Sensor Tower owns ad blocker and VPN apps that collect user data
buzzfeednews.com
buzzfeednews.com
This is also why I don't use a VPN I don't run (or certainly not one that hasn't been audited with a good reputation), and I certainly would never fucking dream of using a free VPN unless all the traffic over it is absolutely worthless.
... How many of these things install root certs where even after you've canceled your subscription you're still accepting their bullshit?
On the other hand, this could make for a hilarious experiment using adversarial neural networks to troll the assholes mining data from the VPNs.
It does seem like a bit of a flaw that removing the app on iOS doesn't automatically remove the profile such apps install: https://support.apple.com/en-au/HT205347
I'm pretty sure Apple will remove the VPN profile, which is why leaving a root certificate seems dangerous for users who don't know what they're for.
There can, of course, be legitimate uses for this tech. https://www.charlesproxy.com/documentation/ios/ or maybe opting out of certificate transparency reports, but they do seem like edge cases.
AFAIK only system apps can install profiles. These apps work by getting the user to install a separate profile via Safari.
> I'm pretty sure Apple will remove the VPN profile, which is why leaving a root certificate seems dangerous for users who don't know what they're for.
If these aren't enterprise profiles then Apple may not have an easy mechanism to block them (other than blocking their semantics).
Apple has a ton of variants of profiles, I keep expecting them to deprecate swaths of types/installation methods to help this be more understandable.
The Mozilla foundation is a non-profit.
The Mozilla Corporation is a for-profit entity with hundreds of millions of dollars in revenue.
The integration happened in 2015. The acquisition was not until 2017.
> Less than one percent of users in Germany installing Firefox from our main download page will receive a version of Firefox with Cliqz recommendations enabled out of the box.
> This experiment also includes the data collection tool Cliqz uses to build its recommendation engine. Users who receive a version of Firefox with Cliqz will have their browsing activity sent to Cliqz servers, including the URLs of pages they visit. Cliqz uses several techniques to attempt to remove sensitive information from this browsing data before it is sent from Firefox. Cliqz does not build browsing profiles for individual users and discards the user’s IP address once the data is collected.
Not the one that authored the text-only browser I am typing this from.
Whether Mozilla turns a profit or not makes little difference in this instance. Mozilla does not survive on donations from users. Its employees are not volunteers working for free to defend user privacy. Its generously compensated executives and staff need money from the online ad business, just like employees from the other browser vendors. If Mozilla stopped taking money from Google or some other online ad business partner, then Mozilla employees would lose their jobs.
Maybe of interest: https://dustri.org/b/mozilla-is-still-screwing-around-with-p...
Note I do not recommend using a text-only browser interactively for any sort of commercial or important online activity. I use it for recreational activities like reading HN and the websites posted here.
I used lynx many years ago in the early 90's. After switching to links, I would never intentionally use lynx again. It amazes me that people still mention lynx when the topic of text-only browsers comes up. I would be shocked if these people who recommend it are using it as their browser on a daily basis for decades.
You'd think that maybe this would cause them to exercise some strategy, like rushing to conquer mobile since Chrome's mobile ui is trash, but nope. Hell, Brave of all things is doing better at mobile than Firefox.
Did Quantum became worse or you're basically saying Mozilla is bad at marketing (and having huge vertically integrated ecosystem)?
I ended up going back for a bit and added a password manager, and now I can move between browsers easily - but as I said, it's not always straightforward, especially for _most_ non-tech users.
I find it rather easy, at least in my case. Passwords are all managed via a password manager, I barely use bookmarks, so most of the work is re-installing and configuring a few plugins, which I also don't use many of
Chrome Settings > Passwords > "Export passwords..." (under the three-dots menu).
Not sure when you last checked but the option has been available since at least Chrome 66, which was released almost two years ago: https://www.ghacks.net/2018/04/18/google-chrome-66-password-...
I distinctly recall the option to manually import passwords being harder to find (solution is to either import them from another browser or enable a flag to import passwords from a CSV file).
Ironically Firefox currently still lacks the native ability to manually export passwords, relying on add-ons or third-party tools: https://www.nytimes.com/2018/07/20/technology/personaltech/f...
I have had zero "relapses" back to safari or chrome so far, they all seem to like browsing without ads and tracking.
Firefox is the AMD of browsers.
I thought Safari introduced support for Content Blockers specifically to avoid ad blockers from phoning home and passing potentially sensitive information to the ad blocker's writer.
Lots of people then got quite cross that their favourite blocker had been blocked.
I am very glad that I can install an add blocker on my phone and I don’t have to trust that it’s not going to mine and sell my data.
