Drupe app back on the Google Play Store following security vulnerability

Smart Android And Trik-Commenting on Andorid indeed never endless, because smart devices this one is often updated every certain amount of time. So that the market can always be garapnya menerinya with pleasure. And it is not denied if this device has become the lifestyle of each society. To not wonder if the 6th business information and many are turning to mobail smartphone. With Android which thoroughly dominated the mobile industry, choosing the best Android smartphone is almost identical to choose the best smartphone, period. But while Android phones have few real opponents on other platforms, internal competition is intense.

From the sleek devices impress with the design premium, up to a full plant furniture features, to a very good device, and affordable mobile phone has a heavy weight, the Android ecosystem inhabited by a diverse range of attractive mobile phone Drupe app back on the Google Play Store following security vulnerability Drupe app back on the Google Play Store following security vulnerability,But "oversize" are subjective, and sometimes pieces of the specification and a list of features is not enough to get an idea of how good a phone. In this roundup, we look at the absolute best-the Android phone you can't go wrong with. The habits of young people or to accentuate trand blindly lifestyle, make this a medoroang this clever device industry vying to do modifications to the device, with a distinctly vitur vitur-tercanggihnya. So it can be received over the counter Drupe app back on the Google Play Store following security vulnerability

  • Drupe is a popular dialer app that incorporates different apps under one roof, creating a kind of "master" contacts app.
  • Last week, the app was removed from the Play Store when it was discovered that user data was available online to anyone who knew where to find it.
  • Drupe is back on the Play Store now, and the vulnerability has been patched. But is that enough?

Last week, a security vulnerability in the popular dialer app Drupe was discovered that left the data of tens-of-thousands of users open to anyone who wanted to view it. When the vulnerability was exposed, the Drupe app was removed from the Google Play Store.

However, the app is now back on the Google Play Store for anyone who would like to download it. I just tested a download, install, and activation of the app on my OnePlus 5 running Android 8.1 Oreo, and everything went as expected.

The question is: how many people will actually keep the app after the exposure of this massive vulnerability?

Drupe's security issues were first brought to light by security researcher Simone Margaritelli, who corresponded with Motherboard on the topic. Margaritelli discovered the vulnerabilities and started live-tweeting his findings; however, he did not disclose the name of the app he was investigating at the time.

Editor's Pick

Margaritelli found that some of the copious amounts of data Drupe collects from users was being stored on an insecure Amazon Web Services server. That means that anyone who knew where to look could view call histories, pictures, and even audio recordings of messages.

Motherboard verified Margaritelli's information and found that it was indeed easy for anyone to gain access to the data on the server. Furthermore, the team discovered that, in theory, one could pretty easily extrapolate user IDs and thus access any one users' entire Drupe history.

Anyone with an internet connection and the knowledge of where to look had access to Drupe's user data.

While Margaritelli was live-tweeting this info, someone else

pieced together which app the tweets were about. This user reported it to Google, which in turn removed Drupe from the Google Play Store sometime on Tuesday last week.

Drupe posted on its blog that it fixed the security vulnerability "within an hour" of discovery. It also clarified that only about 3 percent of Drupe users were affected by the vulnerability.

However, the whole situation raises a real concern about using Drupe: exactly how much information is the app collecting from its users, and does it really need that much?

Margaritelli believes that Drupe is actually a data harvester app. He said, "Regardless of whether the app is malicious or not, it has no logical reason to gather all this data and store it on its servers." During his original live-tweet session, he posted this screenshot of all the permissions Drupe gets from its users:

Editor's Pick

Drupe, in response, said that "all of the permissions requested by Drupe to access user data are strictly needed to operate Drupe service features and are never used for any purpose other than for providing these features. No user data, under any circumstances, is being shared with third parties for their commercial uses nor is any user data commercialized in any way. Drupe's business model is completely based on in-app purchases and advertisements."

While that makes Drupe's intentions seem pretty clear, one can't help but wonder: what is the company going to do to assure users that this kind of vulnerability won't happen again?

We reached out to Drupe to answer that very question, but it did not respond before press time. We will update this article should the company issue a statement on the matter.

A Google spokesperson told Motherboard that it is "in contact with [Drupe] about the app's handling of user data." Presumably, Drupe addressed all of Google's concerns because the app is once again available for download. But will anyone download it?

NEXT: 5 best dialer apps and contacts apps for Android



from Android Authority https://ift.tt/2Iz8M6D
via IFTTT

Read:


Subscribe to receive free email updates:

Related Posts :

0 Response to "Drupe app back on the Google Play Store following security vulnerability"

Post a Comment