Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Warning over iPhone apps that can silently turn on cameras at any time
Telegraph ^ | 10/26/17 | James Titcomb

Posted on 10/26/2017 10:52:19 AM PDT by LibWhacker

Apple has been urged to change the way in which iPhone apps are granted access to the phone's camera after a security researcher demonstrated how apps can secretly record photos and videos without the user knowing.

Felix Krause, an Austrian developer who works for Google, built an app that was able to take pictures of its user every second and upload them, without notifying the user. He called it a "privacy loophole that can be abused by iOS apps".

When an app wants to access the camera, for example to scan a credit card or take a profile picture during the set-up process, the iPhone user must give the app permission, in the same way that apps must ask to access the camera roll, location and contacts and to send notifications. Once allowed, it has to be turned off via the settings menu.

The system is similar to the permissions required by apps on Android. Google has recently deleted several apps that surreptitiously recorded users and masqueraded as legitimate apps.

But Krause said that once an app has been granted initial access, it can take photos and videos whenever it is opened up. Unlike on Mac computers, which have a small green light next to the camera when it is being used, there is no indication that an app is recording videos or taking photos, or when it sends them elsewhere.

(Excerpt) Read more at telegraph.co.uk ...


TOPICS: Business/Economy; News/Current Events
KEYWORDS: apps; camera; iphone; privacy

1 posted on 10/26/2017 10:52:20 AM PDT by LibWhacker
[ Post Reply | Private Reply | View Replies]

To: LibWhacker
The practice is banned by Apple's App Store guidelines, which state that a "reasonably conspicuous audio, visual or other indicator must be displayed to the user as part of the Application to indicate that a Recording is taking place".

Not likely to happen with Apple iPhones, apps must go through a screening process by Apple and are rejected if they violate the guidelines. On Android phones there is little if any restriction.

2 posted on 10/26/2017 11:00:06 AM PDT by roadcat
[ Post Reply | Private Reply | To 1 | View Replies]

To: roadcat
On Android phones there is little if any restriction.

If it is a Pixel phone, the Android OS is adhered to strictly. With the other manufacturers (Samsung, LG, Motorola, etc.), all bets are off.

3 posted on 10/26/2017 11:02:58 AM PDT by CatOwner
[ Post Reply | Private Reply | To 2 | View Replies]

bookmark


4 posted on 10/26/2017 11:04:41 AM PDT by freds6girlies (many that are first shall be last; and the last shall be first. Mt. 19:30. R.I.P. G & J)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibWhacker; Swordmaker

Ping!................


5 posted on 10/26/2017 11:07:44 AM PDT by Red Badger (Road Rage lasts 5 minutes. Road Rash lasts 5 months!.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibWhacker

Swordmaker may be spying you iPhone users : )


6 posted on 10/26/2017 11:11:15 AM PDT by minnesota_bound
[ Post Reply | Private Reply | To 1 | View Replies]

To: roadcat

That’s app Review, which is different, but may catch this sort of thing....

This report is the more once you grant an app permission, for any reason it keeps those permissions indefinitely unless you manually go into the global settings firm and turn them off..

Android behaves the same way, once permission has been granted.

They are suggesting that there be some sort of reaffirmation of permission to use , rather than just a one time thing.


7 posted on 10/26/2017 11:16:29 AM PDT by HamiltonJay
[ Post Reply | Private Reply | To 2 | View Replies]

To: LibWhacker

Comes a point where one must decide whether to trust someone (or, by proxy via app).
Yes, I’ve thought about such possible security issues. Apps having otherwise legitimate access to camera, mic, location, photos, contacts, etc can certainly abuse them.
Before bashing the ecosystem for potential of such abuse, you should ask: what could possibly be done to prevent it? and: do I trust this app?
In this case (as in most cases alleging security flaws on iOS etc), consider how those questions apply:
- having (presumed) legitimately allowed the app to access the camera, the only ways to prevent improper use is either add a new option (like for location) “only when app is in use”, or have iOS ask “allow camera use?” every time the camera is enabled. The former solution is possible, and after this I’d not be surprised if it shows up soon in iOS. The latter would be unduly obnoxious, most apps using the camera properly.
- this app was obviously from a security researcher, who is likely trying to evade security - not someone to trust. Major-brand apps, yes; people with an obvious ulterior motive, no.

And as Swordmaker will likely declare momentarily, once again this “security flaw” _specifically_ requires the victim to deliberately download an app, deliberately approve limited access, deliberately trusting the developers to no abuse the permissions.

I suspect Apple will respond by ending camera access if the app is not active. (I’m wondering if there’s any apps that legitimately do want camera access when backgrounded.)


8 posted on 10/26/2017 11:18:21 AM PDT by ctdonath2 (It's not "white privilege", it's "Puritan work ethic". Behavior begets consequences.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CatOwner

No, its about the app store itself... Play doesn’t put apps through the same type of review process before they allowed to be up for sale... Apple does...

it has nothing to do with OS behaviors on the phone


9 posted on 10/26/2017 11:20:03 AM PDT by HamiltonJay
[ Post Reply | Private Reply | To 3 | View Replies]

To: HamiltonJay

Question is: under what condition should iOS request re-affirmation? offhand (as an app developer) I don’t see what would prompt that, and I see arbitrary re-affirmation requests as annoying to users. If the app is trustworthy, there’s no reason to keep asking; if the app _isn’t_ trustworthy, I shouldn’t run it.


10 posted on 10/26/2017 11:22:29 AM PDT by ctdonath2 (It's not "white privilege", it's "Puritan work ethic". Behavior begets consequences.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ctdonath2

I agree, I am just saying that is what this guy is suggesting. I too develop apps for both android and ios.


11 posted on 10/26/2017 11:36:59 AM PDT by HamiltonJay
[ Post Reply | Private Reply | To 10 | View Replies]

To: LibWhacker

I think most of these allow access to your image gallery so, if you have anything you don’t want the world to see stored on your phone...


12 posted on 10/26/2017 11:37:22 AM PDT by outofsalt ( If history teaches us anything it's that history rarely teaches us anything)
[ Post Reply | Private Reply | To 1 | View Replies]

To: roadcat

Not really worried. If they ever do that to Android phones, they’re going to get all sorts of pictures of the inside of my pocket.


13 posted on 10/26/2017 11:43:40 AM PDT by dangus
[ Post Reply | Private Reply | To 2 | View Replies]

To: LibWhacker

So, Google programmer finds potential camera security in IOS? No conflict of interest here...

Seriously, though, if true, and if Apple has dropped the ball, that’s not a good thing. Nothing like feeling like you have to stick some tape over the lens on your phone...

Not quite related, but at my local workplace, they had to issue a warning (presumably one or more people got fired or otherwise disciplined) that just because your phone asks you to take a picture of your current location (presumably for google maps or something) doesn’t mean you should.

Silly people.

Funny thing is, if you setup the right social engineering type app, you could probably get people to take the compromising photos for you. People seem to be so easily programmed these days.


14 posted on 10/26/2017 11:48:22 AM PDT by Kommodor (Terrorist, Journalist or Democrat? I can't tell the difference.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LibWhacker

I’ll take my phone in the shower with me. They won’t do it more than once.


15 posted on 10/26/2017 11:50:56 AM PDT by AppyPappy (Don't mistake your dorm political discussions with the desires of the nation)
[ Post Reply | Private Reply | To 1 | View Replies]

To: outofsalt

Yeah, I’m thinking about that. Some of my ammo purchases require photo ID, usually a driver’s license, and I find it convenient to keep a pic of my driver’s license on my iPhone. But now I’m definitely rethinking that!


16 posted on 10/26/2017 11:55:59 AM PDT by LibWhacker
[ Post Reply | Private Reply | To 12 | View Replies]

To: AppyPappy

Good plan! Give ‘em something they can’t unsee... I think I could fix them up with one of those pics, myself. LOL!


17 posted on 10/26/2017 11:57:46 AM PDT by LibWhacker
[ Post Reply | Private Reply | To 15 | View Replies]

To: roadcat

Not a loophole. Nothing sensational here. The problem is that the USER doesn’t think of things like this, and so doesn’t think about revoking the app’s permission after granting it.

Apple is not a big evil corporation showing illicit pictures of you to strangers.

Is there any testing done of these apps? Should Apple do it? Should independent organizations do it? (This one did, and that’s the solution for the problem.)


18 posted on 10/26/2017 12:24:07 PM PDT by I want the USA back (It's harder and harder to have a sense of humor in this insane world.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Red Badger; ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; ...
A Google developer has demonstrated that using Apple provided APIs, a developer can open the camera and upload a photo or video. Whoop-de-do. That is well documented in the Apple Developers’ Tool Kit and all Apple Developers already know it is possible. They also know that they cannot get such a capability past the curators of the Apple App Store if it is hidden, intended to steal information, data, or invade the privacy of iOS device users. Such attempts will get them banned for life from developing for Apple devices. This is pure FUD (Fear, Uncertainty, and Doubt) in advance of tonight’s release of the iPhone X to pre-orders. There is NOTHING NEW HERE! — PING!


Apple FUD from Google Developer
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

19 posted on 10/26/2017 12:57:27 PM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 5 | View Replies]

Read some more about the issue.

Well...yeah.
It’s a “foreground only” issue, meaning you’re actually using the app.
Yes, if you give an app permission to use the camera, it can use the camera - and not necessarily tell you when it’s on.
Yes, there’s not an indicator in iOS letting you know the camera is on. Maybe there should be...but such cases being so rare, I’d hate to load the status bar with yet another indicator. Adding a hardware light seems overkill for such a small device and such a rare issue. The whole point would be an acknowledgement of badness where it shouldn’t be, a subtly user-distressing situation.

Remember: the camera uses a _lot_ of power, so any app that is surreptitiously using one will likely get complaints about it using an undue amount of power, and subsequently get analyzed & outed for its impropriety.


20 posted on 10/26/2017 1:34:22 PM PDT by ctdonath2 (It's not "white privilege", it's "Puritan work ethic". Behavior begets consequences.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson