{"id":39689,"date":"2018-02-14T11:56:50","date_gmt":"2018-02-14T10:56:50","guid":{"rendered":"http:\/\/diaridigital.urv.cat\/?p=39689"},"modified":"2018-02-19T14:00:27","modified_gmt":"2018-02-19T13:00:27","slug":"mobile-health-applications-put-the-personal-data-of-millions-of-users-at-risk","status":"publish","type":"post","link":"https:\/\/diaridigital.urv.cat\/en\/mobile-health-applications-put-the-personal-data-of-millions-of-users-at-risk\/","title":{"rendered":"Mobile health applications put the personal data of millions of users at risk"},"content":{"rendered":"<p>80% of the most popular health applications available on Android do not comply with standards intended to prevent the misuse and dissemination of their users\u2019 data. This is the finding of a European study started in 2016 and involving Agust\u00ed Solanas, head of the Smart Health research group at the URV\u2019s Department of Computer Engineering and Mathematics, and researchers from the University of Piraeus (Greece) headed by Constantinos Patsakis. The research has brought to light evidence of serious security problems regarding the twenty most popular applications on the internet. The research consisted of analysing the security problems, communicating them to the software developers and then checking them to see if they had been resolved.<\/p>\n<p>The applications chosen by the researchers had been downloaded between 100,000 and 10 million times and had a minimum rating of 3.5 out of 5. To analyse their levels of security, the researchers intercepted, stored and monitored private data relating to users\u2019 health problems, illnesses and medical records. The researchers analysed how the applications communicated, how they stored information, which permissions they required to operate, and how they handled the data. The results showed the existence of serious security problems in the way users\u2019 data were handled.<\/p>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_39364\" aria-labelledby=\"figcaption_attachment_39364\" class=\"wp-caption aligncenter\" style=\"width: 2681px\"><a href=\"http:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-39364\" src=\"http:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas.jpg\" alt=\"Agust\u00ed Solanas \u00e9s un dels investigadors principals d'aquesta recerca. \" width=\"2681\" height=\"1805\" srcset=\"https:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas.jpg 2681w, https:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas-300x202.jpg 300w, https:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas-768x517.jpg 768w, https:\/\/diaridigital.urv.cat\/wp-content\/uploads\/2018\/02\/Agusti-solanas-1024x689.jpg 1024w\" sizes=\"auto, (max-width: 2681px) 100vw, 2681px\" \/><\/a><figcaption id=\"figcaption_attachment_39364\" class=\"wp-caption-text\">The researcher Agust\u00ed Solanas.<\/figcaption><\/figure>\n<p>Only 20% of the applications stored the data on the user\u2019s smartphone, and one in two requested and administered passwords without using a secure connection. The researchers also found that 50% of the applications shared data with third parties, including text, multimedia content or X-ray images. More than half transferred users\u2019 health data via HTTP links, which means that anybody with access can get their hands on the data.<\/p>\n<p>20% of the applications did not inform the user of any privacy policy or the content was not available in English, the language of the application. Others requested access to geolocation, microphones, cameras, contact lists, external storage cards and Bluetooth, even though the application did not need access to these data to operate.<\/p>\n<h5>Information for businesses<\/h5>\n<p>On completing the analysis, the researchers contacted the software developers to inform them of the security problems. After waiting for a given period, they then analysed the same parameters and found that although some of the security issues had been fixed (e.g. insecure health data transfers or the ability to identify users via insecure data transfers to third parties), other problems such as data leaks regarding the use of the application had not been resolved.\nThe research has been partially funded by the European OPERANDO project (as part of the H2020 programme) and has also received funding from the COST programme (Cooperation in Science and Technology) through Acci\u00f3 Cryptacus.<\/p>\n<p><strong>Reference: <\/strong>&#8220;Security and Privacy Analysis of Mobile Health\nApplications: The Alarming State of Practice&#8221;. A. Papageorgiou, M. Strigkos, E. Politou, E. Alepis, A. Solanas, C. Patsakis.\u00a0 <em>IEEE Explore<\/em>. DOI: <a href=\"http:\/\/ieeexplore.ieee.org\/document\/8272037\/\">10.1109\/ACCESS.2018.2799522<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A study detects serious security problems after analysing the twenty most popular Android health apps<\/p>\n","protected":false},"author":5,"featured_media":39352,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[806,3462,82,236,818,195,805,786,178,196],"tags":[],"class_list":["post-39689","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-communicating-science","category-computer-engineering-mathematics","category-general-en","category-health","category-press-releases","category-research","category-research-centres","category-school-engineering","category-science-technology","category-international"],"acf":[],"_links":{"self":[{"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/posts\/39689","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/comments?post=39689"}],"version-history":[{"count":0,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/posts\/39689\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/media\/39352"}],"wp:attachment":[{"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/media?parent=39689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/categories?post=39689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/diaridigital.urv.cat\/en\/wp-json\/wp\/v2\/tags?post=39689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}