Pandora, Angry Birds, other apps selling private info to advertisers
lifehacker.com
lifehacker.com
Source link without the lifehacker bullshit: http://online.wsj.com/article/SB1000142405274870469400457602...
edit: Direct link to awesome visualization tool : http://blogs.wsj.com/wtk-mobile/
These phones don't keep secrets. They are sharing this personal data widely and regularly, a Wall Street Journal investigation has found.
An examination of 101 popular smartphone "apps" -- games and other software applications for iPhone and Android phones -- showed that 56 transmitted the phone's unique device ID to other companies without users' awareness or consent.
Later on, the UDID is called "supercookie" and the article emphasizes the fact that it "can never be changed or turned off".
That would be truly scary if they showed some proof that the user, as a person, could be easily identified by their phone's UDID. Okay, the carrier has that information, but who else has it? Somehow I don't think that the relationship between your phone's UDID and your identity is something easily available to just about anyone.
The UDID and the phone owner's name are easily correlated. As soon as you register for an account on a game or app, you will connect UDID to your email or first/last name. As soon as that happens, it could easily end up in Rapleaf or another system for other data brokers to get access to.
The connection just has to happen once, in one app, for all of them to benefit from it.
On the plus side, an app getting this data could auto-register you since it knows you based on your UDID as soon as you install the app, just sending you an email confirmation and a password. :-)
On iOS, this is hard, thanks to sandboxing. You pretty much have to redirect the user to the Safari browser with the UDID in the query string - which is a pretty crap experience for the user, which is why it's rarely done.
Even then you've only gotten the data into the mobile browser, which is not what the data market wants to pay for right now. People still predominantly buy things through their desktop computers.
I don't know if it's vanity or narcissism or what, but everyone assumes their 'data' has a lot of commercial value. It doesn't. Back when I was running an iPhone analytics startup, I looked into all of this stuff. Wasn't even worth the development work to monetize it.
I was thinking the iOS equivalent of a webpage with a hidden iFrame.
If we could cookie the user properly it's what I'd use for analytics instead of the UDID.
If you're talking about setting a cookie with the data broker's user ID, which then can be read by the data broker on other websites - which is the standard way of shuffling non-PII data around in the absence of an explicit user opt-in - then this doesn't work due to iOS' application sandboxing. You can set a cookie with the data broker's user ID, but the data broker won't be able to retrieve it when the user's off elsewhere surfing the web, when it matters.
Your user-agent and request details are enough for me to tie you to an existing account: https://panopticlick.eff.org/
The UDID has nothing to do with the IMEI/IMSI which are both known by the carriers.
Every time you switch that phone on that phone ID is tied to the SIM on the network.
However, it was considerate of you to think it through like that. :)
However in this case I'm willing to let it slide as in the past two days this story has been submitted three times* with a total of 30 upvotes and one comment between them.
In cases like this I usually upvote the first submission and file under 'Things that I think are interesting, but other people seem not to'.
* http://news.ycombinator.com/item?id=2018906 http://news.ycombinator.com/item?id=2019508 http://news.ycombinator.com/item?id=2018902
"Please submit the original source. If a blog post reports on something they found on another site, submit the latter."
I think PG sacrifices a lot of clarity for some cleverness here, so here's my rewrite, that I believe is identical in spirit, and hopefully at least slightly clearer:
"Please submit the original source. If a blog post reports on something they found on another site, submit the site the blogger found it on."
Personally, I'm not a rules nut, but he DID ask for the official stance.
Don't abuse the text field in the submission form to add commentary to links. The text field is for starting discussions. If you're submitting a link, put it in the url field. If you want to add initial commentary on the link, write a blog post about it and submit that instead.
Personally, I think a comment explaining the motivation for linking to a blog rather than the original source, as dshankar provided, is sufficient to justify a blog link.
A lot of blog posts wind up being just extremely wordy retweets.
I'd also submit that a blog post is the way to go if the source material is either too technical or too difficult to follow, and a blog post simply makes more sense to the HN readership. Or, even if the article is just way too long. Linking straight to a Nature article may be too much for the casual reader.
Don't expect many up links if you read out in 4 chan though
"I am a consultant for a software company that does iOS apps. It is scary how much information Apple gives us about the customer. We know everything the customer has (ever) done on their device. This includes their browsing history."
Can anyone verify this? If so, this is crazy.
Honestly, I am not too worried about my browsing history on my phone ;-)
However, you can access the address book without prompting.
Yes, for example, Angry Birds is doing these things. But it's by your request. The graphic doesn't show the data being "sold" or sent to marketers.
Does WSJ mean location as in your approximate locale (useful to understand where your users are coming from), or actual GPS coordinates?
Their lack of specificity is a bit confusing.
-Network Communications
-System tools (prevent phone from sleeping)
This doesn't include even coarse location, much less a fine GPS position. Unless they're cracking your system, they can't get more than a guessed geolocation of the IP address you're at.
Nor can they access your contacts, read your personal details, steal your emails, read your phones identifier, etc.
