In brief
Before downloading an app, understand its permissions and assess the risk of personal data theft. This April 2015 article explains how background threads can continue running and drain batteries, and why unnecessary permissions raise security concerns.
Which app do you use first whenever you turn on your phone? Facebook? Whatsapp? Or do you check your email? Generally, we go to the App Store or Google Play to download apps we like and do what we want to do… Over time, we may find that even a fully charged phone quickly runs out of battery while idle. There are also frequent news reports about phones being tapped or infected with malware, and many online tutorials advise owners to format their phones and back up their data. With this in mind, I would like to share some insights from the perspectives of programming and users.
1. Turning off your phone does not necessarily stop all activity—you never know what programs apps are running in the background
In computing, a program running in the background is called a thread. A thread runs independently in the background, separately from the main program. A callback method implemented in the background can update the main page periodically. In the world of Android / iOS there are three types of threads: those that run a single task, those that repeat a task, and those that continuously use a backend class.
All of these threads can quickly drain the phone's battery unless users stop them through settings or bring up the App Stack and swipe them away. Even exiting an app in the usual way may not stop its threads.
If you have experience developing an Android app, you will understand that all startup and shutdown procedures are first triggered by capturing button events. Even after you leave an app, a thread created by its developer requires the user to stop it through settings.
Hackers can intercept the button-press and button-release events during the shutdown process and run threads to do anything. If you have rooted your phone or jailbroken your iPhone, apps can even steal all user data, along with the email addresses and phone numbers in your contact list.
2. Apps that require too many unnecessary permissions raise security concerns.
Many app developers, particularly those focused on Android development, enable a few extra permissions to make it easier to improve their apps. This is particularly serious with camera and flashlight apps:
A little attention makes it clear that turning on a flashlight has nothing to do with enabling Wi-Fi or accessing user data. Yet users in a hurry often overlook which permissions an app requests on their phones. Google and Apple also take very different approaches to approving apps for their stores. Google scans an APK just once to check for obvious Trojans and whether its content meets the requirements; an app can be listed in as little as two hours. Apple, however, takes several weeks. After screenshots and text descriptions are submitted, the entire review is conducted manually. If an app needs to communicate or work with other electronic devices, an Apple App Reviewer will also require the developer to submit a demonstration video so that others can understand how to use the app. As a result, people generally find it easier to believe that iOS apps are safer than Android apps.
As we can see, apps offer convenience but also carry hidden risks. Before downloading an app, pause and consider whether you fully understand the permissions it uses and have assessed the risk of your personal data being stolen. Whether storing data in the cloud is safe is a topic for another occasion.