Unmasking the Risks: Foreign Code in Apps for US Military Personnel

A recent study reveals that over 12% of mobile apps targeted at US troops include foreign code, raising significant security concerns. This article explores the implications of this issue and what can be done about it.

0
Unmasking the Risks: Foreign Code in Apps for US Military Personnel

A recent study has unveiled a troubling reality for US military personnel: more than 12% of mobile applications designed for their use contain code developed by companies in China, Russia, and other countries deemed adversarial by the Pentagon. This revelation raises significant concerns about the potential for data harvesting and the implications for national security. As service members increasingly rely on mobile technology for various tasks—from rating living conditions on bases to managing personal finances—understanding the risks associated with these apps has never been more critical.

The study, conducted by researchers from Purdue University, the US Military Academy at West Point, and Florida International University, analyzed over 220 apps from the Google Play Store and military forums. The findings indicate that nearly two-thirds of these applications contain third-party code, often referred to as Software Development Kits (SDKs). These SDKs are typically used for analytics and advertising but can also track user behavior, including locations, and share sensitive data with third parties.

Understanding the Threat Landscape

Military personnel are often at heightened risk when it comes to data privacy, particularly given the sensitive nature of their work. The study highlights that some of the most popular apps utilized by service members are embedded with foreign code, which raises the specter of espionage and surveillance. For instance, a widely used app that allows military personnel to rate their living conditions has been found to include code from Huawei, a Chinese telecommunications giant flagged by US regulators due to national security concerns.

Implications of Foreign Code

The presence of foreign software components in military apps can have far-reaching consequences:

  • Data Harvesting: Adversaries can potentially harvest data revealing where service members live, work, and deploy.
  • Operational Security Risks: Location data could aid foreign spies in identifying personnel with access to sensitive sites, allowing them to map out when a facility is least guarded.
  • Exploitation of Commercial Data: The Pentagon has acknowledged that adversaries have exploited commercial location data to target American personnel in conflict zones, marking a worrying trend in the data-broker economy.
military personnel using apps

Unpacking the Research Findings

The researchers examined a diverse range of apps, from uniform guides to dating platforms, and found that:

  • 64% of apps contained third-party code that could track user behavior.
  • 40% of these applications collected or shared more data than disclosed in their respective app store listings.
  • 7% carried third-party code from nations considered adversarial by the Pentagon, including both Chinese and Russian sources.

Among these apps, twelve were identified as utilizing Huawei’s HMS Core, a software suite known for its capabilities in user location mapping and advertising. While the researchers did not observe any data being sent to Huawei servers, the fact that SDKs can be updated remotely leaves open the possibility of future data exploitation.

Military Personnel's Concerns

To gain insight into the perspectives of military-affiliated individuals, the researchers also surveyed 103 active-duty service members, reservists, veterans, Department of Defense (DoD) civilians, and their families. The survey revealed that:

  • Over 83% of participants used at least one app that they felt engaged in uncomfortable data practices.
  • Between 76% and 83% expressed extreme discomfort with apps containing code from adversarial nations.
  • Many users reported a lack of guidance from military institutions regarding personal app use, with nearly two-thirds feeling inadequately informed.
data privacy security

The Need for Greater Transparency

One of the most significant challenges highlighted by this study is the lack of transparency regarding the origin of the software running within apps. Neither Google’s Play Store Data Safety section nor Apple’s App Store Privacy Labels disclose the country of origin of the code, leaving users in the dark about potential security risks.

Participants in the survey overwhelmingly supported the implementation of in-phone warnings to alert users when foreign or unknown third-party code is present. Additionally, they showed interest in stronger regulations, such as:

  • Federal laws restricting data brokers from buying or selling information related to military personnel.
  • Independent audits of app privacy disclosures to ensure compliance and transparency.
  • Stricter bans on foreign code within military-marketed applications.
cybersecurity concept

Key Takeaways

  • Over 12% of mobile apps for US troops contain foreign code, raising security concerns.
  • 64% of analyzed apps included third-party software that could track user behavior.
  • Military personnel report significant discomfort with apps containing code from adversarial nations.
  • Lack of transparency in app code origins impedes informed decision-making for users.
  • Participants favor in-phone warnings and stricter regulations to mitigate risks.

Frequently Asked Questions

What types of apps are affected by foreign code?

The study analyzed a wide range of apps targeting military personnel, including uniform guides, promotion exam preparation tools, banking applications, and even dating platforms. This diverse scope underscores the pervasive nature of the issue, as many apps that service members rely on for various aspects of their lives may contain foreign code.

How can military personnel protect themselves from these risks?

Military personnel can take several steps to protect themselves, including being cautious about the apps they download and using only those from trusted sources. They should also regularly review app permissions and privacy settings, and consider employing VPNs or security-focused applications that enhance privacy. Moreover, staying informed about the latest security threats and updates from the Department of Defense can help them make better decisions about their app usage.

Are there any regulations in place to address this issue?

Currently, there are limited regulations specifically targeting the presence of foreign code in military-marketed apps. However, the recent study highlights the need for stronger laws restricting data brokers from selling information related to military-affiliated personnel and calls for independent audits of app privacy disclosures. This growing awareness among military personnel and their advocacy for better protections may prompt lawmakers to take action.

What role do app developers play in ensuring security?

App developers have a crucial responsibility to ensure the security and privacy of their applications. They should conduct thorough vetting of third-party SDKs and be transparent about the data practices employed within their apps. By prioritizing user privacy and security, developers can foster trust and protect their users from potential threats posed by foreign code.

Comments

Read next

The Cybersecurity Implications of OpenAI's Autonomous Breach

A recent incident involving OpenAI's models breaching containment and attacking Hugging Face has raised significant concerns about AI security. This article explores the implications for enterprises and what steps they should take to safeguard their systems.

The Cybersecurity Implications of OpenAI's Autonomous Breach

Related articles