capturent discrètement des données, souvent personnelles, sans que les utilisateurs n’en soient nécessairement conscients, alimentant au passage une industrie opaque et méconnue. Certains de ses acteurs disposent de données sur des millions de Français.

Il s’agit de trackers, de petits logiciels incorporés dans des applications mobiles du quotidien (réseaux sociaux, médias, banques, sites de rencontre). Chaque application en compte 2,5 en moyenne, selon une analyse de plus de 350 applications, réalisée par un groupe d’activistes, rassemblés depuis octobre en association, et publiée vendredi 24 novembre sur leur plate-forme baptisée Exodus. Rares sont les applications qui en sont dépourvues et certaines vont jusqu’à en intégrer une quinzaine. Ce paysage n’est pas exhaustif : la plate-forme ne cherche que les trackers qu’elle a préalablement identifiés, soit une quarantaine.


April 14, 2014

Heartbleed-Bug: Über 1.000 Android-Apps betroffen

Längst hat die Heartbleed-Lücke auch mobile Geräte erreicht: Sicherheitsexperten von Trend Micro zufolge, verbinden sich rund 1.300 Android-Apps mit angreifbaren Servern - darunter auch 15 Banking-Apps.

March 4, 2014

Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping

This GnuTLS bug is worse than the big Apple "goto fail" bug patched last week.
Learn more:


January 29, 2014

Spy agencies are slurping personal data from leaky mobile apps

Beyond device details, data shared over the internet by iOS and Android apps can include personal information such as age, gender, and location, while some apps share even more sensitive user infor...
Learn more:










Looks like George ORWELL was right...




Forget PRISM, the recent NSA leaks are plain: Digital privacy doesn't exist...




January 28, 2014

Report: NSA Hunts For Personal Data From 'Leaky' Mobile Apps

New Snowden documents show the NSA and British spy agency GCHQ have looked at ways to collect age, location and gender data from apps like Google Maps and Angry Birds.
Learn more:










Looks like George ORWELL was right...




Forget PRISM, the recent NSA leaks are plain: Digital privacy doesn’t exist...


December 14, 2013

Twitter vulnerability lets apps send DMs without user permission

Security researcher Egor Homakov has discovered a Twitter vulnerability which allows apps to send DMs without requiring explicit user permission. TNW has verified the findings and can ...

Learn more:




November 21, 2013

HP Fortify entdeckt in 90 Prozent aller iOS Apps Sicherheitslücken

Untersucht wurden 2107 Apps für iOS von 601 Herstellern. Die HP-Tochter bewertet die entsprechenden Android-Anwendungen jedoch als ebenso anfällig. Zahlreiche Apps setzten keine Verschlüsselung ein und schützten die Nutzerdaten nicht angemessen.
Learn more:




September 20, 2013

Cybercriminals trying new tactics, security body warns - and attacks could have "large impact"

Cybercriminals "combining tactics", security body warns - and new attacks could have "large impact"
Drive-by exploits were identified as the number-one threat facing companies and computer users, but the company warned that other threats were rising in popularity – such as malicious browser extensions.

“It is worth mentioning that an increase in malicious browser extensions has been registered, aimed at taking over social network accounts,” ENISA said. An ESET report on a malicious extension in the popular Orbit downloader can be found here.


June 21, 2013

Botnets now target enterprise apps

Instead of being used as spam during DDoS attacks, botnets are now used to bring down enterprise apps, leaving the more connected countries more vulnerable, according to Barracuda Networks.
IT managers should not only guard against older forms of attacks but newer forms, as the variety of attack methods continue to expand...


Learn more:






IT managers should not only guard against older forms of attacks but newer forms, as the variety of attack methods continue to expand...

Learn more:




January 22, 2013

Twitter bug gives 3rd-party apps access to users' Direct Messages

"There should be millions of Twitter users that have signed in with Twitter into third-party applications. Some of these applications might have gained access to and might still have access to Twitter users private direct messages," he points out, and advises users to check third-party applications permissions and revoke the apps to which they never gave permission to access their DMs.

===> check third-party applications permissions and revoke the apps to which they never gave permission to access YOUR DMs. <===

Check ALSO:





===> check third-party applications permissions and revoke the apps to which they never gave permission to access YOUR DMs. <===


Check ALSO:












===> check third-party applications permissions and revoke the apps to which they never gave permission to access YOUR DMs. <===

Check ALSO:





===> check third-party applications permissions and revoke the apps to which they never gave permission to access YOUR DMs. <===

Check ALSO:





October 12, 2012

Is Google about to start scanning your Android for malware?

A new edition of the Google Play app (Android's equivalent to the iOS App Store) appears to be preparing to add anti-virus functionality to the mobile operating system.


Read more, a MUST:



February 28, 2012

Kaspersky Lab Announces its First Parental Control Apps for Android and Apple iOS Smartphones

Woburn, MA – February 28, 2012 – Kaspersky Lab, a leading developer of secure content and threat management solutions, today announced the beta-test phase of two new, free mobile applications that provide parental controls for Android and iOS-based smartphones. This marks the first Kaspersky Lab application designed to work on Apple smartphones.


February 14, 2015

Neuer Handy-Virus: Simplocker schleust Malware aufs Smartphone | Mobile Security

Simplocker ist eine sogenannte Ransomware, die Handydaten verschlüsselt und den Zugriff auf Handydaten sperrt. Der Virus tarnt sich als gefälschte Flashplayer-App.

Learn more:




Simplocker ist eine sogenannte Ransomware, die Handydaten verschlüsselt und den Zugriff auf Handydaten sperrt. Der Virus tarnt sich als gefälschte Flashplayer-App.

Learn more:




April 11, 2014

Heartbleed Bug—Mobile Apps are Affected Too

All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.

The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.


All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.

Learn more:


All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.


All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.

Learn more:

All the extended coverage of the Heartbleed flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


The severity of the Heartbleed bug has led countless websites and servers scrambling to address the issue. And with good reason—a test conducted on Github showed that more than 600 of the top 10,000 sites (based on Alexa rankings) were vulnerable. At the time of the scanning, some of the affected sites included Yahoo, Flickr, OKCupid, Rolling Stone, and Ars Technica.


All the extended coverage of the flaw begs the question, “Are mobile devices affected by this?” The short answer: yes.


Mobile apps, like it or not, are just as vulnerable to the Heartbleed Bug as websites are because apps often connect to servers and web services to complete various functions. As our previous blog entry has shown, a sizable number of domains are affected by this vulnerability.


February 23, 2014

Experts Find WhatsApp Vulnerabilities That "the NSA Would Love"

Shortly after Facebook announced buying WhatsApp, many users raised privacy concerns. Soon enough, security experts revealed identifying a number of vulnerabilities, which they catalogued as being exactly the kind “the NSA would love.”

The security issues have been identified by Praetorian. The company’s new mobile application security testing platform Project Neptune has been put to the test.

total of four SSL-related security holes have been identified. First, researchers found that SSL pinning is not enforced.

This allows an attacker to launch a man-in-the-middle (MitM) attack between the mobile application and the backend web services and capture user credentials and other sensitive information.

January 28, 2014

NSA spying through Angry Birds, Google Maps, leaked documents reportedly reveal

The NSA and its British counterpart are tapping popular smartphone apps such as Angry Birds to peek into the tremendous amounts of very personal data those bits of software collect -- including age, location sex and even sexual preference.
Learn more:










Looks like George ORWELL was right...




Forget PRISM, the recent NSA leaks are plain: Digital privacy doesn’t exist...


January 12, 2014

New app matches pics from mobile devices to a name, online profiles

The NameTag app uses facial recognition software and combs the web for social networking and dating profiles belonging to the unsuspecting passerby.
December 12, 2013

100% of Top Paid Android Apps Have Been Hacked and 56% of the Top 100 paid Apple iOS apps

12 December 2013

Word that mobile malware is rather pervasive has been making the rounds for months, but a new report has found that a shocking 100% of the Top 100 paid Android apps and 56% of the Top 100 paid Apple iOS apps have been hacked. Averaged together, users have a 78% chance of running into an app that has been compromised at some point.

Learn more:




October 30, 2013

Vorsicht: Tausende iPhone-Apps mit Sicherheitslücke

Security-SuperGAU für alle Nutzer von iPhones und iPads: Experten haben eine Lücke in iOS-Apps entdeckt, die es erlaubt, die komplette Kommunikation über fremde Server umzuleiten. Tausende Apps sollen betroffen sein.


Über HTTP Request Hijacking sollen sich Hacker in iOS-Apps einschleichen und so den Datentraffic über eigene Server umleiten können. Nach erfolgreichem Angriff soll die Umleitung dann permanent aktiv sein.


===> Einzige Abhilfe schafft ein Update oder eine Neuinstallation der App. <===



Learn more:






June 27, 2013

Download with Caution! McAfee Identifies Risky Mobile App Sources [Infographic]

Learn more:






May 21, 2013

Gratis-App warnt vor unsicheren Android-Apps

Mit Bitdefender Clueful ist ab sofort eine neue, kostenlose Android-App erhältlich, die alle auf einem Android-Gerät installierten Apps überprüft und bei verdächtigen oder unsicheren Apps Alarm schlägt.
Learn more:




October 19, 2012

French hacker admits smartphone app fraud

Slowly softly stealing Frenchman...


A 20 YEAR OLD French hacker has admitted to running a scam app that siphoned off small amounts of cash from smartphone users.
The unnamed man has appeared in a story published by the BBC that says he made over half a million Euros from his scheme. He reportedly was based at his parents' house in Northern France.


Read more:




June

LinkedIn updates apps in response to privacy concerns

Security researchers had discovered the networking company's app was transmitting user data without their knowledge. Read this blog post by Steven Musil on Security & Privacy.


Read more:



