Results 1 to 6 of 6
Like Tree3Likes
  • 3 Post By FunkY

Thread: Privacy-violating, useless AVG antivirus app pulled from Windows Phone Marketplace

  1. #1
    Star
    Overall activity: 0%

    Join Date
    Apr 2010
    Posts
    1,996
    Liked
    460 times
    Points
    38,635

    Angry Privacy-violating, useless AVG antivirus app pulled from Windows Phone Marketplace

    Privacy-violating, useless AVG antivirus app pulled from Windows Phone Marketplace
    By Peter Bright | Published 2 days ago



    To the surprise of many, an antivirus application was published on the Windows Phone Marketplace earlier in the week. The publication of AVG Mobilation for Windows Phone was peculiar for two main reasons. The first is that Windows Phone simply doesn't have any viruses to scan for. Second, Windows Phone applications are sandboxed; they have no access to the system files or other applications. Even if a virus were to be developed for the platform, the virus scanner would not be able to detect or remove it.

    AVG was apparently undaunted by these obstacles, and developed the free, but ad-supported, Mobilation regardless. Though Windows Phone gives applications no ability to access most files on the system, there are some exceptions. Third-party software can access photos and music stored on the device, and so, for lack of anything better to scan, this is what Mobilation examines.

    Or at least, what it pretends to examine. Analysis by Rafael Rivera suggested that it was not even particularly thorough in the scanning it did perform: it checked the names of the files it scanned and if they matched the string "eicar" or "עברית" it flagged them as "suspicious". "eicar" is a reference to the EICAR file used to test anti-virus software. "עברית" is Hebrew written in Hebrew. Its significance is not obvious.

    Being merely useless is not, however, against the terms of the Windows Phone Marketplace, and even with its restrictions, there is the possibility that the platform does attract viruses. Some of these might even use music and image files to propagate. AVG putting the infrastructure in place to scan these files is not entirely unreasonable.

    However, further investigation showed that the software was not merely useless. Ex-Microsoft employee Justin Angel decompiled the program and found that it collects a range of information—including the phone's unique ID, the network operator, the owner's e-mail address—and then sends this information, along with the phone's GPS location, to AVG's servers.

    The relevance of this information to a virus-scanner appears to be negligible.

    The evidence of shady behavior led to Microsoft pulling the application late last night, so that it could investigate fully.

    AVG in turn made a lengthy blog post in support of its product. However, the post is remarkably quiet about any of the allegations made of Mobilation. It talks about another security product for Windows Phone that AVG released at the same time, a "Safe Search" application that verifies the safety of URLs to block access to malicious websites—but this is irrelevant to the complaints being made.

    The post also talks about the malware threat on Android and attempts to use this to justify the development of the Windows Phone product; it describes it as a "step in the right direction." That there are marked differences between Windows Phone's curated Marketplace and Android's free-for-all Market has been ignored.

    Finally, the post concludes with a statement that AVG takes privacy very seriously, that it won't sell the data it collects, and that nobody should have anything to worry about. It avoids explaining why it needs the data in the first place.

    Repeated requests to the company for further information have gone unanswered.

    Update: AVG says that the data collection is for the phone tracking feature that their software provides. It's enabled by default, they say, because they don't want users to be in the position of having lost their phone without enabling the feature. Quite how it works on a platform with no multitasking is unclear, as is the necessity of a second location tracking feature: Windows Phone itself already includes this functionality.

    As well as talking about its own software, AVG also took great pains to claim that the software was produced with the full knowledge and involvement of Microsoft, and that it made alterations at Microsoft's request. Exactly what this means is unclear; it could mean simply that the application was initially rejected from Marketplace and that AVG had to make changes in order to have it approved for publication at all, or it could mean that Microsoft was actively involved in the product's development. We are awaiting comment from Microsoft to clarify the situation.

    Update: Microsoft tells us only that "AVG's app has been removed from Windows Phone Marketplace while we work with AVG to ensure that the app is in full compliance with our published policies."

    If the product was indeed written with Microsoft's involvement, that raises further questions. The presence of a virus-scanner, even if useless, does Windows Phone no favors. The image of desktop Windows is seriously tarnished by the malware specter, and allowing a (largely bogus) anti-virus program onto the phone platform serves only to taint that, too.

    Photograph by Rafael Rivera


    Source
    http://arstechnica.com/microsoft/new...arketplace.ars

    Yes you are right -> English is not my nature language = Me talk bad English

  2. #2
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    Wow...
    Every day brings a chance for you to draw in a breath, kick off your shoes, and dance.

  3. #3
    sm1
    sm1 is offline
    Experienced User
    Overall activity: 5.0%

    Join Date
    Nov 2009
    Posts
    769
    Liked
    57 times
    Points
    8,760
    There's no such thing as a free lunch I am always skeptical about free av software. I am becoming paranoid now

  4. #4
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Thank you FunkY a good read, and not what i was expecting, so really it's all a ploy and AVG have been found out.. i have no problems with them, but i can see them been bitten by this report... naughty but sm1 made a good point and i agree there is no such thing as a free lunch.
    Last edited by JayCub; 09-13-2011 at 01:39 AM. Reason: it's not my keyboard it's me

  5. #5
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    wow nice move from Grisoft AVG
    AVG spyware for Windows mobile phone.

    [edit to add]
    AVG antispyware 7.5 was excellent in my opinion, formerly known as Ewido Anti-Spyware, old times
    Last edited by leofelix; 09-13-2011 at 05:30 PM.
    Roger and out

  6. #6
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Saw this via Stumbleupon, some of the comments on Ars mimic my own if I was commenting on them.
    pacman -Syyu life not found in sync db

 

 

Similar Threads

  1. Nokia to release Windows Phone 7?
    By dredge in forum Mobile Phone
    Replies: 2
    Last Post: 09-25-2010, 10:15 AM
  2. KIN - a new Windows Phone
    By safeguy in forum Mobile Phone
    Replies: 0
    Last Post: 04-14-2010, 12:34 AM
  3. Try out Windows Phone 7 on your PC today
    By riteshtechie in forum General Forum
    Replies: 0
    Last Post: 03-19-2010, 12:29 AM
  4. Replies: 1
    Last Post: 11-12-2007, 02:57 PM
All times are GMT +8. The time now is 09:57 AM.