Open 24/7/365

We Have A Life-Time Warranty /
Guarantee On All Products. (Includes Parts And Labor)

Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

Code placed in consumer-facing apps is tied to U.S. national-security contractors, documents show. Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

Google has yanked dozens of apps from its Google Play store after determining that they include a software element that surreptitiously harvests data.


Ultimate Resource On Private Blockchain Brave Browser

Online Privacy Tools And Tips

How To Protect Your Online Privacy While Working From Home

The Pandemic Turbocharged Online Privacy Concerns

California Lawmaker Says National Privacy Law Is a Priority

The Panamanian company that wrote the code, Measurement Systems S. de R.L., is linked through corporate records and web registrations to a Virginia defense contractor that does cyberintelligence, network-defense and intelligence-intercept work for U.S. national-security agencies.

The code ran on millions of Android devices and has been found inside several Muslim prayer apps that have been downloaded more than 10 million times, as well as a highway-speed-trap detection app, a QR-code reading app and a number of other popular consumer apps, according to two researchers who discovered the behavior of the code in the course of auditing work they do searching for vulnerabilities in Android apps.

Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

They shared their findings with Google, a unit of Alphabet Inc., federal privacy regulators and The Wall Street Journal.

Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

Measurement Systems paid developers around the world to incorporate its code—known as a software development kit, or SDK—into their apps, developers said. Its presence allowed the Panamanian company to surreptitiously collect data from their users, according to Serge Egelman, a researcher at the International Computer Science Institute and the University of California, Berkeley, and Joel Reardon of the University of Calgary.

Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

Modern apps often include SDKs written by little-known companies like Measurement Systems “that aren’t audited or well understood,” Mr. Egelman said. Inserting them is often enticing for app developers, who get a stream of income as well as detailed data about their user base.

“This saga continues to underscore the importance of not accepting candy from strangers,” Mr. Egelman said.

The two men—who also co-founded a company called AppCensus that examines the security and privacy of mobile apps—consider the software to be the most privacy-invasive SDK they have seen in the six years they have been examining mobile apps. It can “without a doubt be described as malware,” Mr. Egelman said.

Virginia-Based Defense Contractor Working For U.S. National-Security Agencies Use Google Apps To Secretly Steal Your Data

He and Mr. Reardon documented their findings on the Measurement Systems code in a report published Wednesday that was shared with the Journal and was earlier provided to the Federal Trade Commission. In the post, the two men detailed the list of apps where they found the code.

They also shared their findings in March with Google, which initiated an investigation resulting in the ban. “FTC investigations are nonpublic, we cannot comment on whether we are investigating a particular matter,” an FTC spokeswoman said.

The apps containing Measurement Systems software were removed from the Google Play Store as of March 25, according to Scott Westover, a Google spokesman, for collecting users’ data outside the rules that Google has established. Mr. Westover said the apps could be relisted if the software was removed. Some are already back in the App Store.

Google’s action doesn’t impair Measurement System’s ability to collect data from the millions of phones around the world where its software is already installed. Messrs. Egelman and Reardon found that the SDK stopped collecting data on its users and unplugged itself shortly after the two men began circulating their findings.

Measurement Systems software ran inside more than a dozen apps—including numerous Muslim-themed prayer apps such as Al Moazin and Qibla Compass, according to Messrs. Egelman and Reardon. The Measurement Systems software kit was present on apps downloaded on at least 60 million mobile devices and likely many more, according to the two researchers. Google declined to say how many apps in total contained the software.

According to their findings, the software’s true reach could be much larger as it can spot the existence of other devices running on the same Wi-Fi network as one using an app that has the code, potentially providing a way to map social networks.

Parfield, the Egypt-based developer of Al Moazin and other religious-themed apps, said it was told Measurement Systems was collecting data on behalf of internet-service providers as well as financial-service and energy companies. The makers of Qibla didn’t respond to a request for comment.

Measurement Systems told app-makers it wanted data primarily from the Middle East, Central and Eastern Europe and Asia, according to documents reviewed by the Journal—an unusual request because U.S. and Western European data typically commands the highest prices among commercial brokers. Several developers said Measurement Systems required them to sign nondisclosure agreements.

