Live data from Hacker News

Sensor Tower owns ad blocker and VPN apps that collect user data

buzzfeednews.com

111–120 of 125 posts

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#111
post #87
post #31

Earlier quoted context omitted.

"Every other browser vendor is a for-profit entity, ..." Not the one that authored the text-only browser I am typing this from. Whether Mozilla turns a profit or not makes little difference in this instance. Mozilla does not survive on donations from users. Its employees are not volunteers working for free to defend user privacy. Its generously compensated executives and staff need money from the online ad business,…

Can you recommend one text-only browser?

https://en.wikipedia.org/wiki/Links_(web_browser)

Note I do not recommend using a text-only browser interactively for any sort of commercial or important online activity. I use it for recreational activities like reading HN and the websites posted here.

I used lynx many years ago in the early 90's. After switching to links, I would never intentionally use lynx again. It amazes me that people still mention lynx when the topic of text-only browsers comes up. I would be shocked if these people who recommend it are using it as their browser on a daily basis for decades.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#112
post #98

Earlier quoted context omitted.

Assuming they do so, the comment I replied to is still extremely misleading. But do you have any actual evidence they do so? Having some IPs that show up as residential isn't good enough. That article doesn't call out any specific VPNs.

Very misleading yes: https://luminati.io/static/patent/2019-12-31_NordVPN_Complai...

That is an accusation that Nord or third party partners is turning devices into residential proxies.

It includes a direct quote from Nord on page 5 that says they buy access to IPs, and that the individuals they buy from are "fully aware of the purpose and receive a reward for the traffic sent and received".

Even if you think the "fully aware" part is a lie, I don't think there's any reason to think the part about buying it is a lie.

Even the worst version of a VPN buying IPs from some shady dealer is very different from secretly putting data on their own users' connections. It remains quite misleading to write "oxylabs (NordVPN), luminati (Holla)", implying that Nord is doing the same thing as Hola, of turning their own users into proxies.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#113
post #89
post #57

Earlier quoted context omitted.

I use two devices. The first runs a kernel+userland I can edit and acts as the gateway/AP and DNS server for the second, which runs some commercially-motivated, "locked-down" consumer OS.

What hardware are you using for the gateway/AP? What's the backhaul, a USB LTE modem? Do you carry it in a handbag with a USB battery pack? I've been thinking about doing this and scrapping all but one of my data plans, and having a robust default-deny whitelist of allowed IPs/netblocks/hostnames on the phone vlan/ssid, but haven't worked out all the details yet. How are you doing it?

The gateway is a small form-factor computer with a rechargeable battery, e.g., a netbook or laptop. The AP is a SBC that the preferred kernel, e.g., NetBSD, OpenBSD, Linux, etc., supports. The AP draws power from the gateway's battery via USB.

Regarding LTE modems, I do not use a data plan on "locked-down" mobile devices for personal use. Somehow I have been able to survive on WiFi alone.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#114
post #113
post #89

Earlier quoted context omitted.

What hardware are you using for the gateway/AP? What's the backhaul, a USB LTE modem? Do you carry it in a handbag with a USB battery pack? I've been thinking about doing this and scrapping all but one of my data plans, and having a robust default-deny whitelist of allowed IPs/netblocks/hostnames on the phone vlan/ssid, but haven't worked out all the details yet. How are you doing it?

The gateway is a small form-factor computer with a rechargeable battery, e.g., a netbook or laptop. The AP is a SBC that the preferred kernel, e.g., NetBSD, OpenBSD, Linux, etc., supports. The AP draws power from the gateway's battery via USB. Regarding LTE modems, I do not use a data plan on "locked-down" mobile devices for personal use. Somehow I have been able to survive on WiFi alone.

So you carry around a laptop powered on all day when you are out? What about battery life?

I’m looking at something like a raspberry pi zero, using the built in wifi to serve as an AP, powered from a large-ish USB battery pack, something that could run 18h+, with a USB LTE modem. Ideally I could get it small enough to strap to an ankle or something so I don’t need to bring a bag.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#115

Earlier quoted context omitted.

> Every other browser vendor is a for-profit entity, and as such will limit good ad-blocking measures as Safari I thought Safari introduced support for Content Blockers specifically to avoid ad blockers from phoning home and passing potentially sensitive information to the ad blocker's writer. Lots of people then got quite cross that their favourite blocker had been blocked.

