Android and iOS data collection
tomsguide.com
tomsguide.com
Abstract:
> We investigate what data iOS on an iPhone shares with Apple and what data Google Android on a Pixel phone shares with Google. We find that even when minimally configured and the handset is idle both iOS and Google Android share data with Apple/Google on average every 4.5 mins. The phone IMEI, hardware serial number, SIM serial number and IMSI, handset phone number etc are shared with Apple and Google. Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this. When a SIM is inserted both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple together with their GPS location. Users have no opt out from this and currently there are few, if any, realistic options for preventing this data sharing.
That is the extent of the data sharing unless the user allows more.
I was not aware that my location was being tracked by other people's iPhones.
It's been doing this for nearly a decade since I believe their acquisition of WifiSlam back in 2013. They use it roughly triangulate a device's position when GPS/Cellular is not available.
If you can imagine it happening, it is safest to assume that it is already happening.
Edit: he/their
If Apple is using iPhones to pair location and MAC addresses of nearby devices, that is indeed "location being tracked by other people's iPhones".
Whether your (and everybody else) iPhone and gps helping tell where my stolen bicycle is, is a good enough benefit to outweigh the privacy trade off is a good question (that Apple never asked me before opting me into their global Bluetooth surveillance platform).
They weren't fined whatsoever for the collection of the data. The fine was for stonewalling the investigation.
> But, the commission said, Google did not engage in illegal wiretapping because the data was flowing, unencrypted, over open radio waves.
At what point does reading unencrypted radio waves on open-use frequencies become an invasion of privacy? It'd be like a restaurant owner requiring people get permission before being able to write down the restaurant's name. If it's possible to passively read it for free, you can't control who views it.
In any case, yes Apple may be within legality to record devices nearby broadcasting their location, but it feels scummy to me.
Those are definitely not randomized by default, even if operating systems tell them to act as if they are.
And even then, why would that require being on the same network? I can see my wifi router's MAC without being connected to the network, ditto for your phones bluetooth.
Edits because mobile.
The hardware still has a set MAC, and the rest of the hardware whos addresses are being reported may or may not be randomized.
If the transmitter is inside a house, and the unintended receiver is outside, that seems pretty clearly a violation of privacy.
They're putting radios everywhere and anywhere now, but I don't think consumers generally expect and want anyone to be able to hear their devices, let alone scoop up the data and store it in a database with gps coordinates.
You might also ask at what point does reading of unencrypted audio frequency vibrations originating from a private home become an invasion of privacy? Most homes aren't perfectly soundproof, and it's not too hard to make devices that can listen in. Is it ok just because you can? Same for radio imaging, etc.
When you pair a tag with a device they agree a shared key which is used to create a temporary identifier that changes every couple of hours. The tag broadcasts this identifier every few seconds, and nearby devices who hear it create a location message based on their position and encrypt it using the identifier as a public key, and then send that to Apple.
Apple can’t read that message. Only the paired device can recreate the current temporary private key and decode for location data, etc. The paired device knows what the current temporary identifier should be and just asks Apple for any associated messages the Find My network may have received
In theory Apple can’t snoop any of this - as long as the shared secret does leave the paired devices. It’s always possible there’s a back-door for targeted unveiling under legal obligation, of-course - but it’s supposed to be private under general use.
My AirTags have their "location being tracked by other people's iPhones".
Sure - if we believe Apple (and I mostly do here) that their protocol and encryption works the way they describe, and that there's no bugs or back doors - then the only person who get to see my AirTag's location is me.
But that still means "And Apple have clearly decided that’s ok" that my AirTags have their "location being tracked by other people's iPhones". They're selling me products on the assumption that your iPhone (and everybody else's, or at least enough other iPhone owners to make it useful) will happily listen out for bluetooth signals from AirTags, power up their GPS to get a current location, encrypt a bunch of data, then use your cellular data plan to send it to Apple for me.
I'm sure 99% of the people on HN, if you'd told them 10-15 years ago that's what their phone would be doing by default in 2021, they'd have laughed at you and called you delusional. Or asked which dystopian scifi writer came up with that insane plot device.
That's the benefit that they expose to the user. What they do with the data as well as that is only known to some people in Apple.
This is how you can triangulate those Apple key rings, that aren’t even connected to the internet.
