Author Topic: iPhone, Android App Sarahah Quietly Uploads Phone Contacts to Company Servers  (Read 43 times)

0 Members and 1 Guest are viewing this topic.

Offline Quizmaster

  • Flying Nurse
  • Seasonal Competition Team
  • *
  • Posts: 23301
    • Smokey's Security Forums
  • .: Surf Queen
iPhone, Android App Sarahah Quietly Uploads Phone Contacts to Company Servers
« Reply #1 on: September 12, 2017, 08:15:43 PM »
iPhone, Android App Sarahah Quietly Uploads Phone Contacts to Company Servers
28 August 2017, 7:57 am

Sarahah is an application that has become a hit in a matter of months, and while many Android and iOS users rushed to install it, many of them didn’t have a clue that their phone contacts are being silently uploaded to the company’s servers.

The discovery was made by security analyst Zachary Julian and reported by The Intercept, which wrote that the same behavior happens on both Android and iOS once users provide the app with access to the contact list.

While an app requesting access to the phonebook is not unusual if the app in question does provide a feature that works with contacts, not the same thing can be said about Sarahah. No such functionality is available right now, but the developer says it’s exactly this reason why the company actually uploads the phone contacts to the company’s servers.

Update to remove phone contact collection feature... (read more)

Source: Softpedia News / Security

>> To obtain the full Softpedia Security News article, click the link in the first post line <<

 


Except where otherwise stated, all content, graphics, banners and images included © 2006 - 2018 Smokey Services™ -- All rights reserved
Design board graphics, banners and images by DSTM & PseFrank

This site does not store profiling-, tracking-, third-party and/or any other non-essential cookie(s) on client computers and is fully compliant with the EU ePrivacy Directive
Smokey's does not use any Web Analytics/Analysis Service, and also does not use any browser fingerprinting techniques



Smokey's also provides free fully qualified Log / Malware Analysis & Removal Help and System Health Checks