Cybernews: airline apps are very chatty...

Research site Cybernews.com has analysed the applications of 14 airlines. With worrying results, according to the site.
cyber security
(Photo by Petter Lagson on Unsplash

Online applications have been known to 'spy' on their subscribers by recording a certain amount of data. Cybernews, an online cybersecurity analysis site, played along. It analysed 14 popular air transport sites. Its investigation revealed that the applications examined could have access to sensitive or private information of their travellers.

According to data presented by the Cybernews team, American Airlines and United Airlines are the airlines collecting the most data out of the 14 airline applications studied. Philippine Airlines, on the other hand, collected the fewest data points.

The study was based on a series of criteria: access to the user's location, camera, storage, phone status, microphone, contacts, device accounts, messages and calls. The results of the research showed that not all apps disclose the data points on Google Playstore that can be collected by the permissions users grant to the app on their device.

User location

All travel applications have access to the exact geographical location of their user. Most airlines explain that they locate their users mainly for reasons of functionality, personalisation and marketing. Some carriers do not mention this collection via their applications. This includes Ryanair, Delta Airlines and Aegean. For their part, Spirit and Frontier Airlines state that they only collect the user's approximate position, whereas authorisations allow access to the exact position.

Access to the camera

12 of the 14 applications tested have authorisation to access the phone's camera. However, only three airlines revealed that they collect camera-related dataCybernews reports that the airlines' applications do not indicate that they 'spy' on camera data, indicating this as part of the application's functionality and attempts to ensure security and compliance. Among the airline apps that do not indicate the camera data 'snooping' feature are, according to Cybernews, Air Asia, Fly Delta, Spirit Airlines, Southwest Airlines, Frontier Airlines, Singapore Airlines, Vietnam Airlines and Aegean Airlines.

Read from the phone's data storage

Also according to Cybernews, 11 applications tested could read and write to the device's storage. One application was only allowed to read files from the device's storage. The data that applications can access can include user-generated files, photos, videos, documents and other data. private data. If exploited by malicious actors, it can potentially lead to data loss and privacy breaches. Only three airlines disclosed that they collected file-related data, claiming that it was necessary for application functionality, analysis and security reasons. The other nine airlines did not mention that they had potential access to the storage.

Phone status evaluation

9 of the 14 airline applications analysed had this authorisation. Reading information about the phone's status is considered as sensitive because it allows an application to access data that can identify the device and the user. This can include information such as the device's phone number, network status, network operator, IMEI codes, SIM card and ISP information.

Using microphone data

None of the airlines studied by Cybernews mentioned microphone access. However, the site's team found that 4 airline applications have this authorisation. These are AirAsia, United Airlines, Ryanair and Singapore Airlines.

Access to user contacts

Contact information is sensitive because it may contain private data. on friends and familycolleagues and acquaintances. According to Cybernews, 3 out of 14 applications have access: AirAsia (read and communicate with the third party), Turkish Airlines (read only) and Vietnam Airlines (read only).

Ryanair can read all the user's internet accounts

According to the search site, Ryanair allows its application to access the user's accounts associated with the device. These include Google, Meta, Samsung and other accounts, including email addresses. This could present privacy and security risks.

Some airlines may call on behalf of a user

Four airlines had authorisation to access text messages and calls on users' handsets. Applications with such authorisation can send text messages and call the user's name. Turkish Airlines, United Airlines and Spirit Airlines do not inform their customers.