(Press-News.org) New York, NY—June 18, 2014—In a paper presented—and awarded the prestigious Ken Sevcik Outstanding Student Paper Award—at the ACM SIGMETRICS conference on June 18, Jason Nieh, professor of computer science at Columbia Engineering, and PhD candidate Nicolas Viennot reported that they have discovered a crucial security problem in Google Play, the official Android app store where millions of users of Android, the most popular mobile platform, get their apps.
"Google Play has more than one million apps and over 50 billion app downloads, but no one reviews what gets put into Google Play—anyone can get a $25 account and upload whatever they want. Very little is known about what's there at an aggregate level," says Nieh, who is also a member of the University's Institute for Data Sciences and Engineering's Cybersecurity Center. "Given the huge popularity of Google Play and the potential risks to millions of users, we thought it was important to take a close look at Google Play content."
Nieh and Viennot's paper is the first to make a large-scale measurement of the huge Google Play marketplace. To do this, they developed PlayDrone, a tool that uses various hacking techniques to circumvent Google security to successfully download Google Play apps and recover their sources. PlayDrone scales by simply adding more servers and is fast enough to crawl Google Play on a daily basis, downloading more than 1.1 million Android apps and decompiling over 880,000 free applications.
Nieh and Viennot discovered all kinds of new information about the content in Google Play, including a critical security problem: developers often store their secret keys in their apps software, similar to usernames/passwords info, and these can be then used by anyone to maliciously steal user data or resources from service providers such as Amazon and Facebook. These vulnerabilities can affect users even if they are not actively running the Android apps. Nieh notes that even "Top Developers," designated by the Google Play team as the best developers on Google Play, included these vulnerabilities in their apps.
"We've been working closely with Google, Amazon, Facebook, and other service providers to identify and notify customers at risk, and make the Google Play store a safer place," says Viennot. "Google is now using our techniques to proactively scan apps for these problems to prevent this from happening again in the future."
In fact, Nieh adds, developers are already receiving notifications from Google to fix their apps and remove the secret keys.
Nieh and Viennot expect PlayDrone to lay a foundation for new kinds of analysis of Android apps. "Big data is increasingly important and Android apps are just one form of interesting data," Nieh observes. "Our work makes it possible to analyze Android apps at large scale in new ways, and we expect that PlayDrone will be a useful tool to better understand Android apps and improve the quality of application content in Google Play."
Other findings of the research include:
showing that roughly a quarter of all Google Play free apps are clones: these apps are duplicative of other apps already in Google Play
identifying a performance problem resulting in very slow app purchases in Google Play: this has since been fixed
a list of the top 10 most highly rated apps and the top 10 worst rated apps in Google Play that included surprises such as an app that, while the worst rated, still had more than a million downloads: it purports to be a scale that measures the weight of an object placed on the touchscreen of an Android device, but instead displays a random number for the weight
Good news for the hundreds of thousands of developers who upload content to Google Play and even more so for the millions of users who download the content!
INFORMATION: END
Columbia Engineering team finds thousands of secret keys in Android apps
First large-scale study of Google Play finds crucial security problem using new tool, PlayDrone
2014-06-18
ELSE PRESS RELEASES FROM THIS DATE:
New manufacturing methods needed for 'soft' machines, robots
2014-06-18
WEST LAFAYETTE, Ind. — Researchers have developed a technique that might be used to produce "soft machines" made of elastic materials and liquid metals for potential applications in robotics, medical devices and consumer electronics.
Such an elastic technology could make possible robots that have sensory skin and stretchable garments that people might wear to interact with computers or for therapeutic purposes.
However, new manufacturing techniques must be developed before soft machines become commercially practical, said Rebecca Kramer, an assistant professor of mechanical ...
Quest for education creating graying ghost towns at top of the world
2014-06-18
Ethnic Tibetan communities in Nepal's highlands are rapidly shrinking as more parents send their children away for a better education and modern careers, a trend that threatens to create a region of graying ghost towns at the top of the world, according to a study that includes Dartmouth College.
The findings, which have major social and demographic implications for the Himalayan region, appear in the journal Mountain Research and Development. A PDF of the study is available on request.
Taken together, the outmigration of young people, a low birth rate and population ...
Counterterrorism, ethics, and global health
2014-06-18
The surge in murders of polio vaccination workers in Pakistan has made headlines this year, but little attention has been devoted to the ethical issues surrounding the global health impact of current counterterrorism policy and practice. An essay in the Hastings Center Report reviews the range of harms to population health traceable to counterterrorism operations.
It also identifies concerns involving moral agency and responsibility – specifically of humanitarian health workers, military medical personnel, and national security officials and operatives – and it highlights ...
Proposed children's study needs refinement, report finds
2014-06-18
PRINCETON, N.J.—A study that would track the health of 100,000 babies to age 21 has been put on hold following the release of an assessment report issued June 16 by the National Research Council and Institute of Medicine (IOM).
While the congressionally mandated report endorses several aspects of the proposed study design of the National Children's Study (NCS), the authors – including Sara McLanahan, the William S. Tod Professor of Sociology and Public Affairs at Princeton University's Woodrow Wilson School of International and Public Affairs – are critical of the sampling ...
False negative results found in prognostic testing for breast cancer
2014-06-18
A recent study evaluating HER2 testing in a large cohort of women with breast cancer found important limitations in the conventional way HER2 testing is performed in the US and internationally.
Dartmouth-Hitchcock Norris Cotton Cancer Center physicians and researchers retested tumor samples from a large group of women and found that 22 out of 530 women had their tumor type incorrectly classified. They reported their findings in a publication titled "Assessing the Discordance Rate between Local and Central HER2 Testing in Women with Locally Determined HER2-Negative Breast ...
New Stanford blood test identifies heart-transplant rejection earlier than biopsy can
2014-06-18
Stanford University researchers have devised a noninvasive way to detect heart-transplant rejection weeks or months earlier than previously possible. The test, which relies on the detection of increasing amounts of the donor's DNA in the blood of the recipient, does not require the removal of any heart tissue.
"This test appears to be safer, cheaper and more accurate than a heart biopsy, which is the current gold standard to detect and monitor heart-transplant rejection," said Stephen Quake, PhD, professor of bioengineering and of applied physics. "We believe it's likely ...
How a new approach to funding Alzheimer's research could pay off
2014-06-18
More than 5 million Americans suffer from Alzheimer's disease, the affliction that erodes memory and other mental capacities, but no drugs targeting the disease have been approved by the U.S. Food and Drug Administration since 2003. Now a paper by an MIT professor suggests that a revamped way of financing Alzheimer's research could spur the development of useful new drugs for the illness.
"We are spending tremendous amounts of resources dealing with this disease, but we don't have any effective therapies for it," says Andrew Lo, the Charles E. and Susan T. Harris Professor ...
Maybe birds can have it all: Dazzling colors and pretty songs
2014-06-18
ITHACA, N.Y. – A study of one of the world's largest and most colorful bird families has dispelled a long-held notion, first proposed by Charles Darwin, that animals are limited in their options to evolve showiness. The study – the largest of its kind – was published today in the Proceedings of the Royal Society B.
The natural world is full of showstoppers – birds with brilliant colors, exaggerated crests and tails, intricate dance routines, or virtuosic singing. But it's long been thought that these abilities are the result of trade-offs. For a species to excel in one ...
Demand for diabetes, thyroid care outpaces supply of endocrinologists
2014-06-18
Washington, DC—As more people are diagnosed with diabetes and other hormone conditions, a growing shortage of endocrinologists could force patients to wait longer to see a doctor, according to a new Endocrine Society workforce analysis published in the Journal of Clinical Endocrinology & Metabolism (JCEM).
Endocrinologists are specially trained physicians who diagnose diseases related to the glands. They specialize in treating diabetes, obesity, osteoporosis, thyroid disorders, adrenal diseases, and a variety of other conditions related to hormones.
The analysis found ...
Scientists take first dip into water's mysterious 'no-man's land'
2014-06-18
Scientists at the Department of Energy's SLAC National Accelerator Laboratory have made the first structural observations of liquid water at temperatures down to minus 51 degrees Fahrenheit, within an elusive "no-man's land" where water's strange properties are super-amplified.
The research, made possible by SLAC's Linac Coherent Light Source (LCLS) X-ray laser and reported June 18 in Nature, opens a new window for exploring liquid water in these exotic conditions, and promises to improve our understanding of its unique properties at the more natural temperatures and ...
LAST 30 PRESS RELEASES:
Exposure to more artificial light at night may raise heart disease risk
Optimal cardiovascular health among people with Type 2 diabetes may offset dementia risk
Quick CPR from lay rescuers can nearly double survival for children after cardiac arrest
An AI tool detected structural heart disease in adults using a smartwatch
Assessing heart-pumping glitch may reduce stroke risk in adults with heart muscle disease
Low-dose aspirin linked to lower cardiovascular event risk for adults with Type 2 diabetes
Long-term use of melatonin supplements to support sleep may have negative health effects
Healthy lifestyle combined with newer diabetes medications lowered cardiovascular risk
Researchers pinpoint target for treating virus that causes the stomach bug
Scientists produce powerhouse pigment behind octopus camouflage
Researchers unveil a powerful new gene-switch tool
Analyzing 3 biomarker tests together may help identify high heart disease risk earlier
Study shows how kids learn when to use capital letters - it’s not just about rules
New switch for programmed cell death identified
Orcas seen killing young great white sharks by flipping them upside-down
ETRI achieves feat of having its technology adopted as Brazil’s broadcasting standard
Agricultural practices play a decisive role in the preservation or degradation of protected areas
Longer distances to family physician has negative effect on access to health care
Caution advised with corporate virtual care partnerships
Keeping pediatrics afloat in a sea of funding cuts
Giant resistivity reduction in thin film a key step towards next-gen electronics for AI
First pregnancy with AI-guided sperm recovery method developed at Columbia
Global study reveals how bacteria shape the health of lakes and reservoirs
Biochar reimagined: Scientists unlock record-breaking strength in wood-derived carbon
Synthesis of seven quebracho indole alkaloids using "antenna ligands" in 7-10 steps, including three first-ever asymmetric syntheses
BioOne and Max Planck Society sign 3-year agreement to include subscribe to open pilot
How the arts and science can jointly protect nature
Student's unexpected rise as a researcher leads to critical new insights into HPV
Ominous false alarm in the kidney
MSK Research Highlights, October 31, 2025
[Press-News.org] Columbia Engineering team finds thousands of secret keys in Android appsFirst large-scale study of Google Play finds crucial security problem using new tool, PlayDrone



