Automatic updating of Android apps becomes riskier
Posted on 12 June 2014.
Google has made unwelcome changes to the way new app permissions are disclosed to users: no warnings will be shown if a new permission if is in the same category as an old one that has previously been accepted.

The change has been introduced with the recently released new version of the Play store app, and has apparently made to streamline the installing of updates and to avoid confusing users.

With this update, a user who has previously permitted an app to access the device's coarse GPS location will not be notified when the new version of the app starts collecting information about the device's fine location, as both permissions belong to the same category.

Similarly, an app that initially only had the permission to read the call log could now be updated to initiate phone calls without the user's knowledge. Or if it originally was permitted to read the contents of the SD card, it can be updated to write to it. Find out more about the different permission groups here.

"Unfortunately, most groups contain at least one 'innocent' or common permission that many apps on the Store use next to some more nasty ones," noted a software developer that goes by the online handle "Tubeman," who created an app named Permission Tester to test for this "latest Google security screw up."

If you are not comfortable with this new change, you can prevent it by turning off auto-updates for specific apps by opening the Play Store app, touching the app's icon, selecting "My Apps", selecting the app, and unchecking the box next to "Auto-update" in the Menu.

A second "improvement" announced by Google makes the "full Internet access" permission disappear from the primary permissions screen and get automatically approved.

"These days, apps typically access the Internet," Google explained, and says that Google Play’s app review systems already check all apps for abuse of these access permissions.









Spotlight

Infographic: 25 years of the firewall

Posted on 24 July 2014.  |  The firewall turned 25, and McAfee is celebrating with an infographic that creatively depicts its lifetime. If you take a moment to scan the infographic, you’ll notice the firewall's introduction and evolution coincide with certain security events.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Jul 25th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //