(Press-News.org) Almost half of the mobile apps running on Apple's iOS operating system access the unique identifier of the devices where they're downloaded, computer scientists at the University of California, San Diego, have found. In addition, more than 13 percent access the devices' location and more than 6 percent the address book. The researchers developed a new app that detects what data the other apps running on an iOS device are trying to access.
The findings are based on a study of 130,000 users of jailbroken iOS devices, where users have purposefully removed restrictions that keep apps from accessing the iPhone's operating system. Most apps in the study were downloaded from Apple's App Store and access the same type of information on unlocked, jailbroken, phones and on locked phones, said Yuvraj Agarwal, a research scientist in the Department of Computer Science and Engineering at UC San Diego, who co-authored the study with fellow researcher Malcolm Hall. Agarwal will present the findings at ACM MobiSys, the premier mobile systems conference, which takes place June 25 to 28 in Taipei, Taiwan.
The findings suggest that although Apple's App Store no longer accepts new apps or app updates that access the unique identifier as of March of this year, many apps can still get a hold of that information. The unique identifier allows app vendors and advertisers to track users' behaviors across all the different apps on their devices, including iPhones, iPads and iPods. In addition, some apps can associate the unique identifier with the user's email and other personal information.
The researchers believe that it's the first time anyone has done such an extensive privacy study focused on iOS-based apps across a large user population.
The ProtectMyPrivacy App
To carry out their study, researchers developed an app of their own, called ProtectMyPrivacy, or PMP. It lets users know what personal information the other apps on their devices are trying to access. PMP enables users to selectively allow or deny access to this information on an app-by-app basis, based on whether they feel the apps need the information to function properly—for example, a map app needs to access the location of a device to provide driving directions. iOS devices currently notify users when apps try to access location, photos and contacts. But they do not notify users when apps access the unique identifier or music library and users can't deny access to those two pieces of information.
Since gathering data for the study, researchers have also added notifications and recommendations for when an app accesses other privacy-sensitive information, such as a devices' front and back camera, microphone and photos.
PMP also makes recommendations about whether to allow the other apps to access user data, based on an extensive crowdsourcing 'recommendation engine' that compiles the privacy decisions made by other users.
"We wanted to empower users to take control of their privacy," said Agarwal, who is also an alumnus of UC San Diego's Jacobs School of Engineering. "The choice should be in users' hands."
For locked devices, researchers are currently providing a web page that tells users which information more than 150 apps for iOS—some of the most popular—are trying to access and gives recommendations about whether to allow or deny access. The page can be viewed at http://www.protectmyprivacy.org/liveview/
For example, Facebook, the most popular app, accesses the devices' identifier, location and contacts. PMP's crowdsourcing engine recommends denying access to the identifier and contacts music, but allowing access to location.
Findings by the numbers
ProtectMyPrivacy has already been downloaded from the Cydia store by more than 130,000 users since March 2012. Its users have downloaded and used more than 225,000 unique apps from Apple's App Store. The researchers analyzed the data accessed by those apps and found that 48.1 percent of them accessed the device's unique identifier; 13.2 percent the location information; 6.2 percent the address book; and 1.6 percent the music library.
As of January 2013, Apple reported that it had sold 500 million iOS devices. Estimates of how many are jailbroken vary, but Forbes reported in February 2013 that seven million devices had been jailbroken in just four days after a new jailbreaking tool was released. Cydia, an app store that caters only to jailbroken devices, had 23 million users as of March 2013 –a sizeable portion of Apple's mobile devices.
Read the full paper here.
Recommendations to protect your privacy
Almost all of PMP's users—99 percent-- voluntarily shared their privacy decisions, indicating which apps they think should be allowed—or denied—access to their privacy-sensitive data. These decisions – which are contributed anonymously – are then processed on PMP servers to generate the crowdsourced privacy recommendations shown to users. As a result, PMP is able to make recommendations for 97 percent of the 10,000 most popular iPhone apps. "We have already shown millions of recommendations, and more than two-thirds of all our recommendations are accepted by our users, showing that they really like this unique feature of PMP," said Agarwal. Users chose to deny access to one or more pieces of sensitive data for 48.1 percent of apps.
The version of PMP available in the Cydia store gives users the option to feed fictitious or anonymized information to nosy apps. Examples include an address book filled with made-up entries, a random location that may be in a completely different country, and a randomly generated unique identifier.
The researchers say that they do not recommend jailbreaking your iPhone to install PMP, because doing so could potentially leave a user open to other vulnerabilities. But in order to conduct their research, they needed to be able to intercept information about the privacy-protected data that apps were accessing. This required low-level access to the operating system, which is not technically possible on locked, non-jailbroken, iOS devices.
Sometimes, it is not the apps themselves that access the data, but a third-party library or code contained within the apps. For example, Flixster, a popular app for movie reviews and recommendations, in its 5.2 version, was flagged for accessing some private data. Flixster contacted Agarwal and Hall to say that it does no such thing. The computer scientists did some digging and found that a third-party ad library used by the app was accessing users' address books and sending back information. "We provided feedback to the app's developers in case they are unaware that a third party library may be accessing their users' private data," recalled Hall, a visiting researcher in Agarwal's Synergy Lab at UC San Diego. He also pointed out that "an updated version of Flixster now uses another ad library that does not access this kind of information."
Agarwal and Hall tried submitting to the Apple Store a "lite" version of their app that wouldn't interact with the iOS operating system, but the app was rejected. That version would have given users information about the data specific apps access and recommendations about what to allow and deny. It would not have given users the ability to protect their data by providing fictitious information.
Agarwal will join the School of Computer Science at Carnegie Mellon University as an assistant professor in the fall.
