Jump to content

Researchers Issue Security Warning Over Android VPN Apps


uk666

Recommended Posts

  • Andr-Tech

Researchers Issue Security Warning Over Android VPN Apps

android_security_risk_popular_free_vpn_a

A research team has issued a warning over the lack of security in many VPN apps available from Google Play. A worrying 38% of the apps tested contained some kind of malware.

There is a misnomer about VPN networks and what they really do. Claims that they can make you “completely anonymous” online are usually inaccurate, even if they may increase your privacy to some degree. Unfortunately, the Commonwealth Scientific and Industrial Research Organisation (CSIRO), in partnership with the University of New South Wales and UC Berkley, have learned of greater issues than that.

In CSIRO’s research paper ‘An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps,’ the team investigated 283 Android VPN apps to explore their impact on user privacy and security. Here are some of the highlights of what they learned about the apps:

  • 18% do not encrypt traffic at all
  • 84% leak user traffic
  • 2 out of 3 use third-party tracking libraries
  • 38% reveal a malware or malvertising presence
  • More than 80 percent request sensitive data such as user accounts and text messages
  • Less than 1% of app reviews mention security or privacy concerns
  • Based on these findings, it is estimated that 4 out of 5 of Android VPN apps will ask for sensitive permissions, 4 out of 5 contain malware, 2 out of 5 are not even encrypted and some may be seeking to access your data to sell to third parties.

“The very reason users install these apps — to protect their data — is the very function they are not performing and these apps have been installed by tens of millions of users,” said CSIRO in the paper.

Worst offenders
Below is the researchers’ list of what were considered the most worrisome VPNs of those tested, five of which have been taken off the Play Store since the paper was published.

  • OkVpn [removed]
  • EasyVpn [removed]
  • SuperVPN [removed]
  • HatVPN [removed]
  • sFly Network Booster [removed]
  • Betternet
  • CrossVpn
  • Archie VPN
  • One Click
  • Fast Secure Payment

The apps in the list were those with the highest (worst) AV score, which tests apps for 5 different type of malware: Adware, Trojan, Malvertising, Riskware and Spyware. All of the apps excluding SuperVPN had a Play Store rating of 4.0 or more at the time, the research was published.
 

  • Like 1
  • Thanks 1
Link to comment

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
×
×
  • Create New...