Monday, March 5, 2012

Loophole Could Give Android Devs a Private Picture Show

By Richard Adhikari
LinuxInsider

Someone has found a way for Android Apps to get the latest picture taken from a user's Android phone. Then they're posting it on a photo sharing website with out permission. How does this happen? "For some reason, the Android developers didn't establish permissions for photo access, so if your app has permission to access the Internet, it has access to your photos too," said the Yankee Group's Carl Howe. "Bouncer" was supposed to be a new layer to Android security. Bouncer supposedly analyzes newly uploaded apps for malware, spyware, and Trojans. Unfortunately it did not find the hackers getting Android users pictures.