Dozens of iPhone Apps 'Constantly' Sending Location Data to Data Monetization Firms

by

Dozens of popular iPhone apps are sharing the location data of millions of mobile devices with third-party data monetization firms, according to a group of security researchers called GuardianApp (via TechCrunch).

The apps in question are mostly news, weather, and fitness apps that require access to location data to work properly, but then share that data to earn money.


According to security researchers, the apps send both precise location and other sensitive customer data to data monetization companies "at all times, constantly" sometimes without customers being aware of the location data collection. The information is used for purposes like creating databases for ad targeting.

Researchers used tools to monitor network traffic to discover apps collecting Bluetooth LE data, GPS longitude and latitude, WiFi SSIDs, accelerometer information, battery charge percentage, location arrival/departure timestamps, and more.

While the apps say that personally identifiable information is not included in the data collection, one of the researchers, Will Strafach, told TechCrunch that latitude and longitude coordinates can provide information on a person's home or work. Many customers who agree to provide apps with location data may not be aware of the extent of the information being collected and shared.

Apps that were found to be collecting location info and sending it to data monetization firms include ASKfm, NOAA Weather Radar, Homes.com, Perfect365, C25K 5K Trainer, Classifieds 2.0 Marketplace, GasBuddy, Photobucket, Roadtrippers, Tapatalk, and more, with a full list available on the site.

The data is being sent to companies that include Reveal, Sense360, Cuebiq, Teemo, Mobiquity, and Fysical. These companies denied wrongdoing, suggested customers were able to opt out at any time, and said that developers are required to inform customers about the data collection.

Some of the apps in question do indeed have clear data collection notices when opening them up for the first time, but data monetization firms do not make sure apps are following disclosure policies and not all do.

"None of these companies appear to be legally accountable for their claims and practices, instead there is some sort of self-regulation they claim to enforce," said Strafach.

iPhone users who want to avoid having their location data shared with data monetization firms should be wary of the third-party apps they install that are using location services. Limiting ad tracking in Privacy settings by going to Privacy > Advertising is recommended.

GuardianApp also suggests users use a generic name for router SSIDs and turn off Bluetooth functionality when Bluetooth is not in use.

Top Rated Comments

(View all)
Avatar
27 months ago
I didn't think Apple allowed this sort of thing.
Score: 16 Votes (Like | Disagree)
Avatar
27 months ago
The best way to be able to still use some of these apps (like Pay By Phone parking) that need your location to work well, but not share your location all the time, is to make sure Location Privacy is set to "While Using".

Any app that tries to keep using your location in the background when set to "While Using" will pop up a big blue banner saying "<app> is currently using your location." You can then remove the offending app, or at least kill it. Waze has this issue, but I suspect it's a longstanding bug and not intentional.
Score: 11 Votes (Like | Disagree)
Avatar
27 months ago
I don't use any of the apps in question.

The linked article would carry more weight, if it was more than an advertisement for Guardian's new VPN app.
Score: 10 Votes (Like | Disagree)
Avatar
27 months ago

The best way to be able to still use some of these apps (like Pay By Phone parking) that need your location to work well, but not share your location all the time, is to make sure Location Privacy is set to "While Using".

Yes, at the risk of stating the obvious, for most apps there is a huge difference between granting Location Services access "While Using" versus "Always." For example, I do use GasBuddy, but I'm not too concerned about it because I set Location Services to "While Using," and I only fire it up once a month. There are virtually no third-party apps on my phone that I grant "Always" access to.

You can then remove the offending app, or at least kill it. Waze has this issue, but I suspect it's a longstanding bug and not intentional.

Ironically, the Waze UI is so bad that "just kill the app (and relaunch it from scratch)" is my default technique for navigating through the app.
Score: 7 Votes (Like | Disagree)
Avatar
27 months ago

Would you mind explaining all this in a bit more detail? Not familiar with much of what you’re talking about.

Only for Linux!?
More like a Question, can this be done by running Linux in a VM on my Mac and then use that one to set the DNS.
This seems to me a bit geeky if you ask me.
I do have a second generation Raspberry Pi, would that work, is there any non geeky way to set this up, most of the time if you go to those sites explaining this stuff makes it too hard for non geeks.
I am by no means a dummy but networking is not easy at all.

Yup, I too would like to know more about it, seems like you need some kind f Linux distribution to get this to work.

Pi-Hole can be set up on Linux or Raspbian. If you use Linux, don't run it on Ubuntu LTS 18.04 because it isn't yet supported.

I've tested and run it on a Raspberry Pi (Raspbian OS), Ubuntu 16.04 LTS on a Dell Optiplex 990 and I've run it in a VM (virtual machine) under Ubuntu in VMware Fusion on a Mac Mini. Currently I'm just using the Raspbery Pi as the DNS server, or Pi-Hole.

All you have to do once set up is to tell your WiFi router/access point and/or firewall to use the IP address of the Pi-Hole for it's DNS. You can also manually set each device, phone, tablet, PC, laptop et al. to point to the Pi-Hole for it's DNS.

Once you get it setup then you can add curated blocklists to the 'gravity service' of Pi-Hole and it imports all those domains on the list into your Pi-Hole for blocking. You can also blacklist and whitelist domains as needed too. There will always be some false-positives or sites that are blocked that you don't want blocked and once you square off those rough edges its smooth sailing.