The Measurement Systems SDK was in other popular Android consumer apps, including weather apps, QR code scanners and the highway-radar detection app. Pixalate, a third-party company that monitors app analytics, provided the Journal with data about the geographical distribution of users of apps running Measurement Systems. One weather app that the code was running inside was particularly popular in Iran.

The SDK was harvesting a large amount of data about each user—including precise location, personal identifiers such as email and phone numbers as well as data about nearby computers and mobile devices, Messrs. Reardon and Egelman found.

While consumer-data brokers sometimes collect such data, they typically don’t include personalized identifiers such as email addresses and phone numbers, as that can run afoul of data-privacy laws.

The Measurement Systems SDK can also collect information that is stored in the phone’s clipboard—passwords, for example—whenever the cut-and-paste feature is used. And it has the ability to scan some parts of the phone’s file system, including specifically the files stored in the WhatsApp downloads folder, Messrs. Reardon and Egelman discovered.

It couldn’t necessarily read the contents of the files but it could match them against known files using a technique called compare-by-hash.

WhatsApp is widely used across the world as an alternative to text messages but it encrypts messages as they cross the internet, protecting user’s privacy but often frustrating the ability of law enforcement and intelligence agencies to intercept content.

“A database mapping someone’s actual email and phone number to their precise GPS location history is particularly frightening, as it could easily be used to run a service to look up a person’s location history just by knowing their phone number or email, which could be used to target journalists, dissidents, or political rivals,” Mr. Reardon wrote in a blog post explaining their findings.

The Defense Department and other national-security entities have previously said they buy large amounts of data sourced from commercial providers but have declined to discuss specifics. “As part of their authorized activities, Department of Defense Components purchase publicly and commercially available data to inform analysis of foreign threats to national security,” a Pentagon spokesman said previously.

Measurement Systems’ internet domain was registered in 2013 by a U.S.-based company named Vostrom Holdings Inc., according to web domain records from as recently as last month. Those records now list as being registered to a service that “protects the privacy of domain name holders.”

Vostrom does business with the federal government through a subsidiary, Packet Forensics LLC, according to corporate records. Measurement Systems S de R.L. also listed two holding companies as officers, both of which share a Sterling, Va., address with people affiliated with Vostrom, according to corporate records.

In addition, one of those people controlled a U.S. LLC with the same name: Measurement Systems LLC, according to corporate ownership records. It was dissolved the same week the Journal sought comment from Vostrom and Packet Forensics.

Measurement Systems said in an email: “The allegations you make about the company’s activities are false. Further, we are not aware of any connections between our company and U.S. defense contractors nor are we aware of…a company called Vostrom. We are also unclear about what Packet Forensics is or how it relates to our company.” Measurement Systems didn’t reply to questions about how their domain came to be registered by Vostrom.

Vostrom and its subsidiaries are affiliated with Rodney Joffe, a longtime cybersecurity consultant for the U.S. government, and are run by several of his protégés, according to corporate ownership records and a person familiar with the matter.

“Mr. Joffe has a minority ownership interest in Packet Forensics and serves as the nonexecutive chairman, but has had no operational role in the business for many years. Mr. Joffe has never had a financial interest in, or been engaged by, Vostrom Holdings,” said a spokeswoman for Mr. Joffe.

Mr. Joffe sources specialized data and capabilities for government entities, sometimes on classified programs, people familiar with his career say. He has figured prominently in a long-running controversy about the monitoring of web traffic at properties belonging to Donald Trump during the 2016 election.

As a growing percentage of information on the internet has become encrypted, governments have turned to software on mobile devices to collect information about people and the places they go. A robust market has emerged for collecting location data from phones, and government agencies have become major buyers of such data, the Journal has reported.

The data can include geolocation, prompting the growth of a multibillion-dollar location-analytics industry to understand the movements of people. Numerous technology executives whose companies don’t typically sell to the government have also described being approached by U.S. intelligence agencies and asked to voluntarily provide user data in bulk about their users, or to run warrantless queries of their data for law enforcement.

