Live data from Hacker News

Popular iPhone apps caught sending user location data to monetization firms

techcrunch.com

251–260 of 261 posts

Re: Popular iPhone apps caught sending user location data to monetization firms

#251
post #59

Earlier quoted context omitted.

That’s not an issue in iOS/Safari because extensions can’t do that kind of thing. I’ve seen other people complain about this for chrome. I saw people justifying it by saying that that permission is necessary if you want to interact with the page directly (hide/show content, etc.). Doesn’t mean the extensions are to be using it, but it may be necessary. Much like GPS data for a weather app.

GPS data for a weather app is not necessary, because it's way to precise for its purpose. Most of the time I need to know how the weather is elsewhere, or how the weather is going to be today. How does precise (to a meter) GPS data help me there exactly?

I use a precipitation radar app that tells me with fair amount of accuracy whether/how heavily it's going to rain 15-90 minutes from now. It often does matter what part of the city you're on. Since we bike everywhere to get around, it's kind of nice to get an idea whether waiting another 10 minutes to leave avoids the heaviest part of a shower, or better just bite the bullet because it's only getting worse in the next hour.

Although now that I think of it, I have its location locked to my home address because I didn't feel like being tracked :) It generally works well enough within ~3km or so, and I compensate the hit in accuracy by looking at the sky and drops/splashes in puddles/windows/cars (it's much harder to judge the intensity of rain by trying to spot droplets in mid-air).

I don't need the longer term forecast quite as much to have an app for it, for that I just use a bookmark to my local news weather page.

Re: Popular iPhone apps caught sending user location data to monetization firms

#252
post #211

Earlier quoted context omitted.

In the US, high quality weather data and forecasts can be bookmarked as a web page/icon for your zip code, https://www.weather.gov . Works well and no data leakage.

But you do get Google analytics and the dodgy sounding 4seeresults.com and cfigroup.com embeds.

I wonder if those are blocked by iOS content blockers, e.g. Firefox Focus.

Re: Popular iPhone apps caught sending user location data to monetization firms

#253

Earlier quoted context omitted.

I personally believe this is unlikely, because then the firms paying for this data will not be so sure that the information is legitimate, whereas collecting directly from user devices makes fraud more difficult.

Are you sure that that is actually a big problem for them? I imagine it would be quite hard to convincingly fake user data data. I could also imagine ways around that. For instance their proprietary SDK could generate the data and cryptographically sign it. Or they could require that app makers set up a special subdomain that points to their ip address. I guess it would only be worth the trouble if enough people care…

It is most definitely a problem. Detecting fake clicks is hard enough even when the links are pointing to ad-tracking hosts. In fact browser adblocking could be wiped out instantly if ad networks trusted websites to report their own hits.

Re: Popular iPhone apps caught sending user location data to monetization firms

#254

Earlier quoted context omitted.

You dont have to restrict yourself to using an Iphone. Embrace choice.

So I have to settle with an environment that doesn't value privacy or security on a hardware or software level because of some vague ideal of free choice. Okay.

Your statement is a bit ironic, given the thread you're commenting in.

Re: Popular iPhone apps caught sending user location data to monetization firms

#255
post #253

Earlier quoted context omitted.

Are you sure that that is actually a big problem for them? I imagine it would be quite hard to convincingly fake user data data. I could also imagine ways around that. For instance their proprietary SDK could generate the data and cryptographically sign it. Or they could require that app makers set up a special subdomain that points to their ip address. I guess it would only be worth the trouble if enough people care…

It is most definitely a problem. Detecting fake clicks is hard enough even when the links are pointing to ad-tracking hosts. In fact browser adblocking could be wiped out instantly if ad networks trusted websites to report their own hits.

That day probably someone will write a browser extension that does essentially what trackmenot did against search engines: make noise. That is, as soon as the user loads a page, N threads would crawl the same page in background and start random silent clicking while the user surfs normally. They could even make a memory map of the site and assign the random clicking to any of the active connections just in case on the other side someone tries to filter against the connection order (1st one is the user, from 2 on they're bots).

Re: Popular iPhone apps caught sending user location data to monetization firms

#256

Earlier quoted context omitted.

Do you have it as a service, or a set of OpenVPN scripts I can install? I could see a nice Grafana dashboard of my outbound traffic. Install your cert on my device, break into sessions and then further analyze traffic.

This will be a commercial service, in order to fund ongoing research efforts allowing us to quickly discover and block all possible forms of tracking, phishing, and other malicious traffic. That said, in the future, lists will be published for folks with the ability and time to operate a Pi-Hole for themselves, if preferred.

Your shame list will be golden! Please post to HN when you launch, I'll sign up.

Re: Popular iPhone apps caught sending user location data to monetization firms

#257

Earlier quoted context omitted.

So I have to settle with an environment that doesn't value privacy or security on a hardware or software level because of some vague ideal of free choice. Okay.

Your statement is a bit ironic, given the thread you're commenting in.

No, it's not unless you're already biased. Android and iOS have the issue of ad-infested apps doing bad things with your data (and I'd even assume Android is in a worse situation), but this doesn't apply to most paid or trustworthy apps. It's not solely an iOS issue.

Re: Popular iPhone apps caught sending user location data to monetization firms

#258

Earlier quoted context omitted.

So I have to settle with an environment that doesn't value privacy or security on a hardware or software level because of some vague ideal of free choice. Okay.

Your statement is a bit ironic, given the thread you're commenting in.

It also doesn't say anything about Apple's behavior regarding private data or the lengths they go to to secure iOS devices, compared to most Android manufacturers or Google.

Re: Popular iPhone apps caught sending user location data to monetization firms

#259

Earlier quoted context omitted.

Why doesn't Apple disclose the entitlements they have approved for every app on the app store?

Approving entitlements is exceptionally rare honestly. The only app I have found this happen with is Uber: https://www.businessinsider.com/uber-iphone-app-secret-acces...

I mean things like "This app can use location services and access the Internet", like Android has. Why doesn't Apple disclose these sandbox limitations?

Re: Popular iPhone apps caught sending user location data to monetization firms

#260
post #247
post #96

Earlier quoted context omitted.

>There's nothing stopping anyone from buying a Purism 5 Apart from the fact that it doesn't actually exist yet. Not to mention it's already a badly specced phone commanding top dollar being made by a small company that could easily go broke in a year. I'm all for what they are trying to achieve and really hope they succeed, but history is full of privacy phones that have failed spectacularly. For half the price I cou…

>Apart from the fact that it doesn't actually exist yet. Well, sure, I'll give you that point, but it's going to happen. >it's already a badly specced phone commanding top dollar The selling point isn't the specs. It's the RYF certification and kill switches. Even if they can't get the RYF, it's still a better option than anything else out there. >being made by a small company that could easily go broke in a year I r…

> you still have a sealed battery, a backdoored baseband, and binary blobs

A fair call, but I'm of no importance to China and am betting on lineage lasting.

Time will tell. As snarky as my comment came across, I'm entirely keen for purism to win this uphill battle, but I won't be pre-ordering.

Post reply on HN