Live data from Hacker News

Popular iPhone apps caught sending user location data to monetization firms

techcrunch.com

21–30 of 261 posts

Re: Popular iPhone apps caught sending user location data to monetization firms

#22

How do researchers find this information? Presumably the apps are using encrypted network connections to submit your location data to surveillance backends. Is guardianapp reversing each application using jail broken devices? Using an iOS emulator to inspect the running app?

> How do researchers find this information?

The first suspicion arises when the app uses more bandwidth if you move it a lot, compared to the app on a stationary phone. I guess researchers can emulate the "moving". And they can virtualize the clock as well. So in principle they can send the app around the world in a matter of seconds and see what the app does on the network.

Re: Popular iPhone apps caught sending user location data to monetization firms

#24

How do researchers find this information? Presumably the apps are using encrypted network connections to submit your location data to surveillance backends. Is guardianapp reversing each application using jail broken devices? Using an iOS emulator to inspect the running app?

Extremely few applications pin the certificates. You just need to install a self signed one on the device and then you can MITM.

Re: Popular iPhone apps caught sending user location data to monetization firms

#25
post #3

Stories like this, the Uber story, and the recent one about Google tracking location even when you opt out, are why I'm looking forward to Purism 5 with PureOS and kill switches.

How does having some kill switch solve the issue of an app that needs geolocation selling the data or otherwise using it in a way other than you intended?

Re: Popular iPhone apps caught sending user location data to monetization firms

#26
No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category.

The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4.

Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of copyright infringement.

Of course WeatherBug on desktops was adware/malware for a very long time. Maybe it still is.

Then you get scareware stuff like the earthquake notification app. You better let us track everything you do otherwise you might die!

There are so many good apps on the store made by good developers. It’s amazing how much better your experience is if you just avoid free apps when possible.

Of course some of these apps, like the ones that you NEED to use for certain parking meters, are especially evil because there is an any choice. If you need that service, you’re giving up your privacy.

I wish Apple would crack down on this stuff. I imagine a lot of these apps are doing things that already violate the App Store guidelines. If they don’t, they probably SHOULD.

Re: Popular iPhone apps caught sending user location data to monetization firms

#27
Does the App Store for either iOS or macOS give any indication whether or not an application is open source?

I know that is not at all a guarantee that an app would be more respectful of the user's privacy, but I'd bet that it would save a chunk of guesswork.

Re: Popular iPhone apps caught sending user location data to monetization firms

#28
post #17

One thing to keep in mind is that ip addresses provide a pretty good location too. Even without GPS data, they at worst know what city you are in, probably down to the house depending on the ISP

What ISP attaches your home address to your IP?

The data has been mapped and correlated over the years along with IP's. On many ISPs, the ip is fairly static. May not be the ISP's. Fill out a web form to buy something and now that ip->location is linked, use a cell phone app that collects the SSID's and location and ip...

Re: Popular iPhone apps caught sending user location data to monetization firms

#29

Does the App Store for either iOS or macOS give any indication whether or not an application is open source? I know that is not at all a guarantee that an app would be more respectful of the user's privacy, but I'd bet that it would save a chunk of guesswork.

No, not that I’m aware of. And I think that would be meaningless to 99.8% of users. It’s not like you can filter your searches anyway.

If people DID start thinking of it as some kind of sealer quality, unscrupulous actors would simply open source their apps and leave all the garbage in. So it would become meaningless.

Re: Popular iPhone apps caught sending user location data to monetization firms

#30
post #12

Earlier quoted context omitted.

I am really hoping that one day we can legislate respect for privacy and be able to use mass produced widely available hardware and software. A solution for a few outliers doesn’t really influence the big picture. I am very interested in what individuals/institutions support privacy at scale. I am aware of the EFF. Who else?

The EFF is just astroturfing, https://thebaffler.com/salvos/all-effd-up-levine >A solution for a few outliers doesn’t really influence the big picture. There's nothing stopping anyone from buying a Purism 5. If someone doesn't care about their privacy, they don't deserve it. Freedom isn't free, and all that.

If I buy that phone, and I get a weather app… it’s going to need to know where I am to provide me the forecast.

And once I give it that permission, how does the phone/OS prevent them from selling the data that I gave them permission to have?

It doesn’t.

Post reply on HN