> Users have no opt out from this
> Both iOS and Google Android transmit telemetry
> both iOS and Google Android send details to Apple/Google
Are there no details on what sort of data these packets contain? It should be possible for users to decrypt and inspect these packets.
>Traffic from the phones ran through the laptop, which decrypted logged and analyzed data, then re-encrypted the data and sent it on its way to the destination servers.
That's from the article. I haven't read the paper.
What are my options? Banning guests from my network is enough or I have to physically not allow phones near my wifi?
Full disclosure I work for Google, but not on anything related to this.
I used location sharing actively then as now, found it mostly annoying - but also learnt how they built up their SSID location databases.
I did find it creepy, but could also see how it would massively assist location services.
For phones, the only mitigation is a lifestyle change to switch from always-reachable to scheduled availability windows or the always-async workflows of pre-mobile computing. A faraday bag can deny realtime telemetry, even if it's cached for relay when connectivity returns.
And, of course, you can't install or update any apps.
The iPhone depends on Apple services to function even outside of iCloud and updates. I've tried.
Most apps aren't updated more than once a week, some are not updated for months.
There are a few high-quality iOS apps which support NAS (e.g. WebDAV) for local, surveillance-free, cross-device sync.
Gmail accounts require password entry on the device, even if the account is installed via Apple Configurator.
Is that still true, if the password provided in the profile is an App Password for the account? IIRC those can be used for direct IMAP access to Gmail's servers without those servers complaining; so I would expect them to also work fine for creating a Gmail web-API binding.
Regardless of an app's implementation of polling/notifications, most apps will poll servers when first started or network service is restored.
Good that Apple provides this "stable firewall interface".
In some ways, even cellular connectivity itself is problematic or any baseband system that requires some form of out-of-band processing to function (even if it doesn't "call home").
Most people won't know (or care) about any of this anyway, and the disruption trade for some invisible gains that are supposed to come out of unplugging like this isn't likely to attract any reasonable mass of users to do it. It would probably be mostly destructive anyway considering the information flow of civilisation depends on so much of this integration now.
Technically we could do without all of this, but practically it would be luddite's errand to try and do any this.
I wonder what we could do instead, but considering the min-maxing for profit sets the stage today, I doubt someone can come up with an alternative that yields the same (perceived) benefit from using Google's or Apple's technologies.
Considering most new people from the past few years are primarily mobile users and a lot of those never even had access to (or a need for) a desktop-like type computing, there is very little mindshare about what else might be possible in the digital realm.
The point of using an "ecosystem" is positive network effects, in the case of iOS it means a pool of shared-risk protection against common attacks, and a business model which yielded a huge app ecosystem, a.k.a front-end clients for web services. The greater those positive effects, the greater the incentive to mitigate the negative effects. Some are provided by Apple's obscure combinations of on-device Settings, device policy that is only configurable with Apple Configurator, or enterprise MDM policy.
It is unnecessary that such mitigations be employed by "most people", they only need to pass a cost-benefit analysis for those who use them. E.g. many iOS remote attacks can be mitigated by disabling Javascript, yet there has not been an option for per-site whitelisting of JS in Safari. Brave on iOS (reskin of Safari) provides this policy with one-click per site and now Apple allows Brave to be the system-wide default, possibly due to antitrust/EU/legal pressure. iOS 15 has added web extensions, which are already transforming the web experience.
It could be argued that if more people used "surveillance escape valves", there could be pressure to close them. The bigger the ecosystem, the more incentives there are to jump through hoops to gain benefits and mitigate risks. It's an ongoing negotiation, not blind surrender, even if the balance of power begins with asymmetry. E.g. people may start using Brave on iOS because it blocks Youtube interstitial video ads, allowing free access to the network effects of the YT ecosystem without paying a monthly fee. But once they are using Brave, JS security protections are one click away. The pendulum swings back and forth.
From 2012, https://www.zdnet.com/article/president-obamas-top-secret-ip...
> The president is getting his daily intelligence briefing on an iPad. Ten years ago we wouldn't have done that, but that's what the president wants, so that's what he gets. Now, that iPad is neutered-it has no connectivity. It gets plugged into a docking station. We can do that for the president, but can we can't scale that. So the question is, can we use commercial products that are secure?" said Levine.
This can be said for pretty much any technology/software/hardware/mitigation that some people dismiss out of hand…
> It could be argued that if more people used "surveillance escape valves", there could be pressure to close them.
I would even go one step further and argue that our devices should actively send spoofed data (not necessarily random) and poison the data wells these companies like to drink from to amass their power they wield asymmetrically at scale against individuals.
I mean, your work could be dependent on an embedded appliance from an enterprise vendor, where that 'appliance' just consists of an app running on an iPad in kiosk mode sealed into an ugly case, with its lightning port hard-wired to a particular accessory.
If you're an IT admin of an organization and you have to support an appliance like this within your Intranet, it's in your best interests to lock it down from doing anything other than "its job as an appliance." For the same reason you wouldn't leave any ports open on a machine/VM other than the ones it needs to perform its function.
$appliance does not require mdm
This is a solution that doesn’t scale, and any IT admin supporting more than a handful of Apple devices in their network should look at MDM.
In this case I was suggesting that you have a vendor upstream of you doing this, where you then take receipt of a system (e.g. a POS system) of which an "embedded" iPad is a one component, and is a black box, perhaps even epoxied into an enclosure.
In such a case, you literally cannot do anything to the iPad. It's locked down into its kiosk application, and getting admin access to it would require taking the system it's a part of apart to a degree that would void your warranty with the vendor.
Instead, the only thing you can alter, is the network the iPad connects to.
...the only alternative right now is throwing cash at a librem5 and there's still plenty of work until it's feasible for a linux phone as a daily driver.
Looking further ahead, Pinephone development is active.
The question of course is whether they do anything equally bad as either Google/Apple or the NSA. It looks obvious to me that Russia funds this because they don't want the former inside their devices.
Trying to run their own mass surveillance using Sailfish wou be pretty much a waste of resources. There are no masses that use it and the Russian opposition could easily avoid touching such device. However, in typical Stalin/KGB/Putin-style paranoia you would want to eavesdrop your friends to make sure they don't work against you. So that is somewhat worrying.
Disclaimer: Typed on a Sailfish device.
I think GrapheneOS provides a maximally usable experience with maximal control over your device.
Unfortunately linux phones are nowhere near the polish of Android forks, and let’s be honest - hardware-wise a 3-4 years old phone mid-level android hardware is a minimum.
Android works fine without the Google bits. Make sure to get a device which is supported by an AOSP-derived distribution like LineageOS and you're almost there. Install the alternative distribution, do not install any Google services (i.e. skip the 'gapps' or Google apps), install F-droid or Aurora Droid, done - you'll end up with a device running free software (apart from the radio firmware and any driver blobs used in building the distribution). If you need software from the play store there is Aurora Store, an alternative front-end which can be used without a Google account. If some of that software needs access to the Google Services Framework (indicated in the listing as 'gsf-dependent' or something along those lines) you can install microG, an in-progress but remarkably functional free software implementation of such.
I've been doing this for about 10 years now and never had the impression I missed out on anything by not using a stock distribution with a Google account - the opposite is true. Batteries last longer since there is less background activity, devices have a far longer useable life span by virtue of the distribution being kept up to date.
Want to go one step further: use a laptop which you connect to the internet over burner phone's tethered internet connection, using a self-hosted VPN or Tor.
I always had a call recorder installed on my mobile, it saved my bacon a few times when dealing with scammy companies and various wankers.
Then a wakeup call arrives for me - my phone updates to the new version of android, on which google blocked call recording.
I installed a landline, and stopped spending money on fancy phones. I can't eacape them, but they will never see me spend more than a bare minimum.
Every time you call a firm, they record you, and will use it against you.
Secondly, its still legal to record without notifying in Uk, you just arent allowed to use it in court
Recording videos in public is also often illegal in many places, yet all smartphones come with 2-7(?) cameras. The web browser lets you download pirated content from shady sources. You can post illegal text-based content (defamation etc.) in various apps. You could probably even cause some noise complaints with the alarm app.
And that's just preinstalled software.
I've been considering buying a Linux phone. Does anyone here own one?
It, ummmm, very rough around the edges, software wise.
So far I have only used the default Manjaro distribution it came with. Im both looking forward to, and dreading, working my way through a dozen or so alternative distros to find the least worst collection of brokenness and bugs.
But I 100% knew what I was buying into when I paid for it, and am very happy I have it.
> It, ummmm, very rough around the edges, software wise.
I can imagine. How's the driver situation? Lots of proprietary blobs?
What about the device itself? Build quality? I see it has hardware switches for RF and sensors, I really like that.
> So far I have only used the default Manjaro distribution it came with.
I wonder why Manjaro and not stock Arch Linux.
Even if this is the case, what are you going to do? Buy a normal phone? That will just get you even more proprietary blobs.
You shouldn't let aversion to proprietary blobs put you off getting a PinePhone if all the other options you'd consider contain more proprietary blobs.
Google's apparently trying to get all these manufacturers to contribute their drivers to the kernel. Not sure how successful they've been.
I was hoping the situation would be better here. Proprietary Linux drivers suck. Even nvidia drivers have caused instability in my system before, switching to nouveau fixed it. I hate those things so much.
Interestingly enough, no, the drivers are all open source and mainlined. There is even a work-in-progress driver for hardware video decoding.
There are a couple proprietary firmware blobs that have to be loaded at boot time but that is just like on a laptop.
That's amazing. So unlike Android phones I can actually use a stock kernel. I think I'm gonna buy one.
> There are a couple proprietary firmware blobs that have to be loaded at boot time but that is just like on a laptop.
So the kernel itself is not tainted? I'm fine with that.
Hardware and build quality wise, I’m quite happily surprised at how good it feels. It’s certainly not at iPhone13 Pro levels of industrial design, but it feels like it compares favourably to, say Galaxy S4 vintage “flagship phones”.
And yeah, that row of hardware switches was a very powerful deciding feature for my purchase.
I'm not used to the notion that X11 even supports touch events. I wonder what the experience is like. Will I need mobile versions of Linux software or can I expect existing desktop software to work?
Honestly I'd be satisfied if I could have a fully featured terminal and browser. Looks like the pinephone even supports physical keyboards!
I suppose this market is still too new. I'm hopeful things will get better in the future as well. I'm very impressed by the fact the pinephone can run the upstream Linux kernel. Maybe that wouldn't have been possible with higher end hardware. I'm not sure.
So business as usual for Apple.
I suppose they have no fear of losing market share from losing their "privacy" moniker. Too many folks that are locked in to the brand, and who will now happily switch to saying Apple's data collection is 'better/ok'.
Not sure what more Apple could add that hasn't been thoroughly documented in their security [1] and privacy [2] overviews.
It's not like something new has been discovered by TomsGuide that people weren't aware of before.
[1] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...
[2] https://www.apple.com/legal/privacy/pdfs/apple-privacy-polic...
The only way to prevent that is that is to never make network requests. That’s probably a reasonable expectation, but it’s certainly not the same thing as sending your lat/long every few minutes.
It's a similar story with "security", as Zoom demonstrated somewhat recently.
99% of users have no way to actually check a smartphone to see "how private" it is, or "how secure" it is. And I imagine another large portion of users doesn't read tech news, and so they won't see these kinds of articles. So all Apple needs to do is put on a show about privacy, since that's what users actually see.
Especially because during first setup, it clearly asks you to opt-out of services you do not wish to participate in. Also much more transperent.
Here's more info on how people with obsessive compulsive disorder might experience obsessions and compulsions related to matching, symmetry, correctness. https://peaceofmind.com/education/types-of-ocd/perfectionism...
See also: https://www.techradar.com/news/google-is-taking-far-more-dat...
"Privacy is a fundamental human right. At Apple, it’s also one of our core values. Your devices are important to so many parts of your life. What you share from those experiences, and who you share it with, should be up to you. We design Apple products to protect your privacy and give you control over your information. It’s not always easy. But that’s the kind of innovation we believe in."
So, according to Apple, it is designed "to protect your privacy and give you control over your information".
Don't be deceived; the San Bernardino case was a very intentionally public op to convince us that they will "fight" for our right to privacy, but the not-so-public track record since has demonstrated their absolute willingness to lick the boots of virtually every government whose citizens impact their top line materially.
This isn't a slag on Apple, specifically. Facebook, Google, et al will declaim "Russian Propaganda" all day long and then immediately roll over for Russian demands to censor political opposition, for instance. They all do it.
It's all a show. You have no privacy with any of Big Tech, regardless of where you live.
Is there any public information that supports this claim?
See for yourself.
What sort of percentage of the entries on that unprinted list can be summarized as "they follow the law in the places where they do business?"
You’ve reversed cause and effect. Apple’s surprise at the backlash to their position on San Bernardino is well documented. It directly led to the softening of their stance on privacy.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
https://www.theverge.com/2020/1/21/21075033/apple-icloud-end...
The iPhone uploads very nearly the entire contents of the device every night by default to Apple, in a format Apple can easily read.
Some of it is "E2EE", but Apple holds the keys that can decrypt that data.
Data types that are protected by end-to-end encryption—such as your Keychain, Messages, Screen Time, and Health data—are not accessible via iCloud Data Recovery Service. Your device passcodes, which only you know, are required to decrypt and access them. Only you can access this information, and only on devices where you're signed in to iCloud.
No, not by default. That would be impossible, since iCloud Backup first requires an iCloud Account, and then requires enough iCloud storage space to backup your phone. You get 5GB for free, which is not enough for a lot of people.
It's possible your understanding is out of date.
I really dislike this framing and I could not disagree more. Android is open source does that mean it is also zero percent privacy? What about the Anom phone in recent news? If all three are zero percent privacy then would they not be equally private? iPhone is more private than Android as there's much less data exfiltration and the Anom phone is clearly less private than both. I love open source, but saying any closed source system is zero percent private is not helpful.
https://www.techradar.com/news/google-is-taking-far-more-dat...
As opposed to the Google-bait headline in the article above from Tech Radar?
Apple has spent millions of dollars running "Privacy. That's iPhone." campaigns on every platform out there. Given that the facts contradict Apple's privacy-bait campaigns, the title seems apt to me.
The permalink for the article is far more innocuous.
'https://www.tomsguide.com/news/android-ios-data-collection'
Using headline like that to drive traffic is as old as John C Dvorak. Who is a hack but I remember his name well enough to know his middle initial so clearly this tactic works :-)
They stopped giving every app on your phone the same ID for targeting/tracking (Android may follow, eventually). This pissed off Facebook since they can't use your account for targeting in your other apps.
Safari has also led the way (at least as far as mainstream browsers are concerned) with ITP. It even has some ML-based bounce tracking protection. I haven't done any practical tests of that, but it should be a lot better than the disconnect.me lists used by other browsers -- when I compared the domains I got redirected through during normal browsing with the disconnect.me list, only 10% were even present (none of the 100+ "3 random word" domains were listed).
So while both articles have biased titles, at least Tom's Guide provides a more accurate article.
Do you have specific concerns about the characterization of the paper?
Apps abuse permissions, and do nefarious stuff, which is why you have a news post a month about Google removing apps. 4-5 years ago I came across a startup reading all of the SMSs to give you APIs to get bank balance, number of bank accounts etc. iOS that way is "relatively" more secure (not perfect)
The next question would be: Does Apple's (or others) WiFi listen to other traffic even when offline has been selected by the user. They could do it without turning the transmitter on. Maybe on global perspective such users are still the exception, but given their data collection desires I would not be surprised if they do that routinely anyway.
Why do you have ADSL when you can just use your unlimited 4G? Even if you want it for other devices - just get a 4G router.
It was because it was re-using the same backend as the iTunes Store which was ultimately backed by an SAP system. One that required billing addresses for all purchases (free app = $0.00 purchase).
> That was unexpected given the marketing.
An extremely small amount of people will see "privacy" and think "I can use it completely anonymously without any PII being sent".
> Two in three (65%) [iphone] users are “extremely” or “very” concerned about their activities being tracked as they use certain websites and apps, while only 14% said they were not at all concerned.
same survey https://www.sellcell.com/blog/apple-privacy-survey/
Data being sent to Google—in my personal, subjective opinion—a breach of my privacy whereas—again, opinion—it isn’t when it’s sent to Apple.
Use a deGoogled OS such as Calyx, Lineage and Copperhead. Don't install GMS and you won't have these issues.
When idle. Google and Apple are basically American and Five Eyes invigilation devices. What cost money and resources in the past - satellites, airplanes, field agents, now people are paying to carry on them at all times.