Measurement Systems offers to pay developers to include its software code in their mobile apps, saying the code collects “non-personal information about app users.”

In documents reviewed by the Journal, it told developers they could earn anywhere from $100 to $10,000—or more—a month depending on how many active users it could deliver. The company was particularly interested in users who had enabled the app to access a user’s location, the documents showed, but it emphasized that it didn’t need for such permissions to be enabled to collect data.

Related Articles:

AI Experts Warn of Potential Cyberwar Facing Banking Sector vs Bitcoin Which Can Be Stored Off-line

Researchers Use GPU Fingerprinting To Track Users Online

Vast Troves of Classified Info Undermine National Security, Spy Chief Says

San Francisco’s Historic Surveillance Law May Get Watered Down

Teen Cyber Prodigy Stumbled Onto Flaw Letting Him Hijack Teslas

Vast Troves of Classified Info Undermine National Security, Spy Chief Says

Ultimate Resource On Solana Outages And DDoS Attacks

Japan Defense Ministry Finds Security Threat In Hack

Alibaba Admits It Was Slow To Report Software Bug After Beijing Rebuke

US Ransomware Attack Suspect Hails From A Small Ukrainian Town

Google Issues Warning For 2 Billion Chrome Users

Can The IRS Be Trusted With Your Data?

Homeland Security Offers Hackers A Bounty To Find Bugs

Tech Giants Apple, Microsoft, Amazon And Others Warn of Widespread Software Flaw

Apple Sues NSO Group To Curb The Abuse Of State-Sponsored Spyware

How Crypto Vigilantes Are Hunting Scams In A $100 Billion Market

Verizon is Tracking iPhone Users by Default And There’s Nothing Apple Can Do. How to Turn It Off

Massive Encrypted Cellphone Hack Gave Police A Window On Cocaine, Cash And Killers

GoDaddy Breached – Plaintext Passwords – 1.2M Affected!!

Amazon’s Twitch Hack Shows Top Gamers Rake In Six-Figure Payouts

The Mercenary Threat of U.S. Hackers-for-Hire

A Hospital Hit By Hackers, A Baby In Distress: The Case Of The First Alleged Ransomware Death

Google’s Chrome Browser Is Under Active Attack, Patch Now!!!!

How Hackers Use Our Brains Against Us And How We Can Fight Back

AT&T 5G Upgrade Risks Silencing Home Alarms Reliant On Old Tech

Coinbase Users Angry With Customer Support After Funds Disappear From Accounts

Apple Cyber Flaw Allows Silent iPhone Hack Through iMessage

Biden Urges CEOs To Improve U.S. Cybersecurity After Attacks

How Hackers Hammered Australia After China Ties Turned Sour

Electric Vehicle Infrastructure Push Brings Cyber Concerns

Hacker Claims To Steal Data Of 100 Million T-Mobile Customers

Accenture Confirms Hack After LockBit Ransomware Data Leak Threats

CIA Weighs Creating Special China Unit In Bid To Out-Spy Beijing

Israel’s Mossad Intelligence Agency Is Seeking To Hire A Crypto Expert

US Taps Amazon, Google, Microsoft, Others To Help Fight Ransomware, Cyber Threats

US Drops Visa Fraud Cases Against Five Chinese Researchers

Want To Invest In Cybersecurity? Here Are Some ETFs To Consider

How To Protect Your Online Privacy While Working From Home

What Hackers Can Learn About You From Your Social-Media Profile

Biden Administration Blames Hackers Tied To China For Microsoft CyberAttack Spree

US Fights Ransomware With Crypto Tracing, $10 Million Bounties

Faces Are The Next Target For Fraudsters

Russia ‘Cozy Bear’ Breached GOP As Ransomware Attack Hit

Advertising Company Will Use Its Billboards To Track Passing Cellphones

REvil Ransomware Hits 200 Companies In MSP Supply-Chain Attack

What It Will Take To Protect Cities Against Cyber Threats

Home Security Company ADT Betting On Google Partnership To Build Revenue

Carnegie Cyber Kids Academy. World’s Most Prestigious Cyber Defense Training Facility

