{"id":16106,"date":"2017-04-04T11:26:32","date_gmt":"2017-04-04T15:26:32","guid":{"rendered":"http:\/\/www.megalextoria.com\/wordpress\/?p=16106"},"modified":"2017-04-04T11:26:32","modified_gmt":"2017-04-04T15:26:32","slug":"an-update-on-verizons-appflash-pre-installed-spyware-is-still-spyware","status":"publish","type":"post","link":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/2017\/04\/04\/an-update-on-verizons-appflash-pre-installed-spyware-is-still-spyware\/","title":{"rendered":"An Update on Verizon&#8217;s AppFlash: Pre-Installed Spyware Is Still Spyware"},"content":{"rendered":"<p>Verizon recently <a href=\"https:\/\/techcrunch.com\/2017\/03\/28\/evie-verizon-sidescreen\/\">rolled out<\/a> a new pilot project to pre-install on customers\u2019 devices an app launcher\/search tool that, we believe, is really just spyware. This software, called AppFlash, is preloaded on a new model of LG device\u2014<a href=\"https:\/\/www.verizon.com\/about\/news\/get-lg-k20-v-verizon-today\">the LG K20 V<\/a>\u2014rather than in all of their Android line as we previously reported. The software allows Verizon and its partners to track the apps you have downloaded and then sell ads to you across the Internet based what those apps say about you, like which bank you use and whether you\u2019ve downloaded a fertility app.<\/p>\n<p>Verizon is touting \u201cAppFlash\u201d as a customer benefit. In reality, it is just the latest display of wireless carriers\u2019 stunning willingness to compromise the security and privacy of their customers by preloading unwanted apps on users\u2019 devices. To see how AppFlash is dangerous, just look at the <a href=\"https:\/\/www.verizon.com\/about\/privacy\/appflash-privacy-policy\">Privacy Policy<\/a>. It states that the app can be used to:<\/p>\n<blockquote><p>\u201ccollect information about your device and your use of the AppFlash services. This information includes your mobile number, device identifiers, device type and operating system, and information about the AppFlash features and services you use and your interactions with them. We also access information about the list of apps you have on your device.\u201d<\/p><\/blockquote>\n<p>Troubling as it may be to collect intimate details about what apps you have installed, the policy also illustrates Verizon\u2019s intent to gather location and contact information:<\/p>\n<blockquote><p>\u201cWith your permission, AppFlash also collects information about your device\u2019s precise location from your device operating system as well as contact information you store on your device.\u201d<\/p><\/blockquote>\n<p>And what will Verizon use all of this information for? Why, targeted advertising on third-party websites across the Internet, of course:<\/p>\n<blockquote><p>\u201cAppFlash information may be shared within the Verizon family of companies, including companies like AOL who may use it to help provide more relevant advertising within the AppFlash experiences and in other places, including non-Verizon sites, services and devices.\u201d<\/p><\/blockquote>\n<p>With the announcement of AppFlash, Verizon has made clear that it intends to start monetizing our private data as soon as possible, if not sooner. In other words, <a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/03\/five-creepy-things-your-isp-could-do-if-congress-repeals-fccs-privacy-protections\">our prediction that mobile Internet providers would start pre-installing spyware on their customers\u2019 phones<\/a> has come true, even before <a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/03\/congress-sides-cable-and-telephone-industry\">Congress changed the rule to let ISPs like Verizon, AT&amp;T, and Comcast sell your personal data<\/a> to advertisers. In our view, the FCC&#8217;s privacy rules that Congress has voted to roll back would have prohibited Verizon from pre-installing the AppFlash spyware on its phones in this manner\u2014and we can expect Congress&#8217; privacy rollback to embolden further privacy-invasive practices by ISPs.<\/p>\n<p>Last week, Verizon sent us <a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/03\/first-horseman-privacy-apocalypse-has-already-arrived-verizon-announces-plans\">a statement<\/a> about its roll out of AppFlash, asserting that \u201cyou have to opt-in to use the app.\u201d While it\u2019s true that the user is presented with a click-through license the first time they launch AppFlash, it\u2019s entirely unclear from that screen what information is being collected or shared. Instead, those crucial details are buried within the fine print of a Terms of Service. That\u2019s hardly a meaningful mechanism for obtaining informed opt-in consent.<\/p>\n<p>What are the ramifications? For one thing, this is yet another entity that will be collecting sensitive information about your mobile activity on your Android phone. It\u2019s bad enough that Google collects much of this information already and <a href=\"https:\/\/www.eff.org\/deeplinks\/2014\/08\/blocking-consumer-choice-googles-dangerous-ban-privacy-security-app\">blocks privacy-enhancing tools from being distributed through the Play Store<\/a>. Adding another company that automatically tracks its customers doesn\u2019t help matters any.<\/p>\n<p>But our bigger concern is the increased attack surface an app like AppFlash creates. It is likely that with Verizon rolling this app out on certain new phones, hackers will be probing it for vulnerabilities, to see if they can use it as a backdoor they can break into. We sincerely hope Verizon has invested significant resources in ensuring that AppFlash is secure, because if it\u2019s not,<a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/03\/five-ways-cybersecurity-will-suffer-if-congress-repeals-fcc-privacy-rules\"> the damage to users\u2019 cybersecurity could be disastrous<\/a>, especially if Verizon expands its \u201ctest\u201d to additional devices.<\/p>\n<p>Verizon should immediately abandon its plans to monitor its customers\u2019 behaviors, and do what it\u2019s paid to do: deliver quality Internet service without spying on users. And in no case should Verizon expand its test of this spyware to additional models of mobile devices.<\/p>\n<p class=\"raindrops-press-this\">Source: <em><a href=\"https:\/\/www.eff.org\/deeplinks\/2017\/04\/update-verizons-appflash-pre-installed-spyware-still-spyware\">An Update on Verizon&#8217;s AppFlash: Pre-Installed Spyware Is Still Spyware | Electronic Frontier Foundation<\/a><\/em><\/p>\n<p><script type=\"text\/javascript\" src=\"http:\/\/www.miniurls.co\/Webservices\/jsParseLinks.aspx?id=DJhZ4\"><\/script>\n","protected":false},"excerpt":{"rendered":"<p>Verizon recently rolled out a new pilot project to pre-install on customers\u2019 devices an app launcher\/search tool that, we believe, is really just spyware. This software, called AppFlash, is preloaded on a new model of LG device\u2014the LG K20 V\u2014rather than in all of their Android line as we previously reported. The software allows Verizon and its partners to track the apps you have downloaded and then sell ads to you across the Internet based what those apps say about you, like which bank you use and whether you\u2019ve downloaded a fertility app. Verizon is touting \u201cAppFlash\u201d as a customer benefit. In reality, it is just the latest display of wireless carriers\u2019 stunning willingness to compromise the security and privacy of their customers by preloading unwanted apps on users\u2019 devices. To see how AppFlash is dangerous, just look at the Privacy Policy. It states that the app can be used to: \u201ccollect information about your device and your use of the AppFlash services. This information includes your mobile number, device identifiers, device type and operating system, and information about the AppFlash features and services you use and your interactions with them. We also access information about the list of apps [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[2550,1602,1879],"class_list":["post-16106","post","type-post","status-publish","format-standard","hentry","category-news-and-politics","tag-appflash","tag-spyware","tag-verizon"],"_links":{"self":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts\/16106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/comments?post=16106"}],"version-history":[{"count":0,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts\/16106\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/media?parent=16106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/categories?post=16106"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/tags?post=16106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}