{"id":80595,"date":"2021-02-03T09:46:30","date_gmt":"2021-02-03T04:16:30","guid":{"rendered":"https:\/\/www.technologyforyou.org\/?p=80595"},"modified":"2021-02-03T09:46:30","modified_gmt":"2021-02-03T04:16:30","slug":"more-privacy-control-for-all-with-tinycheck-tool","status":"publish","type":"post","link":"https:\/\/www.technologyforyou.org\/more-privacy-control-for-all-with-tinycheck-tool\/","title":{"rendered":"More privacy control for all with TinyCheck tool"},"content":{"rendered":"<p class=\"PageHeadline_text__Yh8Go PageHeadline_text__3S6bw\"><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 14pt; color: #000080;\">To increase privacy control over users\u2019 data, two Kaspersky experts have combined the results of their research and upgraded the openly available TinyCheck tool. Initially developed as a stalkerware detection tool for service organizations working with victims of domestic violence, TinyCheck now also offers help to uncover all types of geo-tracking apps.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">In December 2020, Apple and Google\u00a0prohibited\u00a0any apps in their stores which use X-Mode\u2019s technology that secretly enables tracking and selling of location data. Several months prior to the tech companies\u2019 decision, Kaspersky\u2019s Global Research and Analysis Team (GReAT) director, Costin Raiu started to analyze such apps after he had seen a\u00a0visualization\u00a0that identified people\u2019s movements using their GPS data made available by X-Mode.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Raiu found more than 240 distinct apps with X-Mode\u2019s tracking technology which in total have been installed more than 500 million times. Such data collection becomes possible when developers embed a component \u2013 a software development kit (SDK) \u2013 in their app. The problem with these tracking SDKs is that it is impossible for a user to tell whether an app contains such location tracking components. Also, the app may have a legitimate reason to ask for the user\u2019s location as many rely on location to function properly, but such an app might also sell the GPS data.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">In addition, any app can contain more than just one tracking SDK. For example, while Raiu was looking at an app that included the X-Mode SDK in question, he discovered five other components from other companies that were also collecting location data.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><strong>Making life harder for secret trackers<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Now, Raiu\u2019s findings have been integrated into\u00a0<a href=\"https:\/\/github.com\/KasperskyLab\/tinycheck\">TinyCheck<\/a>, an open-source tool developed and\u00a0<a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2020_kaspersky-and-the-coalition-against-stalkerware-one-year-on-in-the-fight-for-digital-privacy\">published<\/a>\u00a0in November last year by F\u00e9lix Aim\u00e9, another of Kaspersky\u2019s GReAT experts. Initially, TinyCheck was developed to help tackle the issue of stalkerware.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Stalkerware is software used to secretly spy on another person\u2019s private life via a smart device and also installed without the user\u2019s knowledge. While often used to facilitate violence against an intimate partner, the software may also be used in a different context. TinyCheck can now detect both stalkerware and tracking apps, but the tool issues two different alerts to the user.\u00a0<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><img decoding=\"async\" src=\"https:\/\/www.kaspersky.com\/content\/en-global\/images\/repository\/pr\/2021\/tc.png\" alt=\"tc.png\" \/><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><em>A TinyCheck alert when stalkerware is detected.<\/em><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><img decoding=\"async\" src=\"https:\/\/www.kaspersky.com\/content\/en-global\/images\/repository\/pr\/2021\/tcc.png\" alt=\"tcc.png\" \/><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><em>A TinyCheck alert when geo-tracking apps are detected.<\/em><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><img decoding=\"async\" src=\"https:\/\/www.kaspersky.com\/content\/en-global\/images\/repository\/pr\/2021\/tccc.png\" alt=\"tccc.png\" \/><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><em>An excerpt of the TinyCheck report on any detected geo-tracking apps.<\/em><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Using a regular Wi-Fi connection, TinyCheck scans a mobile device\u2019s outgoing traffic and identifies interactions with known malicious sources. In order to make use of TinyCheck, a computer with a Raspberry Pi OS Buster is needed along with one of the following two options: either two Wi-Fi interfaces, one for connecting to the internet and one for your mobile\u2019s connectivity (AP mode), or one Wi-Fi interface and an Ethernet connection for internet. In both cases, the best choice is a Raspberry Pi Model 3 or higher with a small touch screen.