Technology

Military-focused apps found with Chinese and Russian code

Researchers found foreign third-party software in many apps marketed to U.S. military users, raising privacy and security concerns.

James Whitfield

By James Whitfield · Staff Writer

3 min read

Military-focused apps found with Chinese and Russian code
Photo: Ars Technica

A study of mobile apps aimed at U.S. military personnel found that more than one in eight contained software from companies in China, Russia or other foreign countries. The findings matter because outside code used for ads and analytics can help collect sensitive information about service members’ locations and habits, according to researchers at Purdue University, the U.S. Military Academy at West Point and Florida International University.

The researchers reviewed more than 220 apps marketed to military users, including uniform guides, promotion-exam study tools, banking apps and dating apps. They gathered the apps from Google Play and military-focused Reddit forums, according to the study.

Nearly 64% of the apps included third-party software development kits, or SDKs, the researchers found. Those prebuilt tools are commonly used for advertising and analytics, but they can also track user behavior, including location, and share data with outside companies.

The most common SDKs came from Google and Facebook, according to the study. Researchers identified 76 SDKs in all, including code linked to China, Russia, Israel, India, Germany and other countries. About 7% of the apps carried third-party code from countries the Pentagon considers adversarial, the researchers said.

Twelve apps contained HMS Core, a software kit from Huawei that advertises features including location mapping, ad delivery and storage of images and video, according to the study. Some of those apps were built for state National Guard organizations. U.S. regulators identified Huawei as a national security threat in 2020.

The researchers said they did not observe data flowing to Huawei servers. They also warned that SDKs can be changed remotely after installation, creating a risk that code not sending data today could do so later. In one case cited by the study, Huawei code reached an app through a commercial notification tool without the developer knowing it.

Two other apps reviewed by the researchers were built by Russian companies and used Yandex, a Russian advertising service, according to the study.

The study also found gaps between what apps disclosed and what they did. Forty percent of the apps collected or shared more data than their Google or Apple store listings stated, the researchers said. Neither Google’s Play Store Data Safety section nor Apple’s App Store Privacy Labels tells users the country of origin for software components inside an app.

Joshua Shinkle, a Purdue University PhD researcher and the study’s lead author, said the researchers hoped the work would help military-affiliated users, developers and app platforms make better privacy decisions and spur policy discussions about the gaps.

The study included a survey of 103 military-affiliated Americans, including active-duty personnel, reservists, veterans, Defense Department civilians and family members. More than 83% said they used at least one app with data practices that made them uncomfortable, and those respondents used more than three such apps on average, according to the researchers.

Between 76% and 83% of survey participants said they were extremely uncomfortable with apps containing code from China, Russia, Iran or North Korea, the four countries the Pentagon designates as cyber adversaries. Participants also reported more comfort with data collection when an app was branded for military use.

Nearly two-thirds of surveyed users said they had received little or no institutional guidance on personal app use, according to the study. Among those who had received some guidance, nearly three-quarters said it was inadequate. The Pentagon declined to comment.

Asked about possible safeguards, participants rated phone warnings about foreign or unknown third-party code as both highly effective and likely to win their support. The researchers said users also showed similar backing for limits on data brokers handling military-affiliated data, independent audits of app privacy disclosures and tighter restrictions on foreign code in apps marketed to military users.

This story draws on original reporting from Ars Technica.