• About
  • Subscribe
  • Contact
Thursday, March 12, 2026
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

FutureCISO Security Alert: Beware using cartoon avatars

by FutureCIO Editors
June 30, 2021

It’s the new thing on social media. Users are cartooning themselves, aka face photos. Check Point Research (CPR) raises some concerns particularly about how one app, Voila, because it includes specific and unique installation ID (vdid) can potentially be used by criminal elements.

Following a preliminary scan on the Viola app, CPR posted the following notes:

  • The app has been written by a legitimate LLP company registered in the United Kingdom (UK)
  • In terms of permissions, the app utilises only the bare minimum required for operation.
  • The app verifies that the images contain face(s), and only after that verification, the app sends them to the server for processing
  • All communication with the server is performed using HTTPS, so the traffic is encrypted out-of-the-box
  • The app is using well known open-source libraries, where possible
  • When the photo is sent to the server, the app includes the specific and unique installation id (vdid) that was generated by Google Play, potentially linking faces to the specific installation

Yaniv Balmas, head of Cyber Research at Check Point Software Technologies, commented that most users likely assume that the processing of Voila app is done locally on their phone. This is not the case. A non-obvious fact here is that the company sends face pictures to its servers for processing.

“When a face photo is sent to the company’s server, the app includes unique installation IDs that were generated by Google Play. Each photo is packaged up with user identification details. While this fact is mentioned in the company’s privacy policy, the possibility for misuse of the data opens up – either by the company itself or by a 3rd party,” he added.

He postulated that in the event of a hacked, the attackers could potentially gather a large data base of all faces of application users.

“We have no way of telling if the company is doing anything illegal or malicious, but I do think it’s important for new users to be aware of the inherent risks in sending content to servers for processing,” he continued.

Related:  Data centre M&A surges to record $57 billion in 2024, driven by private equity
Tags: Check Point ResearchCheck Point Software Technologiescyber threatsvdid

FutureCIO Editors

No Result
View All Result

Recent Posts

  • 85% believe AI is accelerating their adoption of containers, study finds
  • EtonHouse rolls out enterprise AI workspace with OpenAI
  • Huawei Cloud launches HCF globally, delivering open, simplified, and resilient hybrid cloud
  • Manulife to operationalise agentic AI within its enterprise AI platform with Akka
  • Tech Data and NetApp launch AI Test Drive Centre to accelerate enterprise transformation

Live Poll

Categories

  • AI and Machine Learning
  • Artificial Intelligence
  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CHRO
  • CISO
  • CISO strategies
  • Cloud, Platforms and Ecosystems
  • Cloud, Virtualization, Operating Environments and Middleware
  • Compliance and Governance
  • Compliance and Governance|Technology
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Culture and Behaviour|People
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Data Protection
  • Digital Transformation
  • Education
  • Education
  • ESG and sustainability
  • Finance
  • Finance & Insurance
  • Future Workplace
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Governance, Risk and Compliance
  • Governance, Standards and Regulations
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • IT-OT integration
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Sustainability
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

[wpli_login_link]

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe