Apps hiding malicious functions collect data – including location, audio and camera – which could facilitate surveillance and harassment.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    72
    ·
    edit-2
    6 days ago

    And nowhere to be found is an actual list of affected apps - only a couple examples.

    Great job, NCSC 🤨👍

  • xodoh74984@lemmy.world
    link
    fedilink
    English
    arrow-up
    85
    arrow-down
    18
    ·
    6 days ago

    Isn’t every app that’s not open source assumed to be spyware nowadays?

    Wake me up when this sort of thing is actually illegal. Preferably punishable with jail time.

    • Nougat@fedia.io
      link
      fedilink
      arrow-up
      70
      arrow-down
      1
      ·
      6 days ago

      This isn’t that. This isn’t “let us collect data on you so we can aggregate it and monetize it, it’s buried in the EULA.”

      This is state-sponsored actual malware being used to identify, target, track specific individuals.

      • bizarroland@fedia.io
        link
        fedilink
        arrow-up
        3
        arrow-down
        46
        ·
        6 days ago

        Yeah, and?

        Do you honestly believe there’s a single person on lemmy with enough gravitas to be worth being tracked by the elite?

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          23
          arrow-down
          1
          ·
          6 days ago

          Maybe. The bad actor here seems to be the government of China, and the linked page says:

          The individuals most at risk include anyone connected to: Taiwanese independence; Tibetan rights; Uyghur Muslims and other ethnic minorities in or from China’s Xinjiang Uyghur Autonomous Region; democracy advocacy, including Hong Kong, and the Falun Gong spiritual movement.

          I can imagine them casting a wide net.

        • Snot Flickerman@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          11
          ·
          edit-2
          6 days ago

          Pretty sure US still does three hops of surveillance.

          If you or any friend you have speaks to anyone at all in a foreign country you are put on a list for surveillance.

          I had a Jordanian friend in college and I have a close friend who still keeps in touch with him now that he is back in Jordan. I always assumed that put me on a list based on the three hops method.

          Three hops being:

          Hop 1: Main surveillance target Hop 2: Social network of main surveillance target Hop 3: Social network of anyone in main surveillance target’s social network.

          So if you are the main surveillance target, friends of your friends are also targetted.

          US surveils people for what are otherwise pretty inocuous reasons.

        • darkkite@lemmy.ml
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          1
          ·
          6 days ago

          yes, absolutely. plently of programmers here with various agendas

  • Trihilis@ani.social
    link
    fedilink
    English
    arrow-up
    50
    ·
    6 days ago

    install app

    “Do you agree to share your information with 289 of our partners or opt out by going through a list and deselecting them one by one”?

    Yeah any app that asks this is guaranteed spyware.

    Also, use F-Droid as much as possible. It’s not perfect but still miles better than the play store

    • pHr34kY@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      5 days ago

      Even Aurora store vets all the apps for trackers. Google just take the money and serve up malware.

      At least these days it’s farily obvious when an app is looking at your location or listening in with the mic.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 days ago

      F-Droid is my go-to for anything possible. If I find something I can selfhost and has an app, I make sure the app can be found in F-Droid (or even just an APK shipped in the repo that can be managed with Obtainium), or else I lose interest.