{"id":59286,"date":"2014-01-28T01:14:58","date_gmt":"2014-01-27T23:14:58","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=59286"},"modified":"2025-07-02T00:55:22","modified_gmt":"2025-07-02T07:55:22","slug":"nsa-and-gchq-collected-personal-information-from-mobile-apps","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/nsa-and-gchq-collected-personal-information-from-mobile-apps\/","title":{"rendered":"NSA and GCHQ collected personal information from mobile apps"},"content":{"rendered":"<p>Newly leaked documents by Edward Snowden reveal that the NSA and British Government Communications Headquarters (GCHQ) have been collecting personal information from mobile apps such as <a title=\"Angry Birds news\" href=\"http:\/\/news.en.softonic.com\/b\/angry-birds\" target=\"_self\" rel=\"noopener noreferrer\">Angry Birds<\/a> and <a title=\"Flickr news\" href=\"http:\/\/news.en.softonic.com\/b\/flickr\" target=\"_self\" rel=\"noopener noreferrer\">Flickr<\/a>. The separate intelligence agencies have been working together since 2007, trading information about how to collect data from various smartphone apps. The information collected included age, sex, &#8220;political alignment,&#8221; and even geotag information from uploaded photos from apps like <a title=\"Facebook app download\" href=\"http:\/\/en.softonic.com\/s\/facebook:iphone-android\" target=\"_self\" rel=\"noopener noreferrer\">Facebook<\/a>, <a title=\"Flickr app download\" href=\"http:\/\/en.softonic.com\/s\/flickr:iphone-android\" target=\"_self\" rel=\"noopener noreferrer\">Flickr<\/a>, <a title=\"LinkedIn app download\" href=\"http:\/\/en.softonic.com\/s\/linkedin:iphone-android\" target=\"_self\" rel=\"noopener noreferrer\">LinkedIn<\/a>, and <a title=\"Twitter app download\" href=\"http:\/\/en.softonic.com\/s\/twitter:iphone-android\" target=\"_self\" rel=\"noopener noreferrer\">Twitter<\/a>.<\/p>\n<p><a title=\"PRISM: Leaked NSA slides explains real-time monitoring\" href=\"http:\/\/news.en.softonic.com\/prism-leaked-nsa-slides-explains-real-time-monitoring\" target=\"_self\" rel=\"noopener noreferrer\">Previously leaked documents<\/a> by Snowden revealed the extent of mobile data collection by the NSA. Earlier generations of mobiles phones were monitored for things like text messages and mobile network data, including mobile phone identifiers like IMEI numbers. The metadata was then tagged and stored in the NSA&#8217;s Xkeyscore\/Marina database to be made searchable.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-59298\" title=\"NSA mobile data tracking info\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/01\/NSA-mobile-data-tracking-info-568x426.jpg\" alt=\"NSA mobile data tracking info\" width=\"568\" height=\"426\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/NSA-mobile-data-tracking-info-568x426.jpg 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/NSA-mobile-data-tracking-info-256x192.jpg 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/NSA-mobile-data-tracking-info.jpg 814w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>As mobile phones became more powerful and complex, the NSA and GCHQ began <a title=\"Leaked NSA documents about smartphone data collection\" href=\"https:\/\/www.documentcloud.org\/documents\/1009660-nsa.html\" target=\"_blank\" rel=\"noopener noreferrer\">collecting more information<\/a> including website histories, &#8220;buddy lists,&#8221; downloaded documents, user agents, email addresses, and even BlackBerry PINS. Documents from the GCHQ reveal the agency&#8217;s intense interest in collecting mobile phone data. &#8220;By 2015 up to 90% of internet traffic will be accessed on mobile devices. Over 200 3rd party Location Aware Applications on the iPhone alone,&#8221; states a <a title=\"Leaked GCHQ document\" href=\"https:\/\/www.documentcloud.org\/documents\/1009661-gchq.html\" target=\"_blank\" rel=\"noopener noreferrer\">document from the GCHQ<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-59297\" title=\"GCHQ document\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/01\/GCHQ-document-568x439.png\" alt=\"GCHQ document\" width=\"568\" height=\"439\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/GCHQ-document-568x439.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/GCHQ-document-256x197.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/01\/GCHQ-document.png 1000w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>Worryingly, it appears that mobile ad networks are responsible for the collection of personal data from popular apps like Angry Birds. Ad company <a title=\"Millennial Media\" href=\"http:\/\/www.millennialmedia.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Millennial Media<\/a> worked with Angry Birds developer Rovio in 2011 to integrate ads into the game. The documents do not explain whether or not players offered up data about their ethnicity, marital status, and sexual orientation willingly or if the company accessed the information by other means.<\/p>\n<p>At the Samsung Developers Conference in 2013, <a title=\"Appthority\" href=\"https:\/\/www.appthority.