Most apps collect some kind of information about the user. Sometimes, data is necessary for programs to function—for example, a navigation app needs information about your location to plot a convenient route. Developers also often use information about you to monetize or improve their service — with your prior consent. For example, they collect anonymous statistics to understand in which direction to develop the program.
However, some developers may abuse your trust by collecting information that is not related to the functionality of their program and selling your data to third parties, often without your knowledge. Fortunately, there are services on the Internet that can help you expose such applications.
AppCensus
AppCensus allows you to find out what personal data an app sends and where. To do this, it uses a dynamic analysis method: the program is installed on a real mobile device, given all the requested permissions, and actively used for a certain period of time. At the same time, the service’s specialists track what data it sends, to whom, and in what form — encrypted or unencrypted.
This approach allows you to obtain results that reflect the actual behavior of the application. If you are concerned about the information that AppCensus may provide, you can decline the program and search for a more modest alternative that does not attempt to gather too much information about you. However, the information on AppCensus may be incomplete: the program is only tested for a limited time, and some of the app’s features may not be activated immediately. In addition, AppCensus only examines free and publicly available Android apps.
Exodus Privacy service
Unlike AppCensus, Exodus Privacy studies the app itself rather than your behavior. In particular, the service evaluates the permissions requested by the program and searches for built-in trackers — third-party modules designed to collect data about you and your actions. As a rule, developers add advertising network trackers to their apps, which they use to learn as much as possible about you and show you personalized ads. The service currently knows of more than 200 types of such trackers.
As for permissions, Exodus Privacy evaluates them in terms of the danger they pose to you and your data. If an app requests access that could threaten your privacy or compromise your device’s security, the service will flag it. If you feel that potentially dangerous permissions are not necessary for the app to function normally, it is better not to grant them. If necessary, you can expand its rights later.
App secrets
Both services are very easy to use. Just enter the name of the program in the search field, and you will receive comprehensive information about what data it collects and where it sends it. Unlike AppCensus, Exodus allows you not only to select applications from a list, but also to specify which programs to take from Google Play for analysis in the New analysis tab.
We took a selfie camera with 5 million installations from Google Play as an example. Exodus Privacy shows that it uses four advertising trackers and requires access not only to the camera, but also to the device’s location, which is not really necessary for it to work (in theory, it may do this for good reasons — to write geotags to the EXIF data of photos), and to information about the phone and calls, which it definitely does not need.
Potentially dangerous permissions are marked with exclamation marks: logical access to the camera and device memory for the app, and more questionable access to location and phone information.
An analysis of the same app by AppCensus only raises more questions: according to the service, the selfie camera not only accesses the location of your smartphone or tablet, but also sends this information along with the IMEI (your device’s unique identifier in the cellular network), MAC address (another unique number by which the device can be identified on the Internet and local networks), and Android ID (the number assigned to your system when you first start it) to a certain Chinese IP address in unencrypted form. In other words, you can forget about good intentions.
Is it possible to protect yourself from surveillance?
As you can see, a popular app with an unremarkable privacy policy can put sensitive data at risk. Therefore, we recommend that you treat mobile apps with caution:
- Don’t install apps on your device just for the sake of it. They can track you even if you don’t use them or open them. And if you don’t need an app you’ve already installed, delete it.
- Before installing apps you don’t know, check them using AppCensus and Exodus Privacy. If the analysis results make you uncomfortable, don’t install the app and look for another one.
- Don’t grant apps all permissions at once. If you are not sure why the program needs access to certain information, deny it. We have a separate blog post about permissions in Android, and it is very convenient to control the rights granted to programs using Kaspersky Security Cloud.