Live data from Hacker News

Popular iPhone apps caught sending user location data to monetization firms

techcrunch.com

71–80 of 261 posts

Re: Popular iPhone apps caught sending user location data to monetization firms

#71
post #7

I’m confused. On iPhone you control which apps get location data. You also get warnings on the top of the screen when an app is using your location. How are these apps getting around that?

I don't know if it's possible anymore, but one way used to be that the app would send a list of every wifi network it could see. This can be used to calculate your position surprisingly accurately, in most places in the world.

> I don't know if it's possible anymore

Never was possible on iOS.

Re: Popular iPhone apps caught sending user location data to monetization firms

#72
post #23

Sue Apple, because they own the "curated" distribution channel and they have too much money.

Why would you blame Apple instead of the people behind the offfending application?

For the same reason everyone is blaming Facebook instead of Cambridge Analytica perhaps?

Re: Popular iPhone apps caught sending user location data to monetization firms

#73
post #29

Does the App Store for either iOS or macOS give any indication whether or not an application is open source? I know that is not at all a guarantee that an app would be more respectful of the user's privacy, but I'd bet that it would save a chunk of guesswork.

No, not that I’m aware of. And I think that would be meaningless to 99.8% of users. It’s not like you can filter your searches anyway. If people DID start thinking of it as some kind of sealer quality, unscrupulous actors would simply open source their apps and leave all the garbage in. So it would become meaningless.

Further, what does it being open source help? They could publish the app source without the tracking SDKs (especially as some of them are big enough now that you have to hassle with git-lfs even if you wanted to commit it) and then build it with the tracking SDKs before submitting to the App Store.

Re: Popular iPhone apps caught sending user location data to monetization firms

#74
post #59

Why does it seem like browser extensions are ignored in all of these discussions? For example, right now the Honey Chrome extension has permission to "Read and change all your data on the websites you visit". They could be doing anything with that, I'm just crossing my fingers that they find me good deals and don't abuse my data. Chrome actually acknowledges this: "Warning: Google Chrome cannot prevent extensions fro…

That’s not an issue in iOS/Safari because extensions can’t do that kind of thing. I’ve seen other people complain about this for chrome. I saw people justifying it by saying that that permission is necessary if you want to interact with the page directly (hide/show content, etc.). Doesn’t mean the extensions are to be using it, but it may be necessary. Much like GPS data for a weather app.

Safari extensions can do the same, both on macOS on iOS (though significantly reduced, since loading the extension requires user interaction).

Re: Popular iPhone apps caught sending user location data to monetization firms

#75
post #60
post #50

The lack of any real business model besides gambling on mobile apps sends the market from professional firms like Autodesk and Adobe to solo developers overseas. They have much lower accountability which makes this entirely predictable.

> to solo developers overseas Why is that kind of racism necessary at all? It has nothing to do with where people are. Developers want money. Duh. But the App Store has gone to “ basically everything is free“. The only two ways to accomplish that for most developers are in app purchases, which don’t work every app, and ad/data sales. As new people find new ways to monetize data that they can get their hands on, they’…

Overseas matters a lot. It makes prosecution almost impossible.

Re: Popular iPhone apps caught sending user location data to monetization firms

#76

My company analyzes iOS and Android apps en mass, using static and dynamic analysis. We've partnered with several major universities to provide data like this about apps. If any reseachers are interested in this data, please feel free to reach out. For location in particular, we see which location collection permissions the app has, as well as indirect methods like Bluetooth and Wifi. We also see the commercial integ…

I'm curious as to your methods. Do you have something like a blog post that I could peruse?

Re: Popular iPhone apps caught sending user location data to monetization firms

#77
post #26

No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…

I just think that installing a weather app in general is stupid.

I just dont see the actual need to have one installed for the vast majority of people.

Systems need weather apps/information: ships/boats, planes, etc...

Your phone does not. Nor your desktop.

There was a ship that was getting delayed weather information [0] and it sank and people died - and so its clearly important to track weather on ships and plans and transport that will be at risk in inclement weather.

Otherwise, look out the window, or read the weather off google.

Never install a weather app...

[0] https://www.youtube.com/watch?v=YxTwfYH-PwI

Re: Popular iPhone apps caught sending user location data to monetization firms

#79
I asked a network info app developer why it's not possible to at least track and control network connections on iOS, like Little Snitch does (or did) for MacOS. "iOS doesn't support that". Well, duh? I don't even know what to think. Knowing where the iOS device connects to will be a huge help "cracking down" on BS apps!

And then I read in the comments that it might be virtually impossible for Apple to detect malicious/privacy breaking behavior, or consumers should go pay for apps that are good. Right.

Re: Popular iPhone apps caught sending user location data to monetization firms

#80
post #55
post #47

Earlier quoted context omitted.

The problem is when not being complicated means they are aren't truthful. Do you track crashes? Do you have any logging that tracks an IP address? I view my dedicated home IP as personal, if not all that private, information. Does minimal logging actually require storing personal information? Is there a common, or legal definition of what personal information is? I'm all for simple policies, but I would also rather t…

the app collects no data whatsoever. i have no idea what your IP address is (the app connects directly to environment canada to retrieve the raw radar data). no crash data/telemetry is collected automatically, but bug reports are welcome on the github repo. so please don't insinuate that this policy is not true. and yes, there is a legal definition of personal information. since im based in canada, that would be as d…

But you are sending personal data (ip address) to a third party by directly connecting to their service. Not sure about canadian privacy law, but eu company would need to list this third party in their policy.

edit: just realized this comes across like bikeshedding. I do applaud and like your approach to privacy and its simplicity. It wouldn't decrease the appeal of your app at all to mention that you query the environment canada data, which is probably a public service and will not missue the data itself).

Post reply on HN