Android’s App Store Privacy Section Starts Rolling Out Today

An anonymous reader quotes a report from Ars Technica: Following in the footsteps of iOS 14, Google is rolling out an app privacy section to the Play Store on Tuesday. When you look up an app on the Play Store, alongside sections like “About this app” and “ratings and reviews,” there will be a new section called “Data privacy & security,” where developers can explain what data they collect. Note that while the section will be appearing for users starting today, it might not be filled out by developers. Google’s deadline for developers to provide privacy information is July 20. Even then, all of this privacy information is provided by the developer and is essentially working on the honor system.

Here’s how Google describes the process to developers: “You alone are responsible for making complete and accurate declarations in your app’s store listing on Google Play. Google Play reviews apps across all policy requirements; however, we cannot make determinations on behalf of the developers of how they handle user data. Only you possess all the information required to complete the Data safety form. When Google becomes aware of a discrepancy between your app behavior and your declaration, we may take appropriate action, including enforcement action.”

Once the section is up and running, developers will be expected to list what data they’re collecting, why they’re collecting it, and who they’re sharing it with. The support page features a big list of data types for elements like “location,” “personal info,” “financial info,” “web history,” “contacts,” and various file types. Developers are expected to list their data security practices, including explaining if data is encrypted in transit and if users can ask for data to be deleted. There’s also a spot for “Google Play’s Families Policy” compliance, which is mostly just a bunch of US COPPA and EU GDPR requirements. Google says developers can also indicate if their app has “been independently validated against a global security standard.”

Read more of this story at Slashdot.

Volla Phone 22 Runs Ubuntu Touch Or a Privacy-Focused Android Fork Or Both

The Volla Phone 22, a new smartphone available for preorder via a Kickstarter campaign, is unlike any other smartphone on the market today in that it ships with a choice of the Android-based Volla OS or the Ubuntu Touch mobile Linux distribution. “It also supports multi-boot functionality, allowing you to install more than one operating system and choose which to run at startup,” writes Liliputing’s Brad Linder. Some of the hardware specs include a 6.3-inch FHD+ display, a MediaTek Helio G85 processor, 4GB of RAM, 128GB storage, 3.5mm audio jack and a microSD card reader. There’s also a 48-megapixel main camera sensor and replaceable 4,500mAh battery. From the report: While Volla works with the folks at UBPorts to ensure its phones are compatible with Ubuntu Touch, the company develops the Android-based Volla OS in-house. It’s based on Google’s Android Open Source Project code, but includes a custom launcher, user interface, and set of apps with an emphasis on privacy. The Google Play Store is not included, as this is a phone aimed at folks who want to minimize tracking from big tech companies. Other Google apps and services like the Chrome web browser, Google Maps, Google Drive, and Gmail are also omitted. The upshot is that no user data is collected or stored by Volla, Google, or other companies unless you decide to install apps that track your data. Of course, that could make using the phone a little less convenient if you’ve come to rely on those apps, so the Volla Phone might not be the best choice for everyone.

Volla OS also has a built-in user-customizable firewall, an App Locker feature for disabling and hiding apps, and optional support for using the Hide.me VPN for anonymous internet usage. The source code for Volla OS is also available for anyone that wants to inspect the code. The operating system also has a custom user interface including a Springboard that allows you to quickly launch frequently-used apps by pressing a red dot for a list, or by starting to type in a search box for automatic suggestions such as placing a phone call, sending a text message, or opening a web page. You can also create notes or calendar events from the Springboard or send an encrypted message with Signal. The phone is expected to ship in June at an early bird price of about $408.

Read more of this story at Slashdot.

Android’s Messages, Dialer Apps Quietly Sent Text, Call Info To Google

Google’s Messages and Dialer apps for Android devices have been collecting and sending data to Google without specific notice and consent, and without offering the opportunity to opt-out, potentially in violation of Europe’s data protection law. From a report: According to a research paper, “What Data Do The Google Dialer and Messages Apps On Android Send to Google?” [PDF], by Trinity College Dublin computer science professor Douglas Leith, Google Messages (for text messaging) and Google Dialer (for phone calls) have been sending data about user communications to the Google Play Services Clearcut logger service and to Google’s Firebase Analytics service.

“The data sent by Google Messages includes a hash of the message text, allowing linking of sender and receiver in a message exchange,” the paper says. “The data sent by Google Dialer includes the call time and duration, again allowing linking of the two handsets engaged in a phone call. Phone numbers are also sent to Google.” The timing and duration of other user interactions with these apps has also been transmitted to Google. And Google offers no way to opt-out of this data collection. […] Both pre-installed versions of these apps, the paper observes, lack app-specific privacy policies that explain what data gets collected — something Google requires from third-party developers. And when a request was made through Google Takeout for the Google Account data associated with the apps used for testing, the data Google provided did not include the telemetry data observed.

