Users, beware! ‘Honesty app’ Sarahah is secretly uploading your phone contacts

A senior security analyst has claimed that the viral app Sarahah uploads email and phone contacts from users’ Android device on logging in.

By:INDO ASIAN NEWS SERVICE
| Updated on: Aug 28 2017, 13:36 IST
The app has been found uploading the user’s phone contacts on to the company’s servers.
The app has been found uploading the user’s phone contacts on to the company’s servers. (Shutterstock)
The app has been found uploading the user’s phone contacts on to the company’s servers.
The app has been found uploading the user’s phone contacts on to the company’s servers. (Shutterstock)

The viral 'honesty app' Sarahah where you can send or receive anonymous messages is not as anonymous as it appears as the app has been found uploading the user's phone contacts on to the company's servers.

A senior security analyst Zachary Julian who works for IT security consulting firm Bishop Fox was the first to discover Sarahah uploading private information, using a monitoring software BURP Suite. "As soon as you log into the application, it transmits all of your email and phone contacts stored on the Android operating system," a report in The Intercept on Sunday quoted Julian as saying.

Responding to the accusation, Sarahah's founder Zain al-Abidin Tawfiq said contact lists were being uploaded
Responding to the accusation, Sarahah's founder Zain al-Abidin Tawfiq said contact lists were being uploaded "for a planned 'find your friends' feature" that was not yet released. (Sarahah Facebook)
Responding to the accusation, Sarahah's founder Zain al-Abidin Tawfiq said contact lists were being uploaded
Responding to the accusation, Sarahah's founder Zain al-Abidin Tawfiq said contact lists were being uploaded "for a planned 'find your friends' feature" that was not yet released. (Sarahah Facebook)

Though the app asks for user's permission to access contacts, there is no such feature in the app where these contacts would be required or even a search feature where users can look up for a friend using a contact number.

However, Sarahah's founder Zain al-Abidin Tawfiq said contact lists were being uploaded "for a planned 'find your friends' feature" that was not yet released. In a tweet, Tawfiq wrote that the data request will be removed on the next update.

It often seems suspicious if users do not get anything out of granting access to apps to their contact lists.

For example, earlier in 2017, the newsletter unsubscription service Unroll.me drew a lot of criticism following allegations that it sold user data to cab-hailing service Uber.

Follow HT Tech for the latest tech news and reviews , also keep up with us on Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 28 Aug, 13:25 IST
NEXT ARTICLE BEGINS
keep up with tech