Jump to content
  • Study reveals Android phones constantly snoop on their users

    aum

    • 498 views
    • 3 minutes
     Share


    • 498 views
    • 3 minutes

    A new study by a team of university researchers in the UK has unveiled a host of privacy issues that arise from using Android smartphones.

     

    The researchers have focused on Samsung, Xiaomi, Realme, and Huawei Android devices, and LineageOS and /e/OS, two forks of Android that aim to offer long-term support and a de-Googled experience

     

    The conclusion of the study is worrying for the vast majority of Android users .

     

    With the notable exception of /e/OS, even when minimally configured and the handset is idle these vendor-customized Android variants transmit substantial amounts of information to the OS developer and also to third parties (Google, Microsoft, LinkedIn, Facebook, etc.) that have pre-installed system apps. - Researchers.

     

    As the summary table indicates, sensitive user data like persistent identifiers, app usage details, and telemetry information are not only shared with the device vendors, but also go to various third parties, such as Microsoft, LinkedIn, and Facebook.

     

    data%20collection%20summary.jpg

    Summary of collected data
    Source: Trinity College Dublin

     

    And to make matters worse, Google appears at the receiving end of all collected data almost across the entire table.

     

    No way to "turn it off"


    It is important to note that this concerns the collection of data for which there’s no option to opt-out, so Android users are powerless against this type of telemetry.

     

    This is particularly concerning when smartphone vendors include third-party apps that are silently collecting data even if they’re not used by the device owner, and which cannot be uninstalled.

     

    For some of the built-in system apps like miui.analytics (Xiaomi), Heytap (Realme), and Hicloud (Huawei), the researchers found that the encrypted data can sometimes be decoded, putting the data at risk to man-in-the-middle (MitM) attacks.

     

    volume%20of%20data(1).jpg

    Volume of data (KB/h) transmitted by each vendor
    Source: Trinity College Dublin

     

    As the study points out, even if the user resets the advertising identifiers for their Google Account on Android, the data-collection system can trivially re-link the new ID back to the same device and append it to the original tracking history.

     

    The deanonymisation of users takes place using various methods, such as looking at the SIM, IMEI, location data history, IP address, network SSID, or a combination of these.

     

    data%20collector%20points.jpg

    Potential cross-linking data collection points
    Source: Trinity College Dublin

     

    Privacy-conscious Android forks like /e/OS are getting more traction as increasing numbers of users realize that they have no means to disable the unwanted functionality in vanilla Android and seek more privacy on their devices.

     

    However, the majority of Android users remain locked into never ending stream of data collection, which is where regulators and consumer protection organizations need to step in and to put an end to this.

     

    BleepingComputer has contacted Google for a statement regarding this study but has not heard back at this time.

     

    Gael Duval, the creator of /e/OS has told BleepingComputer:

     

    Today, more people understand that the advertising model that is fueling the mobile OS business is based on the industrial capture of personal data at a scale that has never been seen in history, at the world level. This has negative impacts on many aspects of our lives, and can even threaten democracy as seen in recent cases. I think regulation is needed more than ever regarding personal data protection. It has started with the GDPR, but it's not enough and we need to switch to a "privacy by default" model instead of "privacy as an option".

     

    Source

    • Like 3

    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...