Read more of this story at Slashdot.

Google’s Messages App Can Now Handle iMessage Reactions

Google is updating the default “Messages” app to include a number of new features, such as the ability to handle iMessage “Tapbacks.” TechCrunch reports: Other coming updates include nudges to remind you to reply to messages you missed, separate tabs for business and personal messages, reminders about birthdays you may want to celebrate, support for sharper videos via a Google Photos integration and an expanded set of emoji mashups, among other things. After the update, reactions from iPhone users will be sent as an emoji on text messages on Android. As on iMessage, the emoji reaction — like love, laughter, confusion or excitement — will appear on the right side of the message. (On Android, it’s the bottom right.) This feature is first rolling out to Android devices set to English, but additional languages will follow. […] Android’s interpretation of which emoji to use varies slightly from iPhone, however. For instance, the “heart” reaction on Android becomes the “face with the heart eyes” emoji. And the iMessage’s exclamation mark reaction becomes the “face with the open mouth” emoji.

Google is also integrating Google Photos into the Message app to improve the video sharing experience. While the modern RCS standard allows people with Android devices to share high-quality videos with each other, those same videos appear blurry when shared with those on iPhone, as iMessage doesn’t support RCS. By sending the link to the video through Google Photos, iPhone users will be able to watch the video in the same high resolution. This feature will later include support for photos, too. This addition aims to push Apple to adopt the industry standard by shaming the company over video quality.

Read more of this story at Slashdot.

Apple Launches AirTags and Find My Detector App For Android, In Effort To Boost Privacy

Apple has released a new Android app called Tracker Detect, designed to help people who don’t own iPhones or iPads to identify unexpected AirTags and other Find My network-equipped sensors that may be nearby. CNET reports: The new app, which Apple released on the Google Play store Monday, is intended to help people look for item trackers compatible with Apple’s Find My network. “If you think someone is using AirTag or another device to track your location,” the app says, “you can scan to try to find it.” If the Tracker Detector app finds an unexpected AirTag that’s away from its owner, for example, it will be marked in the app as “Unknown AirTag.” The Android app can then play a sound within 10 minutes of identifying the tracker. It may take up to 15 minutes after a tracker is separated from its owner before it shows up in the app, Apple said.

If the tracker identified is an AirTag, Apple will offer instructions within the app to remove its battery. Apple also warns within the app that if the person feels their safety is at risk because of the item tracker, they should contact law enforcement. […] The Tracker Detect app, which Apple first discussed in June, requires users to actively scan for a device before it’ll be identified. Apple doesn’t require users have an Apple account in order to use the detecting app. If the AirTag is in “lost mode,” anyone with an NFC-capable device can tap it and receive instructions for how to return it to its owner. Apple said all communication is encrypted so that no one, including Apple, knows the location or identity of people or their devices.

Read more of this story at Slashdot.

Over 300,000 Android Users Have Downloaded These Banking Trojan Malware Apps, Say Security Researchers

Over 300,000 Android smartphone users have downloaded what turned out to be banking trojans after falling victim to malware that has bypassed detection by the Google Play app store. ZDNet reports: Detailed by cybersecurity researchers at ThreatFabric, the four different forms of malware are delivered to victims via malicious versions of commonly downloaded applications, including document scanners, QR code readers, fitness monitors and cryptocurrency apps. The apps often come with the functions that are advertised in order to avoid users getting suspicious. In each case, the malicious intent of the app is hidden and the process of delivering the malware only begins once the app has been installed, enabling them to bypass Play Store detections.

The most prolific of the four malware families is Anatsa, which has been installed by over 200,000 Android users — researchers describe it as an “advanced” banking trojan that can steal usernames and passwords, and uses accessibility logging to capture everything shown on the user’s screen, while a keylogger allows attackers to record all information entered into the phone. […] The second most prolific of the malware families detailed by researchers at ThreatFabric is Alien, an Android banking trojan that can also steal two-factor authentication capabilities and which has been active for over a year. The malware has received 95,000 installations via malicious apps in the Play Store. […] The other two forms of malware that have been dropped using similar methods in recent months are Hydra and Ermac, which have a combined total of at least 15,000 downloads. ThreatFabric has linked Hydra and Ermac to Brunhilda, a cyber-criminal group known to target Android devices with banking malware. Both Hydra and Ermac provide attackers with access to the device required to steal banking information. ThreatFabric has reported all of the malicious apps to Google and they’ve either already been removed or are under review.

Read more of this story at Slashdot.