<\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><img decoding=\"async\" src=\"https:\/\/www.kaspersky.com\/content\/en-global\/images\/repository\/pr\/2021\/tinycheck.png\" alt=\"tinycheck.png\" \/><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\"><em>A visualization of how TinyCheck works.<\/em><\/span><\/p>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">\u201cSecret tracking of users and using their data without their knowledge should not happen for any reason. Having the combined list of indicators of compromise for mobile trackers and stalkerware integrated in TinyCheck, users are able to increase their privacy control. TinyCheck is therefore designed as an open source tool that is freely available to anyone, and one which the security community can share and contribute their knowledge to,\u201d\u00a0<strong>comments F\u00e9lix Aim\u00e9, a Kaspersky GReAT security researcher.<\/strong><\/span><\/p>\n<p><span style=\"color: #000080;\"><strong><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">In addition to using TinyCheck, there are a few tips to follow to lower the chances of being tracked by such apps and services, which involve limiting apps\u2019 permissions:<\/span><\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Check which apps have permission to use your location. The following information shows how to perform such checks on an\u00a0<a href=\"https:\/\/www.kaspersky.com\/blog\/android-8-permissions-guide\/23981\/\">Android 8 device<\/a>\u00a0(later versions do not differ significantly) and an\u00a0<a href=\"https:\/\/www.kaspersky.com\/blog\/ios-tracking-setup-part-1\/12625\/\">iOS device<\/a>. If an app does not need location permission, you can simply revoke it.<\/span><\/li>\n<li><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Give apps permission to use your location only while they are being used. Most apps do not need to know your location when they are running in the background, making this setting ideal for many of them.<\/span><\/li>\n<li><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Delete apps that are not used anymore. If the app has not been opened in a month or more, it is probably safe to assume it is no longer needed; and if this changes in the future, it can always be reinstalled.<\/span><\/li>\n<\/ul>\n<ul>\n<li><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">Use proven cybersecurity protection, such as\u00a0Kaspersky Internet Security for Android, which protects you against all kinds of mobile threats.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: 'trebuchet ms', geneva, sans-serif; font-size: 12pt;\">To read about the TinyCheck installation process, please visit\u00a0<a href=\"https:\/\/github.com\/KasperskyLab\/tinycheck#readme\">https:\/\/github.com\/KasperskyLab\/tinycheck#readme<\/a><\/span><\/p>\n<h1 class=\"title style-scope ytd-video-primary-info-renderer\"><span style=\"font-size: 14pt; color: #000080;\">Video | TinyCheck \u2013 A special stalkerware detection tool<\/span><\/h1>\n<p><iframe loading=\"lazy\" title=\"TinyCheck \u2013 A special stalkerware detection tool\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/hJarUzjSrm0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>To increase privacy control over users\u2019 data, two Kaspersky experts have combined the results of their research and upgraded the openly available TinyCheck tool. Initially developed as a stalkerware detection tool for service organizations working with victims of domestic violence, TinyCheck now also offers help to uncover all types of geo-tracking apps. In December 2020, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24813,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,16],"tags":[24275,24276,24274],"class_list":{"0":"post-80595","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-pics-and-videos","8":"category-tech-knowledge","9":"tag-a-special-stalkerware-detection-tool","10":"tag-stalkerware-detection-tool","11":"tag-tinycheck"},"_links":{"self":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts\/80595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/comments?post=80595"}],"version-history":[{"count":0,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/posts\/80595\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/media\/24813"}],"wp:attachment":[{"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/media?parent=80595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/categories?post=80595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.technologyforyou.org\/wp-json\/wp\/v2\/tags?post=80595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}