INFORMATION:
App to protect private data on iOS devices finds almost half of other apps access private data
2013-06-20
ELSE PRESS RELEASES FROM THIS DATE:
The sun moth: A beautiful new species Stenoloba solaris from China
2013-06-20
Scientist describe a new striking species of moth from China with an engaging wing pattern. The new species Stenoloba solaris has its name inspired by the orange circular patch on its wings that resembles the rising sun. The study was published in the open access journal Zookeys.
"During a spring expedition to north-west Yunnan, a striking specimen of an undescribed Stenoloba was collected.", explain the authors Drs Pekarsky and Saldaitis. "Only a single male was caught at ultraviolet light on 24 May 2012 near Zhongdian in northwest China's Yunnan province in the remote ...
Ups-and-downs of Indian monsoon rainfall likely to increase under warming
2013-06-20
The Indian monsoon is a complex system which is likely to change under future global warming. While it is in the very nature of weather to vary, the question is how much and whether we can deal with it. Extreme rainfall, for example, bears the risk of flooding, and crop failure. Computer simulations with a comprehensive set of 20 state-of-the-art climate models now consistently show that Indian monsoon daily variability might increase, according to a study just published by scientists of the Potsdam Institute for Climate Impact Research.
"Increased variability – this ...
Does your salad know what time it is?
2013-06-20
Does your salad know what time it is? It may be healthier for you if it does, according to new research from Rice University and the University of California at Davis.
"Vegetables and fruits don't die the moment they are harvested," said Rice biologist Janet Braam, the lead researcher on a new study this week in Current Biology. "They respond to their environment for days, and we found we could use light to coax them to make more cancer-fighting antioxidants at certain times of day." Braam is professor and chair of Rice's Department of Biochemistry and Cell Biology.
Braam's ...
Lab reproduction of a marine compound with antibiotic properties
2013-06-20
This news release is available in Spanish. Bacterial resistance to drugs leads pharmaceutical labs to be in constant search for new antibiotics to treat the same diseases. For the last thirty years, the sea bottom has yielded a wealth of substances with properties of interest to the pharmaceutical industry. Isolated from a marine microorganism off the coast of Alicante by the company BioMar, baringolin shows promising antibiotic activity at a very low concentration. The Combinatorial Lab headed by Fernando Albericio at the Institute for Research in Biomedicine (IRB ...
Too green to be true? Researchers develop highly effective method for converting CO2 into methanol
2013-06-20
Quebec City, June 20, 2013—Université Laval researchers have developed a highly effective method for converting CO2 into methanol, which can be used as a low-emissions fuel for vehicles. The team led by Professor Frédéric-Georges Fontaine presents the details of this discovery in the latest issue of the Journal of the American Chemical Society.
Researchers have been looking for a way to convert carbon dioxide into methanol in a single step using energy-efficient processes for years. "In the presence of oxygen, methanol combustion produces CO2 and water," explained Professor ...
American Chemical Society global program tackles safe drinking water in Colombia
2013-06-20
The Global Innovation Imperatives (Gii) program, administered by the American Chemical Society (ACS) Office of International Activities, today issued a white paper outlining possible solutions for increasing access to safe drinking water in the rural areas of the world. Although focused on the community of Chocontá, in Colombia, the suggested solutions have broader application.
Chocontá residents rely on rural aqueducts for their water, but supplies are vulnerable to pollution from nearby agriculture and largely go untreated. City officials asked ACS, the world's largest ...
'Forrest Gump' mice show too much of a good thing, can be bad
2013-06-20
VIDEO:
This video shows a control mouse doing a task to test cognitive skills. The mouse must start the test, then scan and touch the screen at the spot where...
Click here for more information.
A line of genetically modified mice that Western University scientists call "Forrest Gump" because, like the movie character, they can run far but they aren't smart, is furthering the understanding of a key neurotransmitter called acetylcholine (ACh). Marco Prado and his team at Robarts ...
Rhode Island Hospital reduces incidence of hospital-associated C. difficile by 70 percent
2013-06-20
PROVIDENCE, R.I. – Rhode Island Hospital has reduced the incidence of hospital-associated Clostridium difficile (C. difficile) infections by 70 percent and reduced annual associated mortality in patients with hospital-associated C. difficile by 64 percent through successive implementation of five rigorous interventions , as reported in the July 2013 issue of The Joint Commission Journal on Quality and Patient Safety.
Clostridium difficile is a toxin-producing bacterium that lives in the colon. A major cause of morbidity and mortality in the U.S., it can cause life-threatening ...
Virus combination effective against deadly brain tumor, Moffitt Cancer Center study shows
2013-06-20
A combination of the myxoma virus and the immune suppressant rapamycin can kill glioblastoma multiforme, the most common and deadliest malignant brain tumor, according to Moffitt Cancer Center research. Peter A. Forsyth, M.D., of Moffitt's Neuro-Oncology Program, says the combination has been shown to infect and kill both brain cancer stem cells and differentiated compartments of glioblastoma multiforme.
The finding means that barriers to treating the disease, such as resistance to the drug temozolomide, may be overcome. The study, by Forsyth and colleagues in Canada, ...
Making a beeline for the nectar
2013-06-20
Bumblebees searching for nectar go for signposts on flowers rather than the bull's eye. A new study, by Levente Orbán and Catherine Plowright from the University of Ottawa in Canada, shows that the markings at the center of a flower are not as important as the markings that will direct the bees to the center. The work is published online in Springer's journal, Naturwissenschaften - The Science of Nature.
The first time bees go out looking for nectar, which visual stimuli do they use to identify that first flower that will provide them with the reward they are looking ...