How To Opt Out Of Amazon’s Bandwidth-Sharing Sidewalk Network

Carnival Discloses Breach of Personal Data On Guests And Crew

UK Cyber Chief Cameron Says Ransomware Key Online Threat

The FBI Secretly Ran The Anom Messaging Platform, Yielding Hundreds Of Arrests In Global Sting

Federal Reserve Hacked More Than 50 Times In 4 Years

All of JBS’s US Beef Plants Were Forced Shut By Cyberattack

It Wasn’t Until Anonymous Payment Systems That Ransomware Became A Problem

How To Use Ian Coleman’s BIP39 Tool For Finding Bitcoin Addresses And Private Keys From A Seed Phrase

A New Ransomware Enters The Fray: Epsilon Red

This Massive Phishing Campaign Delivers Password-Stealing Malware Disguised As Ransomware

Biden Proposes Billions For Cybersecurity After Wave of Attacks

Mobile Crypto ‘Mining’ App Possibly Connected To Personal Data Leak

Ireland Confirms Second Cyber Attack On Health System

US Unveils Plan To Protect Power Grid From Foreign Hackers

Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals

A Hacker Was Selling A Cybersecurity Exploit As An NFT. Then OpenSea Stepped In

Clubhouse And Its Privacy & Security Risk

Using Google’s ‘Incognito’ Mode Fails To Prevent Tracking

Kia Motors America Victim of Ransomware Attack Demanding $20M In Bitcoin, Report Claims

The Long Hack: How China Exploited A U.S. Tech Supplier

Clubhouse Users’ Raw Audio May Be Exposed To Chinese Partner

Hacker Changed Chemical Level In Florida City’s Water System

UK Merger Watchdog Suffers 150 Data Breaches In Two Years

KeepChange Foils Bitcoin Theft But Loses User Data In Sunday Breach

Hacker Refuses To Hand Police Password For Seized Wallet With $6.5M In Bitcoin

SonicWall Says It Was Victim of ‘Sophisticated’ Hack

Tor Project’s Crypto Donations Increased 23% In 2020

Read This Now If Your Digital Wallet Which Holds Your Crypto-currencies Can Be Accessed Through Cellular, Wifi, Or Bluetooth

Armed Robbers Steal $450K From Hong Kong Crypto Trader

Is Your iPhone Passcode Off Limits To The Law? Supreme Court Ruling Sought

Researchers Warn 3 Apps Have Been Stealing Crypto Undetected For A Year

Ways To Prevent Phishing Scams In 2020

The Pandemic Turbocharged Online Privacy Concerns

US Treasury Breached By Foreign-Backed Hackers

FireEye Hack Portends A Scary Era Of Cyber-Insecurity

How FinCEN Became A Honeypot For Sensitive Personal Data

Apple And Google To Stop X-Mode From Collecting Location Data From Users’ Phones

Surge In Physical Threats During Pandemic Complicates Employee Security Efforts

Imagine A Nutrition Label—for Cybersecurity

Cybercriminals Attack GoDaddy-based Cryptocurrency Platforms

Biden Team Lacks Full U.S. Cybersecurity Support In Transition Fracas

Nasdaq To Buy Anti-Financial Crime Firm Verafin For $2.75 Billion

Mysterious Software Bugs Were Used To Hack iPhones and Android Phones and No One Will Talk About It

Dark Web Hackers Say They Hold Keys To 10,000 Robinhood Accounts #GotBitcoin

Hackers Steal $2.3 Million From Trump Wisconsin Campaign Account

Crypto Scammers Deface Trump Campaign Website One Week From Elections

Telecoms Protocol From 1975 Exploited To Target 20 Crypto Executives

With Traders Far From Offices, Banks Bring Surveillance To Homes

Financial Systems Set Up To Monitor Unemployment Insurance Fraud Are Being Overloaded (#GotBlockchain?)

