Hit App Sarahah Quietly Uploads Your Address Book

Sarahah, a new app that lets people sign up to receive anonymized, candid messages, has been surging in popularity; somewhere north of 18 million people are estimated to have downloaded it from Apple and Google’s online stores, making it the No. 3 most downloaded free software title for iPhones and iPads.

Sarahah bills itself as a way to “receive honest feedback” from friends and employees. But the app is collecting more than just feedback messages. When launched for the first time, it immediately harvests and uploads all phone numbers and email addresses in your address book. Although Sarahah does in some cases ask for permission to access contacts, it does not disclose that it uploads such data, nor does it seem to make any functional use of the information.

Zachary Julian, a senior security analyst at Bishop Fox, discovered Sarahah’s uploading of private information when he installed the app on his Android phone, a Galaxy S5 running Android 5.1.1. The phone was outfitted with monitoring software, known as Burp Suite, which intercepts internet traffic entering and leaving the device, allowing the owner to see what data is sent to remote servers. When Julian launched Sarahah on the device, Burp Suite caught the app in the act of uploading his private data.

“As soon as you log into the application, it transmits all of your email and phone contacts stored on the Android operating system,” he said. He later verified the same occurs on Apple’s iOS, albeit after a prompt to “access contacts,” which also appears in newer versions of Android. Julian also noticed that if you haven’t used the application in a while, it’ll share all of your contacts again. He did some testing of the app on a Friday night, and when he booted the app on a Sunday morning, it pushed all of his contacts again.

Source: Hit App Sarahah Quietly Uploads Your Address Book

The callous way companies like this, Sonos, Uber, Google, Microsoft etc etc etc handle your privacy like it’s dogshit is completely incredible.

‘Data is the new oil’: Your personal information is now the world’s most valuable commodity

What “the big five” are selling — or not selling, as in the case of free services like Google or Facebook — is access. As we use their platforms, the corporate giants are collecting information about every aspect of our lives, our behaviour and our decision-making. All of that data gives them tremendous power. And that power begets more power, and more profit.

On one hand, the data can be used to make their tools and services better, which is good for consumers. These companies are able to learn what we want based on the way we use their products, and can adjust them in response to those needs.

“It enables certain companies with orders of magnitude more surveillance capacity than rivals to develop a 360-degree view of the strengths and vulnerabilities of their suppliers, competitors and customers,” says Frank Pasquale, professor of law at the University of Maryland and author of Black Box Society.

Access to such sweeping amounts of data also allows these giants to spot trends early and move on them, which sometimes involves buying up a smaller company before it can become a competitive threat. Pasquale points out that Google/Alphabet has been using its power “to bully or take over rivals and adjacent businesses” at a rate of about “one per week since 2010.”

But it’s not just newer or smaller tech companies that are at risk, says Taplin. “When Google and Facebook control 88 per cent of all new internet advertising, the rest of the internet economy, including things like online journalism and music, are starved for resources.”

Traditionally, this is where the antitrust regulators would step in, but in the data economy it’s not so easy. What we’re seeing for the first time is a clash between the concept of the nation state and these global, borderless corporations.

Source: ‘Data is the new oil’: Your personal information is now the world’s most valuable commodity