I haven’t been bamboozled, I’ve just made a different decision with a different set of trade offs than you.
So the next step is to disallow exe-files. But of course you can let the exe-file get signed for a "small" fee...
Like Facebook?
Should installing the Facebook app on your phone allow them to intercept any network requests your web browser makes?
The dramatically reduced incidence of various non-technical family members having to go to me or Geek Squad for yet another virus infection says otherwise.
Part of the reason I enjoy Safari is that I've found its content blocking system to be very coherent
Apple is hurting themselves too.
They introduced a feature (Intelligent Tracking Protection - ITP) that they claim blocks ads / trackers from tracking you online on the various sites that you visit.
A simplistic explanation:
Every time you visit a website with an ad or a tracker, it leaves a cookie on your browser that identifies you. You could block many of them by telling your browser to block cookies from third-party domains. This coupled with ad blockers is one effective way to tackle online tracking.
What Apple did was to deliberately take away this control from us and ask us to trust them to deicide which cookie is allowed and which is not.
They REMOVED the feature to allow us to block third-party cookies. So now you have only 2 option in Safari - allow ALL cookies or block all cookies. You cannot block all cookies as it breaks nearly all websites. Apple claims that you should allow websites to set cookies so it can research and find out which cookies track you. And so every time you visit a website, and it sets a cookie, Apple collects this information "anonymously".
So in effect, this "privacy feature" is designed to let Apple know about every website you visit.
Ofcourse, Apple claims all this data is anonymously stored (i.e. not tied to any of your personal information like Apple id). (This idea of anonymous collection of data has already been debunked and proven false as it can be "deanonymised").
Second, Apple claims that its anti-tracking feature will not work in private browsing mode because private browsing mode doesn't save cookies once you close a tab. So in effect, Apple deliberately cripples private browsing mode, in effect, advocating that all its users use normal browsing mode (so that Apple, and others, can mine more data from its users)
Third, by taking away cookie control, Apple now is in full control of deciding which cookie can stay in the browser. This means that if you visit a website regularly, Apple will decide how its cookies should be treated, regardless of whether you want it deleted it or not.
All in all, Apples anti-tracking feature is just designed to give their competitors a harder time while giving Apple the ability to mine their users data better and also taking control away from them.
Google researchers also found that Safari's anti-tracking feature was broken and quite weak:
> ... According to the Google researchers, the vulnerabilities left personal data exposed “because the ITP list implicitly stores information about the websites visited by the user”.
> ... The researchers also identified a flaw that allowed hackers to “create a persistent fingerprint that will follow the user around the web”, while others were able to reveal what individual users were searching for on search engine pages.
Apple claims to have fixed this. But the fact remains that the feature is still not quite effective because most online trackers have moved on to browser finger printing.
The developer of the popular ad-blocker uBlock Origin has also stated that Safari / webkit ad-blocking abilities leave a lot to be desired.
Source:
- https://www.theguardian.com/technology/2019/jul/23/anonymise...
- https://www.fastcompany.com/90278465/sorry-your-data-can-sti...
- https://www.nytimes.com/2019/07/23/health/data-privacy-prote...
- https://www.ft.com/content/916a766a-3d27-11ea-a01a-bae547046...
- https://www.theregister.co.uk/2020/01/22/apple_intelligent_t...
Didn't they make blocking of 3rd party cookies the default? If I browse privately and look at the cookies on my machine by going to Prefs > Privacy > Manage Web Site Data, I don't see any cookies showing up after I've closed a page.
source?
Apple begins mining browsing data in Safari via differential privacy - https://macdailynews.com/2017/09/26/apple-begins-mining-brow...
Their CEO is one shady dude. Evasive. Knew his company was sitting on a shady foundation and just kept it going.
Large companies buy Sensor Tower's data.
It might be in the terms of service and briefly shown to them, but in the literal, practical sense, the users actually do not know! It is without their knowledge.
I've been doing the same with Proxomitron for years, although in that case I run the proxy, I certainly trust myself, and --- I'm not sure about whether these apps even have such a feature --- I can modify how/what it filters/blocks at any time.
If you stop it being able to see your traffic, it stops working.
If you stop it being able to get to the Internet, it stops working.
The problem here is needing to trust the filter program. Moving code into a sandbox doesn't help, because you still need an app outside the sandbox to make it actually filter, and the problem is not being able to trust an app.
You have X inside a sandbox. It has the filtering logic, and can't report home. Cool.
But you need Y outside the sandbox so that your content actually gets filtered. Without Y, your "filtering app" does nothing. You need code that is outside the sandbox.
