Get 3 – task list & ToDo! 1.0.2 (iOS / App Store)

175x175bb (33)

This application is available for iOS. This app is designed to be a simple timer, task & to-do list. The latest build was released on Oct 08, 2015. Our latest check was performed on Oct 7th, 2016.

Findings Summary

Our examination revealed total 4 items, where were 3 DAR items and 1 DIT items found. Among DAR items were found 0 worst items, 2 bad items, 1 good item, and 0 best items. Among DIT items were found 0 worst items, 1 bad item, 0 good items, and 0 best items.

Below you find 2 infographics summarizing what we described above. Each image provides information about both DAR and DIT items.

 

 

This slideshow requires JavaScript.


Everything presented below is related to well-known CWEs, such as Sensitive data leakage [CWE-200], Unsafe sensitive data storage [CWE-312], Unsafe sensitive data transmission [CWE-319]. You can read more about it here.

Now let’s go deeper and examine each data item’s protection level.

 

Application Description

Let’s cite the description of this application below:

Get 3 is the latest breakthrough in getting things done efficiently.
You can only choose 3 tasks and you only have 24, 48 or 72 hours to do them.
Focusing on the 3 most important tasks every day is a very powerful method to focus your effort and attention.

Take a rest from the overwhelming lists you have in other to-do list apps.
Clear your mind and focus!

  • Task timer.
  • Daily reminder.
  • Extended statistic.
  • Tasks list.
  • Automatic start task.

You can change your life if you throw out long to-do lists and only focus on the most important tasks every day.
Develop the habit of taking small steps every day towards your goals.
Change your daily routine and save your time with the simple & original app – Get 3.

 

Protection levels.

Locally stored data (Data-at-Rest, DAR).

Locally stored data groups include Application Information, Tasks Information, Media Information.
The average DAR value is 4.50 points (7.00 points of system protection and 2.00 points of own protection). It is higher than a typical value (3.5 points, where’s 7 points of system protection and 0 points of own protection).

Items’ GROUP #1 with average value 3.50 points (7 points of system protection, 0 points of own protection) means data protection levels have following definitions. Frankly talking, extra data found that shouldn’t be accessed where system protection level means – root/jailbreak is required but not possible without wiping device data, and own protection level means – stored as is.

– Application Configs (‘Application Information’ Group) – Different configuration files created by your app, perhaps app permissions. This data item related to mentioned group meant to be any info related to the app, app settings, including installed apps or installers,

– Tasks (‘Tasks Information’ Group) – Different tasks stored locally or sync with server including all notes/tasks details. This data item related to mentioned group meant to be any information referred to tasks, like a typical task manager

Items’ GROUP #2 with average value 6.50 points (7 points of system protection, 6 points of own protection) means data protection levels have following definitions. Frankly talking, protection and privacy issues are still possible but might involve interaction with an app code where system protection level means – root/jailbreak is required but not possible without wiping device data, and own protection level means – data is not available in backups.

– Screen Snapshots (‘Media Information’ Group) – Screenshots of your device screen running certain apps; common as an iOS app multitasking feature (app swipes) or browser tab swipes. This data item related to mentioned group meant to be any data like photo, image, video, audio

Also, keep in mind, using jailbroken device means the system protection level is 0 points and you’re using out-of-date iOS < 8.3 the system protection level is 2 points. If some data marked as shareable via iTunes, then the system protection level is 4 points.

Transferred data (Data-in-Transit, DIT).

Transferred data groups include Analytics ‘n’ Ads Information.
The average DIT value is 4.50 points (5.00 points of system protection and 4.00 points of own protection). It is higher than a typical value (4 points, where’s 4 points of system protection and 4 points of own protection).

Items with average value 4.50 points (5 points of system protection, 4 points of own protection) means data protection levels have following definitions. Frankly talking, data available if it’s allowed only and may require user action where system protection level means – some techniques are available to developers to keep connection bypassing system settings, like proxy settings, etc., and own protection level means – bypassed by fake/stolen root certificates.

– Device Data (‘Analytics ‘n’ Ads Information’ Group) – Device ID, Device Name, Device OS Name and Version, and jailbroken/root status. This data item related to mentioned group meant to be any info related to analytics services like Flurry, Google Analytics, etc. or advertisements

Keep in mind if you’re using out-of-date iOS < 9.0, the system level equals 2 points instead of 4. It means your data can be stolen without involving your actions.

Privacy Policy

No Privacy Policy is available for this application.