top of page

BuzzFeed (Android / Google Play) on Aug 6, 2016. Env App Results


This application is available for Android here. This app was designed to mix and keep informed with top news on one of the most popular social network. The latest build was released on August 3, 2016. Let's cite the description of this application below: ------------------------------------------- BuzzFeed has it all: the stories and quizzes buzzing on social, the news you want now, and the recipes and life tips you didn’t know you needed. FEATURES: • Never be bored again with a great mix of the best News, Buzz, Life, and Videos • Use the side menu to dive into your favorite topics like News, Quizzes, Food, Celeb, Animals, DIY, and more • Use the Trending section to see what stories are about to go viral • One tap to share stories with Email, Messages, Facebook, Twitter, Pinterest and more • Share individual images and videos from within stories. Just tap the image for options! • Bookmark posts you want to come back to and sync them with all your devices • Get push notifications for trending stories so you’re always in the loop • Comment on a post or click the reaction button to share your opinion • Play with YrBFF, BuzzFeed’s new app for the Apple Watch, the best wrist-based friend you’ll ever have If you have any trouble with your app please email us at support@buzzfeed.com so we can help! And don’t forget to check out BuzzFeed.com when you’re on your computer! -------------------------------------------

Findings Summary.

Our examination revealed total 31 items, where were 11 DAR items and 20 DIT items found. Among DAR items were found 0 worst items, 9 bad items, 0 good items, and 1 best item. Among DIT items were found 0 worst items, 18 bad items, 2 good items, and 0 best items. Below you find 3 infographics summarizing what we described above. Each image provide information about both DAR and DIT items.

Bad Items

Good Items

Best Items

Now let's go deeper and examine each data item's protection level.

Protection levels.

Locally stored data (Data-at-Rest, DAR). Locally stored data groups include Application Information, Credentials Information, Social Information, Account Information, Device Information, Analytics 'n' Ads Information, Log Information. The average DAR value is 3.50 points (7.00 points of system protection and 0.00 points of own protection). It equals to a typical value (3.5 points, where's 7 points of system protection and 0 points of own protection).

Items with average value 3.50 points (7 points of system protection, 0 points of own protection) means data protection levels have following definitions. Frankly talking, extra data found that shouldn't be accessed where system protection level means - root/jailbreak is required but not possible without wiping device data, and own protection level means - stored as is.

- Application Configs ('Application Information' Group) - Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any kind of info related to app, app settings, incl. installed apps or installers, - Credentials (IDs) ('Credentials Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Credentials (IDs) ('Social Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Media URLs ('Social Information' Group) - URLs related to media info such as stream media or profile's media, etc. This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Account Data ('Account Information' Group) - Basic info about account like name, list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Stream ('Account Information' Group) - Any kind of social or another stream activity incl. posts, walls, etc. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Device Data ('Device Information' Group) - Owner Device ID, Owner Device Name, Owner Device OS Name and Version. This data item related to mentioned group meant to be details about your device, - Environment ('Analytics 'n' Ads Information' Group) - Different info about environment of you device incl. apps lists, device info, OS name and versions, updates, list of users, network details, etc. This data item related to mentioned group meant to be any kind of info related to analytics services like flurry, google analytics, etc. or advertisements, - Credentials (Tokens) ('Social Information' Group) - Different tokens used to get an access to your account except passwords but incl. app or 3rd party tokens, secret keys and etc. (usually give a full access to your account). This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Application Events ('Log Information' Group) - App events referred to user actions 'n' activities were done. This data item related to mentioned group meant to be any information stored in local or network logs

 

Also, keep in mind, using jailbroken device means the system protection level is 0 points and you're using out-of-dated iOS < 8.3 the system protection level is 2 points. If some data marked as shareable via iTunes, then the system protection level is 4 points.

 

Transferred data (Data-in-Transit, DIT). Transferred data groups include Analytics 'n' Ads Information, Application Information, Credentials Information, Account Information, Documents Information, Social Information, Address Book 'n' Contact Information, Personal 'n' Private Information. The average DIT value is 4.60 points (5.00 points of system protection and 4.20 points of own protection). It is higher than a typical value (4 points, where's 4 points of system protection and 4 points of own protection).

Items' GROUP #1 with average value 4.50 points (5 points of system protection, 4 points of own protection) means data protection levels have following definitions. Frankly talking, data available if it's allowed only and may require user action where system protection level means - some techniques are available to developers to keep connection bypassing system settings, like proxy settings ,etc., and own protection level means - bypassed by fake/stolen root certificates. - Device Data ('Analytics 'n' Ads Information' Group) - Owner Device ID, Owner Device Name, Owner Device OS Name and Version. This data item related to mentioned group meant to be any kind of info related to analytics services like flurry, google analytics, etc. or advertisements, - Application Configs ('Application Information' Group) - Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any kind of info related to app, app settings, incl. installed apps or installers, - Credentials (IDs) ('Credentials Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Credentials (Passwords) ('Credentials Information' Group) - Well known passwords or PINs you're using to get an access to your account (usually worse than tokens because gives a full access to your account). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Credentials (Tokens) ('Credentials Information' Group) - Different tokens used to get an access to your account except passwords but incl. app or 3rd party tokens, secret keys and etc. (usually give a full access to your account). This data item related to mentioned group meant to be any types of credentials incl. basic (ids only), passwords, tokens, etc., - Account Data ('Account Information' Group) - Basic info about account like name, list of sub-account (e.g. financial or other) and some linked data like a phone number. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Media URLs ('Account Information' Group) - URLs related to media info such as stream media or profile's media, etc. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Media Data ('Documents Information' Group) - Any kind of info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Stream ('Social Information' Group) - Any kind of social or another stream activity incl. posts, walls, etc. This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Media Stream ('Social Information' Group) - Any kind of info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Media URLs ('Documents Information' Group) - URLs related to media info such as stream media or profile's media, etc. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Contact Short Profile ('Address Book 'n' Contact Information' Group) - Name, Email ID, Phone number of contacts. This data item related to mentioned group meant to be info stored locally, cached or transferred over the network and belong to this application if it's social even, - Media URLs ('Address Book 'n' Contact Information' Group) - URLs related to media info such as stream media or profile's media, etc. This data item related to mentioned group meant to be info stored locally, cached or transferred over the network and belong to this application if it's social even, - Bookmark Details ('Documents Information' Group) - Details of bookmarks like date and time, timezone, place, participants info, body, linked data. This data item related to mentioned group meant to be any kind of documents stored locally, uploaded, downloaded, synchronized in any file format, - Media Data ('Account Information' Group) - Any kind of info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be any info related to profiles, basic credential ids like email or username or phone number plus some more info depends on applications, - Media Data ('Address Book 'n' Contact Information' Group) - Any kind of info like images, audios, videos, media notes, etc. This data item related to mentioned group meant to be info stored locally, cached or transferred over the network and belong to this application if it's social even, - Credentials (Tokens) ('Social Information' Group) - Different tokens used to get an access to your account except passwords but incl. app or 3rd party tokens, secret keys and etc. (usually give a full access to your account). This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Personalization ('Personal 'n' Private Information' Group) - Info describes user preferences, favourites, tracked data, search requests, suggestions, etc. This data item related to mentioned group meant to be any kind of personal and private info not grabbed from the 3rd party social networks or your IDs

Items' GROUP #2 with average value 5.50 points (5 points of system protection, 6 points of own protection) means data protection levels have following definitions. Frankly talking, data is not available all the time or partially accessed where system protection level means - some techniques are available to developers to keep connection bypassing system settings, like proxy settings ,etc., and own protection level means - ssl pinning (can be patched).

- Credentials (IDs) ('Social Information' Group) - Only account IDs like app or 3rd party user IDs incl. emails, phone number, usernames and etc. (depends on apps). This data item related to mentioned group meant to be info grabbed from 3rd party social networks, - Credentials (Passwords) ('Social Information' Group) - Well known passwords or PINs you're using to get an access to your account (usually worse than tokens because gives a full access to your account). This data item related to mentioned group meant to be info grabbed from 3rd party social networks

 

Keep in mind if you're using out-of-dated iOS < 9.0, the system level equals 2 points instead of 4. It means your data can be stolen without involving your actions.

 

Privacy Policy Full application privacy policy is available here You may find privacy policy details proceeding the link above to compare developer's vision on data protection with our results.

Thanks for staying with us, your Privacymeter Team!

Want more to read?
Tag cloud
Тегов пока нет.
Follow us
  • Black Facebook Icon
  • Black Twitter Icon
  • Black Google+ Icon
  • Black LinkedIn Icon
  • Black RSS Icon
  • Black Pinterest Icon
  • blackberry
  • telegram
  • скачанные файлы
  • re.vu

Подпишитесь на рассылку

Будьте в курсе наших новостей

bottom of page