Live data from Hacker News

Popular iPhone apps caught sending user location data to monetization firms

techcrunch.com

161–170 of 261 posts

Re: Popular iPhone apps caught sending user location data to monetization firms

#161
post #26

No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…

I just think that installing a weather app in general is stupid. I just dont see the actual need to have one installed for the vast majority of people. Systems need weather apps/information: ships/boats, planes, etc... Your phone does not. Nor your desktop. There was a ship that was getting delayed weather information [0] and it sank and people died - and so its clearly important to track weather on ships and plans a…

> Otherwise, look out the window

Sadly I am too naive at reading the atmosphere to determine what the weather will be like five days from now. I have to rely on people with supercomputers for that.

I like Weather Underground's approach; their app is free-with-ad but if you run a weather station and contribute to their network then you can disable the ads for free. Flightradar 24 has a similar business model.

Re: Popular iPhone apps caught sending user location data to monetization firms

#162
post #115

Earlier quoted context omitted.

You cannot decompile apps without a jailbroken device, as they're encrypted with FairPlay. And iTunes, at least with the latest version, no longer lets you download apps.

There are ways to download apps on a desktop without using iTunes.

Do tell

Re: Popular iPhone apps caught sending user location data to monetization firms

#163
post #26

No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…

In Germany the German Meteorological Office has their own app

https://play.google.com/store/apps/details?id=de.dwd.warnapp

https://itunes.apple.com/de/app/warnwetter/id986420993?ls=1&...

The basic weather warning features are free. The whole weather app costs 1,99€.

It's been sued recently by a commercial app company (which also uses their data) for providing the service for free. So normal citizens have now to pay for it (even though they pay for the Office already through their taxes but well...that's capitalism for you). They offer a free version for people who work for fire departments etc. though.

This is the only app I've ever payed for on a app store.

Re: Popular iPhone apps caught sending user location data to monetization firms

#166
post #26

No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…

> The NOAA one isn’t made by the government, seems like using that name should be some kind of copyright infringement. I'm pretty sure copyright doesn't apply here! It's possible it's a trademark infringement? (No idea if the name or acronym are trademarked though), or possibly impersonation of a government entity? Either way, it's certainly not a copyright issue to use the name.

You’re right, trademark infringement just what I should’ve written.

It’s probably fine legally. They’re showing new NOAA weather data, so calling it a “NOAA weather“ or “NOAA Radar” is correct, just misleading.

Re: Popular iPhone apps caught sending user location data to monetization firms

#167
post #26

No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…

Adware Doctor, the number one paid utility in the Mac App Store, is secretly logging the browser history of users, and sending it to a server in China. The app is currently listed on Apple's Mac App Store as the company's fourth-highest "Top Paid" software programs, behind Final Cut Pro, Magnet and Logic Pro X. It is also the store's No. 1 paid utility. The app currently costs $4.99, is validly signed by Apple, and i…

There are exceptions everywhere.

That case is really odd. I read the article about it. It’s really questionable how it got that high up in the App Store, and it’s from a developer who has ripped off other peoples apps and done questionable things in the past.

It wouldn’t surprise me if the developer had used shady tactics to “buy“ a lot of copies of the app to push it up the rankings so that they could start to lure in real users.

More than anything it just looks like Apple was asleep at the wheel with a sketchy developer.

Re: Popular iPhone apps caught sending user location data to monetization firms

#168
post #59

Earlier quoted context omitted.

That’s not an issue in iOS/Safari because extensions can’t do that kind of thing. I’ve seen other people complain about this for chrome. I saw people justifying it by saying that that permission is necessary if you want to interact with the page directly (hide/show content, etc.). Doesn’t mean the extensions are to be using it, but it may be necessary. Much like GPS data for a weather app.

Safari extensions can do the same, both on macOS on iOS (though significantly reduced, since loading the extension requires user interaction).

My understanding was you couldn’t even have extensions on iOS, except for ad blocker style things which are explicitly limited by API to prevent blocker from knowing what it was blocking due to tracking concerns.

I may be wrong about safari on Mac iOS.

Re: Popular iPhone apps caught sending user location data to monetization firms

#169
From the article: "[ASKfm] asks for access to a user’s location that “won’t be shared with anyone.” But the app sends that location data to two data firms, AreaMetrics and Huq. When reached, the app maker said it believes its location collection practices “fit industry standards, and are therefore acceptable for our users.”

Surely this is legally actionable activity, right?

Re: Popular iPhone apps caught sending user location data to monetization firms

#170

Earlier quoted context omitted.

A lot of work went into rooting out these trackers, what data they sent, and what apps they were in. We used a combination of static code analysis for each, runtime analysis (eg. Corellium), and network packet capture/analysis. The good news is that only that last part is required if you would like to try this, now that the commonly used hostnames are published. Folks can add the full list to a system such as Pi-Hole…

Where can I look at the published list of hostnames?

They seem to be published here: https://guardianapp.com/ios-app-location-report-sep2018.html
Post reply on HN