Pandora app found to be sending DOB, gender and location info to ad servers
engadget.com
engadget.com
http://blog.pandora.com/faq/contents/60.html http://blog.pandora.com/faq/contents/392.html
They also outlines their location sharing policy:
You may also get a request for location permissions. This data is used to provide better geolocation for certain ad campaigns. Again, this function would always be under your control. Each time an ad wants to use your location to provide more personalized results, you will be asked for permission to use your location, and you can decline this at any time.
Mobile-App Makers Face U.S. Privacy Investigation: http://online.wsj.com/article/SB1000142405274870380630457624...
In it, the journal reported:
The Journal tested 101 apps and found that [...] in Pandora's case, both the Android and iPhone versions of its app transmitted information about a user's age, gender, and location, as well as unique identifiers for the phone, to various advertising networks. Pandora gathers the age and gender information when a user registers for the service.
As far as I know, the journal stands by their story. The location pushing Tyler details was found in the bundled AdMob code, which does check for ACCESS_COARSE_LOCATION and ACCESS_FINE_LOCATION. While it would seem to be relying on the bundler to request those, I wonder if there isn't something going on that allows AdMob to grab location information if another application that uses the AdMob code has requested it. Android applications can expose public or private (same signer) APIs to other applications on the same device, and send whatever data out of them they have access to.
But there are two reasons it doesn't make sense to me:
1) This is a huge violation of trust - Google specifically says that you shouldn't collect information just to add it to the ad request.
2) It is not enough that the app where the information comes from also uses adMob, it has to be signed by the same key as the app that is reading the information. That is only possible if both apps where developed by the same developer.
Then again, they could be doing the right thing and getting with their engineers to make sure they give accurate answers. The whole thing sounds preliminary: what the code COULD do, versus what it actually sends over the air.
Doesn't bother me so much either.
I do end up with 'interesting' coupons every so often. It's a little like hearing back from an estranged friend.
Or, alternatively, some other social signal that people wanted to trade, similar to Button Men at conventions: http://en.wikipedia.org/wiki/Button_Men
Settings -> Location Services.
No entry for Pandora, so unless it's hacking away through private APIs then it's not sending location info.
http://ad.doubleclick.net/pfadx/pand.iphone/prod.nowplaying;...
Can anyone show me a concrete example of actual harm resulting from ad targeting? I get that you don't like it, but how are you hurt by it?
No, they're not. They provide a service for a price. In this case that price includes personal data. I don't want to pay that price. I would like to know that I'm paying that price so I can make an informed decision on if I want to continue using paying for the service.
>actual harm
It depends of in you count an unknown intrusion of your privacy to harm your privacy.