Here are some sites that I get most of my block lists from:

* https://firebog.net/
* https://blog.cryptoaustralia.org.au/2017/11/15/favourite-block-lists-cryptoaustralia/
* https://github.com/StevenBlack/hosts
* https://discourse.pi-hole.net/t/to-completely-block-facebook-blocklist-facebook-domains/8141

Here is the Raspbery Pi hardware I'm using. https://www.amazon.com/gp/product/B01D92SSX6/ref=oh_aui_search_detailpage?ie=UTF8&psc=1

I'm happy to answer more questions if you have them. I love the Pi-Hole and never want to be on the Internet again without it.

Here is a video on the setup process.
Score: 6 Votes (Like | Disagree)
Avatar
27 months ago
So privacy on iOS is fake
Score: 6 Votes (Like | Disagree)

Top Stories

Here's How You Can Download iOS 14 and iPadOS 14 Around the World [It's Out]

Wednesday September 16, 2020 2:36 am PDT by
Apple's official public release of iOS 14 and iPadOS 14 dropped on Wednesday, September 16, just a day after the company released the Golden Master to third-party developers. Also set to be made available to the general public for the first time are watchOS 7 and tvOS 14. Getting Started With iOS 14 Video Click image to watch iOS 14 Getting Started While that's left a lot of developers...

When Will the iPhone 12 Launch? Here's What We Know

Wednesday September 16, 2020 6:12 am PDT by
Yesterday's "Time Flies" Apple event saw the release of the Apple Watch Series 6, Apple Watch SE, iPad 8, and iPad Air 4, but no new iPhone models. Rumors before the event strongly alleged that it would not see the unveiling of new iPhones, with many reports pointing to an October launch. The lack of new iPhone models yesterday seems to confirm that the iPhone 12 lineup will not appear...

Apple Releases iOS 14 and iPadOS 14 With Home Screen Redesign, App Library, Compact UI, Translate App, Scribble Support, App Clips, and More

Wednesday September 16, 2020 12:48 pm PDT by
Apple has released iOS 14 and iPadOS 14, the newest operating system updates designed for the iPhone and iPad. As with all of Apple's software updates, iOS 14 and iPadOS 14 can be downloaded for free. iOS 14 is available on the iPhone 6s and later, while iPadOS 14 is available on the iPad Air 2 and later. The updates are available on all eligible devices over-the-air in the Settings app. To ...

Apple Updates AirPods 2 and AirPods Pro Firmware to Version 3A283

Monday September 14, 2020 11:24 am PDT by
Apple today released new 3A283 firmware updates for the second-generation AirPods and the AirPods Pro. The second-generation AirPods are being updated from the 2D15 firmware they were previously running, while the AirPods Pros are being updated from the 2D27 firmware they had installed previously. Apple does not provide details on what's included in refreshed firmware so we don't know what's ...

Spotify Says Apple One Bundle Will Cause 'Irreparable Harm to Developer Community'

Tuesday September 15, 2020 12:26 pm PDT by
Apple today announced Apple One, a series of new subscription bundles that provide access to various Apple services at a combined monthly price. In response, Spotify sent out statements (via Peter Kafka) to the press decrying Apple's anti-competitive behavior and calling on "competition authorities" to stop Apple before it is able to cause "irreparable harm" to developers.Once again, Apple...

iOS 14, iPadOS 14, watchOS 7, and tvOS 14 Will Be Released September 16

Tuesday September 15, 2020 11:06 am PDT by
Apple today announced that iOS 14, iPadOS 14, watchOS 7, and tvOS 14 will be officially released on Wednesday, September 16. Apple has seeded the final Golden Master beta versions of each update to developers in advance. ‌iOS 14‌ and iPadOS 14 introduce dozens of new features, including a redesigned Home Screen that supports widgets on the iPhone and iPad for the first time. For more...

New AirPods Pro Firmware Introduces Spatial Audio Support and Automatic Switching

Monday September 14, 2020 12:22 pm PDT by
The new 3A283 firmware that Apple released for the AirPods Pro today appears to introduce support for Spatial Audio, a new feature coming to the higher-end AirPods with iOS 14. Multiple reports on Twitter and the MacRumors forums indicate that the firmware update adds a "Spatial Audio" option to the Control Center, which can be activated to enable the feature. Note that using Spatial Audio...

Apple Releases Safari 14 for Mac Ahead of macOS Big Sur Launch

Wednesday September 16, 2020 1:40 pm PDT by
macOS Big Sur didn't launch alongside iOS 14, iPadOS 14, tvOS 14, and watchOS 7 today, with the update coming later this fall, but Apple did release the Safari 14 update for macOS Catalina and macOS Mojave users. Safari 14 brings improved performance, customizable start pages, a Privacy Report to see which cross-site trackers are being blocked, and a new tab bar design that provides tab...

Full Transcript of Apple's 'Time Flies' Event With Apple Watch and iPad Updates

Tuesday September 15, 2020 8:46 am PDT by
Apple's virtual "Time Flies" event kicks off today at 10:00 a.m. Pacific Time, with Apple expected to debut new Apple Watch and iPad models, but it appears we may not see the iPhone 12 until next month. While we're not expecting to see new iPhones today, Apple's software updates for its various platforms are likely nearly ready for launch, so we may be hearing more about them today. Check...

Everything Apple Announced at Today's iPad and Apple Watch Event in Just Seven Minutes

Tuesday September 15, 2020 2:19 pm PDT by
Apple today held its annual September event, but this year was a bit different because no new iPhones were announced. The "Time Flies" event focused on the Apple Watch Series 6 and the iPad Air, and saw the debut of a new Apple One services bundle. Subscribe to the MacRumors YouTube channel for more videos. It took Apple an hour to introduce the new devices, but we've recapped the event in...