Looking at the WSJ story, they don't even include Angry Birds under Android in their analysis. It is, I think, fascinating that there were so many stories on here about Android apps "stealing your data", yet the iPhone market remained opaque, with so many holding some unsupported notion that a high level curation guaranteed good app behavior.
In this case, despite the Android version being only ad supported, I have comfort that it can't possibly be doing what the iPhone app is doing.
Usually country and state fulfills the above purposes just fine. I've seen GPS coordinates sent off the device and then converted to country / state before the coordinates were discarded - that's how Pinch Media used to do it. Flurry typically just works with IP address, but when GPS is used, it does the rounding off on the device first so the only thing we're sent is already inaccurate.
I doubt that it is, I think even the most aggressive and intrusive ad agency would see that the potential bad press that could come from this would outweigh any marketing benefits.
In actual fact, some contact data is sent out only when I use the "share with friends" function (which is never,) as you would expect? Right?
Time for some wireshark action methinks...
Christ, for the startup times I get, this is a decent explanation. =\
Update: other than location when you're not Apple (e.g. iAds doesn't request permission even though it uses your location).
You can opt out of iAds location stuff though, head to: http://oo.apple.com/
And I will say the new location settings in iOS 4 that let you quickly see what is requesting (and recently used) your location are nice.
It's a pretty decent opt-out method, but it only works because something hardcoded in the iOS version of Safari sends the UDID as a X-Header in the HTTP request headers -- specifically to the oo.apple.com domain (and a handful of others, all owned by Apple.)
If any other company wants to offer a systemwide opt-out for its iOS software, it's a lot more difficult.
This Activities API is also what allows developers to so easily roundtrip to a third party app and back again from within their own app. The barcode scanner is a good example.
EDIT: another example is how Launcher Pro lets you make homescreen shortcuts that "deep link" to functionality that is sometimes several menu-levels down inside an application.
However, if the app doesn't have "Read Contacts" permission then there is no way for the app to access your contacts db, and so reason to worry about it sending your contacts db to someone.
Or course, most apps do request "Internet" permission, so I suppose those apps could be scraping up some info they do have info to and sending that out to a 3rd party. :-(
Also why would you ever criticize recreational protocol analysis? Especially on here.
Transmitting location, gender and all the other data specifically to advertisers is NOT part of normal functionality.
Location Data Contacts Etc
As a developer of mobile apps and a user of both flurry and AdMob, I send them a both user's "data" in order to find out the general location of the user, as well as the OS they are running and the device they own. This isn't "selling" their data, it's giving it to these analytics platforms so we can view our audience and therefore allow us to better serve our users/customers.
The same hoopla can be brought up about Google Analytics and AdWords. This isn't a new phenomenon, and it isn't a big deal.
IP Geo-Location is a hack for when GPS Location and uniqueID aren't available, so the prudent choice to gain accurate analytic info would be to use the most accurate. Especially if you are a developer / publisher trying to tailor your functionality to your particular audience.
Android does inform you, in advance of installation of exactly what information the application would like access to so you can be absolutely aware of what information you are freely giving up when installing an application. Your only means to block access however after installation is if you have root access and modify host entries.
I was pissed until I read the FAQ and discovered when they're using data and what they're using it for. Basically: If you've registered with Crystal Something-or-Other they send your data to them. The WSJ article, at least in the Angry Birds case, seems to have sensationalized things.
Free and paid versions of Angry Birds were tested on an iPhone.
The apps sent the phone's UDID and location to the Chillingo unit of Electronic
Arts Inc., which markets the games. Chillingo says it doesn't use the
information for advertising and doesn't share it with outsiders.
Chillingo does not deny collecting the info, but they do deny using the information for advertising or sharing it with outsiders.Just the other day I implemented a hidden webview in an iPhone app. The webview subscribes users to third-party affiliation programs (e.g. Groupon) automatically ... basically the thirdparty service is chosen based on how much money it gives to affiliates / if it's available at the user's location (that's why it needs to be automatic).
Behind the scenes a Javascript is loaded in the webview that does plain requests to these services. Because many do not provide an API, I have to fake it ... XmlHttpRequest is not enough because of all the restrictions. So I implemented my own XmlHttpRequest-type functionality by using webview-delegates, but without the restrictions.
The logic behind using a WebView is that you can load / update the subscription logic on the server-side, without updating the application in the iTunes Store. Best thing of all, this works even with Apple's earlier restrictions related to dynamic languages.
Also, the logic behind doing this client-side is that many services complain when requests come from the same IP. You cannot be caught when moving this client-side.
Just to be clear: users are properly informed they are going to get subscribed for spams from their city.
Oh, the horror. Though I'm quite thankful for the breakdown, as a lot of this is probably almost completely unknown to people, some of the inclusions seem rather suspect. I wonder if they included legitimate data transmissions to pad the icon gallery / table.
Ah, I would never use a jailed iPhone. So much less usable.
There is nothing wrong with this business model per say, but doing it without the express consent with your users is wrong and making it personally identifiable is wrong.