That is optional.
> Maybe that has changed but using a purpose built ROM like GrapheneOS or CalyxOS is a lot better & actually easier.
If you have a Pixel phone. I'd rather pay as little money as possible to Google.
Do not store anything on your phone that you wouldn’t want your worst enemy to see. Do not even say it while your phone is nearby. Put your phone in an acoustic proof container/soundproof box if you need to have a talk with anyone. Don’t bother with airplane mode, it’s a sinkhole waiting to be discovered so assume it’s compromised until given sufficient evidence to the contrary.
With this in mind, you can sleep soundly knowing that your phone is a monitoring device, and as such privacy-related studies that demonstrate (as they always do) that your phone isn’t as private as you think will not come as a surprise and you will have no bad habits to undo/change.
2) It actually has a lot more to do with functionality than with marketing, as is obvious to even a casual observer. Apple hasn't really even marketed this as a big strength until relatively recently.
So is that the 'pivot' then?
It has been an Apple stance because Apple has no internal need for your personalised data. They have no privacy related business model.
But that is the extent to it. I don't think Apple cares one iota about personal privacy and they are happy to throw users to the fickle winds of censors in China and Russia.
No, it's highlighting a previously unlooked feature.
> They have no privacy related business model.
Not directly, but the issue is their only other legit competitor has an advertising business model directly inverse to a privacy model. Since they are selling a product, the product has to be what people want, and people are increasingly wanting more privacy.
That would be a marketing pivot... which is precisely what the original commenter suggested.
Then why is Apple recording and sending itself every single MAC address on your local network even when telemetry is turned off?
https://www.apple.com/legal/privacy/data/en/location-service...
Or potentially to cloud sync this
By knowing the MAC address and signal strength of devices around you it can triangulate the position of your device without needing an in-built GPS or celluar modem.
It's what allows Macs in particular to know their location in a pretty accurate way.
Reporting the MAC address of all other devices on the network does absolutely nothing to help Apple provice location services and is a massive invasion of privacy that gives them the ability to build a conplete social graph and track the location history of people other than the iPhone owner.
The paper states that iPhones do this even when "use of location is disabled" so your attempts to defend this practice on those grounds is completely absurd.
Back in the early days of the iPhone many analysts projected user data would be a massive business opportunity for Apple. Imagine what the social graph and activity stream of iPhone users must be worth. They walked away from that.
Not doing something is not the same as taking a ethical stance against it and not doing it. You're presuming a motive on their part.
> The created a whole mapping service costing billions to avoid selling user data to Google.
I don't think for a second that they did this for any altruistic reasons. I think it had more to do with Google not shipping concurrent features for Google Maps on iOS. As soon as Apple Maps got better data Google started shipping features like step by step directions for Google Maps on iOS.
It was a competitive response to Google.
The messaging at the time was that as the Google Maps deal was ending, it turned out that all the features were on the table during renegotiation - but Google wanted accounts and location tracking and advertising in the core maps app.
Google's claim is that they had no strategic info that Apple Maps was going to be released. The general feeling of the public is that Apple's QA department also had no info that it was going to be released.
However, I suspect Apple knew that convergence of the phone with a GPS was a critical feature and thus they had to build and buy and bite and claw their way to have a competitive offering they controlled. Google's push for user telemetry during that renegotiation cycle may have prompted Apple to accelerate, and to launch before it was really ready.
That said, Google was never going to stand still with Maps, so they had to launch with a feature deficit at some time to justify the product investment. Google and Apple have their own data sets and their own teams dedicated to tools as well as manual curation of that data.
Steve Jobs was very clear on this back in 2010.
Given that they only recently neutered this API, that seems like a pivot. If you consider that this change was only made in response to criticism that the ITP privacy protections added to Safari were forcing content creators to move from the open web to their app store to remain profitable, then the change seems more like it was forced by the PR pivot than something they were doing out of principle.
But it obviously comes with a privacy cost. So the question is, what is the risk of Apple having this information? What else might they do with it?
The answers to this question are probably very different for Google. And this is why I would trust Apple more than Google for data collection. Apple is more likely to use that information to make your hardware and software work better, and Google is more likely to (also) use that information to improve their myriad other systems - primarily ad targeting.