Apple came up with a better way to mine your personal data through its Safari browser. They introduced a feature (Intelligent Tracking Protection - ITP) that they claim blocks ads / trackers from tracking you online on the various sites that you visit. A simplistic explanation: Every time you visit a website with an ad or a tracker, it leaves a cookie on your browser that identifies you. You could block many of them…

> So now you have only 2 option in Safari - allow ALL cookies or block all cookies.

Didn't they make blocking of 3rd party cookies the default? If I browse privately and look at the cookies on my machine by going to Prefs > Privacy > Manage Web Site Data, I don't see any cookies showing up after I've closed a page.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#116

Earlier quoted context omitted.

Apple came up with a better way to mine your personal data through its Safari browser. They introduced a feature (Intelligent Tracking Protection - ITP) that they claim blocks ads / trackers from tracking you online on the various sites that you visit. A simplistic explanation: Every time you visit a website with an ad or a tracker, it leaves a cookie on your browser that identifies you. You could block many of them…

> So now you have only 2 option in Safari - allow ALL cookies or block all cookies. Didn't they make blocking of 3rd party cookies the default? If I browse privately and look at the cookies on my machine by going to Prefs > Privacy > Manage Web Site Data, I don't see any cookies showing up after I've closed a page.

The gist of my argument is that you have to cede control to them and trust them, for something that we could explicitly do before.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#117

Earlier quoted context omitted.

... This entire discussion IS about bad software that DOES harm you, and you rag on the measures to specifically protect against something like that? What the heck?

Yes, I'm not saying there is no harmful software, I'm saying these kind of "protections" are the wrong solution. The same people who install blindly any add-ons will also install any exe-files if the promising website tells them to because the browsers add-on-system does not provide the required mechanics. So the next step is to disallow exe-files. But of course you can let the exe-file get signed for a "small" fee..…

> The same people who install blindly any add-ons

Like Facebook?

Should installing the Facebook app on your phone allow them to intercept any network requests your web browser makes?

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#118

Earlier quoted context omitted.

> Every other browser vendor is a for-profit entity, and as such will limit good ad-blocking measures as Safari I thought Safari introduced support for Content Blockers specifically to avoid ad blockers from phoning home and passing potentially sensitive information to the ad blocker's writer. Lots of people then got quite cross that their favourite blocker had been blocked.

Apple came up with a better way to mine your personal data through its Safari browser. They introduced a feature (Intelligent Tracking Protection - ITP) that they claim blocks ads / trackers from tracking you online on the various sites that you visit. A simplistic explanation: Every time you visit a website with an ad or a tracker, it leaves a cookie on your browser that identifies you. You could block many of them…

> is designed to let Apple know about every website you visit.

source?

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#119

Haha, I quietly called them out few years ago: https://news.ycombinator.com/item?id=17823292 Their CEO is one shady dude. Evasive. Knew his company was sitting on a shady foundation and just kept it going. Large companies buy Sensor Tower's data.

SimilarWeb is another company with millions of funding that is sitting on a shady foundation as well.

I'm waiting for news about OneTrust, the company handling GDPR/CCPA cookie management for a ziiilllion sites. I can't imagine they aren't getting in on this action.

Re: Sensor Tower owns ad blocker and VPN apps that collect user data

#120
post #28

Earlier quoted context omitted.

> ... How many of these things install root certs where even after you've canceled your subscription you're still accepting their bullshit? It does seem like a bit of a flaw that removing the app on iOS doesn't automatically remove the profile such apps install: https://support.apple.com/en-au/HT205347 I'm pretty sure Apple will remove the VPN profile, which is why leaving a root certificate seems dangerous for users…

> It does seem like a bit of a flaw that removing the app on iOS doesn't automatically remove the profile such apps install AFAIK only system apps can install profiles. These apps work by getting the user to install a separate profile via Safari. > I'm pretty sure Apple will remove the VPN profile, which is why leaving a root certificate seems dangerous for users who don't know what they're for. If these aren't enter…

If Safari has a system back button to take me back to the app, it knows enough to include the “originating app” for the profile. Similarly it could create an association between the domain the profile is hosted on and the app. Finally, Apple could indeed change how profile installation works such that profiles need to be signed and associated with either an Enterprise account or a per-app developer account, to make deleting such apps-with-profiles in future more robust. Lastly, like privacy warnings, Apple could say that Certificate Owner has installed a root certificate to monitor all communications and let you opt out. That would be ideal, to deprecate existing methods and even more explicitly support app-based root certificates in their privacy warning flows.
Post reply on HN