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Appthority<\/a> held a seminar highlighting the dangers of mobile security. While the talk focused on the enterprise market, many of the company&#8217;s discoveries affect all users, not just those with enterprise devices. From its study, Appthority found that 41% of iOS and 77% of Android apps tracked location.<\/p>\n<p>Appthority found five major failures in mobile security:<\/p>\n<ol>\n<li>3rd party SDKs (including adware and analytics) cause security holes: One major risk is that some adware SDKs can perform tasks outside the original app permissions.<\/li>\n<li>Permissions bypass user consent: Apps can sidestep required permissions to complete the same behavior or add more permissions for unused functions.<\/li>\n<li>Include debug information from developer: This can contain information that can be used for targeted attacks against companies to steal data.<\/li>\n<li>Improper handling of private appdata: Some popular apps may encrypt data on its servers, but data is send through unsecure channels.<\/li>\n<li>Apps don&#8217;t apply security to user data: A lack of SSL\/encryption, storing passwords in plain text, and not using expiring oAuth tokens for login.<\/li>\n<\/ol>\n<p>This shows that the means to access user data is not as difficult as you would think. While many popular apps may look secure on the surface, the background functionality may be transmitting data openly for anyone to collect.<\/p>\n<p>There are still many unanswered questions about the NSA and GCHQ&#8217;s mobile data collection, including which countries the data was collected from, how often data was collected, and how the security agencies were able to collect this data without app developers noticing. And with this much data being collected, how much of it is actually used in the fight against terrorism?<\/p>\n<p><em><a title=\"Chris Park features\" href=\"http:\/\/features.en.softonic.com\/editor\/christopher-park\" target=\"_self\" rel=\"noopener noreferrer\">Chris Park<\/a> contributed to this story.<\/em><\/p>\n<p>Source: <a title=\"Spy Agencies Scour Phone Apps for Personal Data\" href=\"http:\/\/www.nytimes.com\/2014\/01\/28\/world\/spy-agencies-scour-phone-apps-for-personal-data.html?_r=0\" target=\"_blank\" rel=\"noopener noreferrer\">The New York Times<\/a><\/p>\n<h4>Read more about PRISM and the NSA<\/p>\n<ul>\n<li><a href=\"http:\/\/features.en.softonic.com\/nsa-scandal-how-closely-is-big-brother-watching-us\">NSA Scandal: How closely is Big Brother watching us?<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/microsoft-publishes-data-on-law-enforcement-requests\">Microsoft publishes data on law enforcement requests<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/facebook-and-yahoo-speak-out-over-prism-and-the-nsa\">Facebook and Yahoo! speak out over PRISM and the NSA<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/facebook-publishes-global-government-requests-report\">Facebook publishes Global Government Requests Report<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/court-sides-with-yahoo-requires-us-government-to-declassify-yahoo-docs-on-fisa\">Court sides with Yahoo!, requires US government to declassify Yahoo! docs on FISA<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/new-report-reveals-microsoft-worked-with-nsa-to-provide-access-to-outlook-com-skydrive-skype\">New report reveals Microsoft worked with NSA to provide access to Outlook.com, SkyDrive, Skype<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Newly leaked documents by Edward Snowden reveal that the NSA and British Government Communications Headquarters (GCHQ) have been collecting personal information from mobile apps such as Angry Birds and Flickr. The separate intelligence agencies have been working together since 2007, trading information about how to collect data from various smartphone apps. The information collected included &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/nsa-and-gchq-collected-personal-information-from-mobile-apps\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NSA and GCHQ collected personal information from mobile apps&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":59298,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-59286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/59286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=59286"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/59286\/revisions"}],"predecessor-version":[{"id":331469,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/59286\/revisions\/331469"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/59298"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=59286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=59286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=59286"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=59286"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=59286"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=59286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}