Google said it remotely removed two apps from the handsets of Android users this week after determining that the developer of the free software programs had intentionally misrepresented their purpose to encourage downloads. However, Google said the free apps developed for security research did not pose security or privacy threats to Android users.
“They were not designed to be used maliciously, and did not have permission to access private data — or system resources” other than ready access to the Internet, wrote Android Security Lead Rich Cannings in a blog posted Wednesday.
Protecting Android Users
According to Cannings, the developer had already voluntarily removed the two apps from the Android Market and most users uninstalled them after a brief trial. Still, Google decided to exercise its right under the Android Market’s terms of service to remotely wipe the software from users’ handsets. “If an application is removed in this way, users will receive a notification on their phone,” he said.
Researchers at SMobile Systems warned earlier this week that the open nature of the Android Market — which allows anyone to develop and publish an application for download — could lead to consumers being defrauded for financial gain.
“Attackers are always trying to find new and inventive ways of harvesting large quantities of personal information,” wrote Troy Vennon and David Stroop in the SMobile report. “An efficient means to this goal is by distributing a seemingly innocent” program that users install “without giving credence to the types of access they are providing the application.”
However, Cannings noted that Android’s remote-wipe capability is just “one of many security controls” that Google has at its disposal to help protect users from malicious apps.
“In case of an emergency, a dangerous application could be removed from active circulation in a rapid and scalable manner to prevent further exposure to…