A Millionaire Hacker’s Lessons For Corporate America

Container Shipping Line CMA CGM Says Data Possibly Stolen In Cyberattack

Major Hospital System Hit With Cyberattack, Potentially Largest In U.S. History

Hacker Releases Information On Las Vegas-Area Students After Officials Don’t Pay Ransom

Russian Troll Farms Posing As African-American Support For Donald Trump

US Moves To Seize Cryptocurrency Accounts Linked To North Korean Heists

These Illicit SIM Cards Are Making Hacks Like Twitter’s Easier

Uber Exec Allegedly Concealed 2016 Hack With $100K BTC ‘Bug Bounty’ Pay-Off

Senate Panel’s Russia Probe Found Counterintelligence Risks In Trump’s 2016 Campaign

Bockchain Based Surveillance Camera Technology Detects Crime In Real-Time

Trump Bans TicToc For Violating Your Privacy Rights While Giving US-Based Firm Go Ahead (#GotBitcoin?)

Facebook Offers Money To Reel In TikTok Creators

How A Facebook Employee Helped Trump Win—But Switched Sides For 2020

Facebook Rebuffs Barr, Moves Ahead on Messaging Encryption

Facebook Ad Rates Fall As Coronavirus Undermines Ad Spending

Facebook Labels Trump Posts On Grounds That He’s Inciting Violence

Crypto Prediction Markets Face Competition From Facebook ‘Forecasts’ (#GotBitcoin?)

Coronavirus Is The Pin That Burst Facebook And Google Online Ads Business Bubble

OpenLibra Plans To Launch Permissionless Fork Of Facebook’s Stablecoin (#GotBitcoin?)

Facebook Warns Investors That Libra Stablecoin May Never Launch (#GotBitcoin?)

FTC Approves Roughly $5 Billion Facebook Settlement (#GotBitcoin?)

How Facebook Coin’s Big Corporate Backers Will Profit From Crypto

Facebook’s Libra Is Bad For African Americans (#GotBitcoin?)

A Monumental Fight Over Facebook’s Cryptocurrency Is Coming (#GotBitcoin?)

Alert! 540 Million Facebook Users’ Data Exposed On Amazon Servers (#GotBitcoin?)

Facebook Bug Potentially Exposed Unshared Photos of Up 6.8 Million Users (#GotBitcoin?)

Facebook Says Millions of Users’ Passwords Were Improperly Stored in Internal Systems (#GotBitcoin?)

Advertisers Allege Facebook Failed to Disclose Key Metric Error For More Than A Year (#GotBitcoin?)

Ad Agency CEO Calls On Marketers To Take Collective Stand Against Facebook (#GotBitcoin?)

Thieves Can Now Nab Your Data In A Few Minutes For A Few Bucks (#GotBitcoin?)

New Crypto Mining Malware Beapy Uses Leaked NSA Hacking Tools: Symantec Research (#GotBitcoin?)

Equifax, FICO Team Up To Sell Your Financial Data To Banks (#GotBitcoin?)

Cyber-Security Alert!: FEMA Leaked Data Of 2.3 Million Disaster Survivors (#GotBitcoin?)

DMV Hacked! Your Personal Records Are Now Being Transmitted To Croatia (#GotBitcoin?)

Lithuanian Man Pleads Guilty In $100 Million Fraud Against Google, Facebook (#GotBitcoin?)

Hack Alert! Buca Di Beppo, Owned By Earl Enterprises Suffers Data Breach Of 2M Cards (#GotBitcoin?)

SEC Hack Proves Bitcoin Has Better Data Security (#GotBitcoin?)

Maxine Waters (D., Calif.) Rises As Banking Industry’s Overseer (#GotBitcoin?)

FICO Plans Big Shift In Credit-Score Calculations, Potentially Boosting Millions of Borrowers (#GotBitcoin?)

Our Facebook Page

Your Questions And Comments Are Greatly Appreciated.

Monty H. & Carolyn A.

Go back

Leave a Reply