But how do we set up Y? In the context of a mobile device, Y would have to be a VPN app.
But the original problem is that we can't trust VPN apps to do what they say.
So even though you moved the actual filtering logic into X, and put it in a secure sandbox, you didn't solve the problem of needing to trust an app.
(And "put Y into the trusted OS" is not a valid solution toward getting filtering on "locked-down mobile platforms".)
But the part of the code that does the vpn CANNOT be inside a sandbox. It has to interface with actual connections.
If you sandbox 100% of the code, it doesn't work.
I've been thinking about doing this and scrapping all but one of my data plans, and having a robust default-deny whitelist of allowed IPs/netblocks/hostnames on the phone vlan/ssid, but haven't worked out all the details yet.
How are you doing it?
Regarding LTE modems, I do not use a data plan on "locked-down" mobile devices for personal use. Somehow I have been able to survive on WiFi alone.
I’m looking at something like a raspberry pi zero, using the built in wifi to serve as an AP, powered from a large-ish USB battery pack, something that could run 18h+, with a USB LTE modem. Ideally I could get it small enough to strap to an ankle or something so I don’t need to bring a bag.
Root certificate ≠ root privileges
Avast recently shutdown their subsidiary Jumpshot [1] who was doing similar. They were intercepting desktop traffic through their anti-virus software and browser plugins, and then selling your complete browsing history on a per-user (don't worry it was "anonymized" /s) to anyone willing to pay. Mostly to corporations, marketing platforms, and hedge funds.
Sensor Tower is doing the precisely the same thing for the same audience.
[1] https://www.vice.com/en_us/article/wxejbb/avast-antivirus-is...
https://medium.com/@derek./how-is-nordvpn-unblocking-disney-...
Wow that's misleading.
Oxylabs and Luminati are both residential proxy networks.
Hola is a VPN that sells access to Luminati.
NordVPN is a VPN that does not sell access to anyone. It is not sending anyone else's data through your connection. There's an accusation that it shares ownership with Oxylabs, and that's about it. NordVPN might be buying, not selling, residential proxy access from someone, but it's very unclear if that's true and either way doesn't have a negative impact on their customers.
https://medium.com/@xianghangmi/resident-evil-understanding-...
But do you have any actual evidence they do so? Having some IPs that show up as residential isn't good enough.
That article doesn't call out any specific VPNs.
"Furthermore, we conducted realtime device fingerprinting when we captured each IP address. And we have successfully identified the device type and vendor information for 547,497 IP addresses. What surprised us is that 237,029 of them turned out to be IoT systems, such as web camera, DVR, and printer."
It includes a direct quote from Nord on page 5 that says they buy access to IPs, and that the individuals they buy from are "fully aware of the purpose and receive a reward for the traffic sent and received".
Even if you think the "fully aware" part is a lie, I don't think there's any reason to think the part about buying it is a lie.
Even the worst version of a VPN buying IPs from some shady dealer is very different from secretly putting data on their own users' connections. It remains quite misleading to write "oxylabs (NordVPN), luminati (Holla)", implying that Nord is doing the same thing as Hola, of turning their own users into proxies.
As far as I now, companies are now legally obligated to give California residents the opportunity to see how their personal information is being tracked, how it's being sold, and how to opt out.
The hard reality is that you have no way of knowing what's being logged if you don't have full access to the servers. I've always pushed for leaving VPN servers on operating systems running in read-only, on read-only disks, and open to the world (i.e customers who log in). It's one of the best forms of real transparency that I can think of.
Funny, I never won that one.
For anything that is not blockable on DNS level one should use uBlock Origin from Gorhill.
Seems like it will be open and shut case, quickly banning the apps and hopefully Sensor Tower entirely, especially given the other details of the article explaining they’ve already banned apps from Sensor Tower for previous violations.
And there is a huge difference between what they can do and what they actually do. In coffee shops and other places, surveillance systems can be used to steal your passwords and logins etc. But I strongly suspect each and everyone has entered their personal details while been recorded bt the surveillance system for many times. Or just in public place where someone can see, etc.
PS: just because there are worse situations, doesn't make this a good one.
The concept is fair as some are willing to pay with money, some are ok to pay with their data. Hiding the fact that you will sell data obviously deserves the punishment.
I was just talking with a colleague of mine who is in this "privacy is important" camp. But he is using mail tracker from hunter.io (since it is free).
It was really hard to explain him that that company which allows you to "Find the email address of any professional" is giving mail tracker for free in order to collect more data (to their defense they clearly say in their privacy policy and you can opt-out of the "sale" of personal information).