Live data from Hacker News

Sensor Tower owns ad blocker and VPN apps that collect user data

buzzfeednews.com

1–10 of 125 posts

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#5
post #2

Most of them are using your connection to sell access to residential proxies: oxylabs (NordVPN), luminati (Holla) etc.

They do far more than simply install backdoors for residential proxy networks. They also capture and resell your entire http(s) request history via their mitm. That's every single HTTP request every single app on your phone makes. It's a gold mine of information. They also sell profiles of exactly which apps you have installed on your phone, how often you're using each, and geolocation data if they get that permission.

Avast recently shutdown their subsidiary Jumpshot [1] who was doing similar. They were intercepting desktop traffic through their anti-virus software and browser plugins, and then selling your complete browsing history on a per-user (don't worry it was "anonymized" /s) to anyone willing to pay. Mostly to corporations, marketing platforms, and hedge funds.

Sensor Tower is doing the precisely the same thing for the same audience.

[1] https://www.vice.com/en_us/article/wxejbb/avast-antivirus-is...

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#6
This is basically a MITM proxy, which I'd say is really essential for true adblocking and content filtering, especially on the locked-down mobile platforms and with the rise of HTTPS. The question is then who runs the proxy and whether you trust them.

I've been doing the same with Proxomitron for years, although in that case I run the proxy, I certainly trust myself, and --- I'm not sure about whether these apps even have such a feature --- I can modify how/what it filters/blocks at any time.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#8

This is basically a MITM proxy, which I'd say is really essential for true adblocking and content filtering, especially on the locked-down mobile platforms and with the rise of HTTPS. The question is then who runs the proxy and whether you trust them. I've been doing the same with Proxomitron for years, although in that case I run the proxy, I certainly trust myself, and --- I'm not sure about whether these apps even…

It should be entirely possible to run the MITM proxy completely on-device, in which case you don't need to trust anything.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#9

> Armando Orozco, an Android analyst for Malwarebytes, said giving root privileges to an app exposes a user to significant risk. Root certificate ≠ root privileges

It's true for both!

It is, but this isn't the first time mainstream news has confused certificates with privileges. (Remember the Facebook VPN thing?)
Post reply on HN