Is your smartphone spying on you?

Some popular apps on your phone may be secretly taking screenshots of your activity and sending them to third parties, according to a new study by a team of Northeastern researchers.
The researchers said this is particularly disturbing because these screenshotsโand videos of your activity on the screenโcould include usernames, passwords, credit card numbers, and other important personal information.
โWe found that every app has the ability to record your screen and anything you type,โ said David Choffnes, one of two computer science professors who supervised the study. โThat includes your username and password, because it can record the characters you type before they turn into those little black dots.โ
The study, which was conducted largely by two studentsโundergraduate Elleen Pan and doctoral candidate Jingjing Renโwas designed to investigate a persistent urban legend that phones are secretly recording our conversations and then selling that information to companies so they can pepper you with targeted advertisements.
While the researchers found no evidence of recorded conversations, they discovered activity that could be even more dangerous.
โWe knew we were looking for a needle in a haystack,โ said Choffnes, โand we were surprised to find several needles.โ
What they found is that some companies were sending screenshots and videos of user phone activities to third parties. Although these privacy breaches appeared to be benign, they emphasized how easily a phoneโs privacy window could be exploited for profit.
โThis opening will almost certainly be used for malicious purposes,โ said Christo Wilson, another computer science professor on the research team. โItโs simple to install and collect this information. And whatโs most disturbing is that this occurs with no notification to or permission by users.
โIn the case we caught, the information sent to a third party was zip codes, but it could just as easily have been credit card numbers,โ he added.
The study
The researchers analyzed more than 17,000 of the most popular apps on the Android operating system, using an automated test program written by the students. Although the study was conducted on Android phones, both Wilson and Choffnes said there is no reason to believe that other phone operating systems would be less vulnerable.
Pan started the project as a research co-op in the fall of 2017 and continued to work on it until she graduated in May. She will present the paper in Barcelona later this month at the Privacy Enhancing Technology Symposium Conference.
โComing into this project, I didnโt think much about phone privacy and neither did my friends,โ said Pan, who is the first author on the paper. โThis has definitely sparked my interest in research, and I will consider going back to graduate school.โ
But for the time being, Pan is preparing for the Barcelona conference and starting a job in August as a software engineer for Square, a mobile payments company.
While conducting the research, Wilson said the team was quite surprised as the results came in.
We knew we were looking for a needle in a haystack, and we were surprised to find several needles.
David Choffnes, one of two Computer Science Professors who supervised the study
โThere were no audio leaks at allโnot a single app activated the microphone,โ he said. โThen we started seeing things we didnโt expect. Apps were automatically taking screenshots of themselves and sending them to third parties.โ
In all, 9,000 of the 17,000 apps had the potential to take screenshots.
โIn one case, the app took video of the screen activity and sent that information to a third party,โ said Wilson.
That app was GoPuff, a fast-food delivery service, which sent the screenshots to Appsee, a data analytics firm for mobile devices. All this was done without the awareness of app users.
Both Wilson and Choffnes emphasized that neither company appeared to have any nefarious intent. They said that web developers commonly use this type of information to debug their apps and improve the user experience.
But that doesnโt mean a malicious company couldnโt use this privacy window to steal personal information for profit.
โThat has the potential to be much worse than having the camera taking pictures of the ceiling or the microphone recording pointless conversations,โ said Choffnes. โThere is no easy way to close this privacy opening.โ
GoPuff has changed its terms of service agreement to alert users that the company may take screenshots of their use patterns. Google issued a statement emphasizing that its policy requires developers to disclose to users how their information will be collected.
But Wilson said this shields the companies from lawsuits while doing little to protect the privacy of users, who rarely read these long, legalistic agreements.
Both said the privacy window will not be closed until the phone companies redesign their operating systems, which isnโt likely to happen anytime soon.