Android application developers may inadvertently disclose users' location data to advertising networks.

 For many known applications, granting permission to access your device’s precise location makes sense for everyone. Your favorite weather app needs to know where you are to get the day’s forecast, or your go-to fitness app for tracking your running route it seems normal, but there is a hidden part to check. 




Some apps are also inadvertently sharing their users’ location data with third parties in the name of increasing their income, including advertisers and data brokers, because the app developer may not know that this data-sharing setting is enabled by default in most applications.

New findings by the known Electronic Frontier Foundation has for popurse warn app developers that some of the third-party code they place in their apps may also collect their users’ location data, which my not accept when they grant permission to the app and need to take more care while doing it. 

Unless the developer actively switches off the collection, the code snippet (known as software development kits, or SDKs) will inherit the app’s permissions and collect the user’s precise location data.

The EFF says many developers might not realize that they are sharing their users’ location data with third parties by default and urged app makers to disable unnecessary data collection whenever possible. 

Although advertising SDKs provide developers with an opportunity to generate revenue from their apps, they often come with a significant privacy cost. Users' location histories can be collected and passed to data brokers, who profit by selling this information to a variety of clients, including government agencies, military organizations, and law enforcement bodies. Beyond commercial use, the accumulation of such sensitive data also creates security and privacy concerns, as data breaches involving brokers have shown that this information can be exposed or stolen by unauthorized parties.Among the Android apps that the EFF identified that were quietly sharing users’ location data were two that had been downloaded a combined 60 million times to date.

The EFF ran its tests by analyzing the apps’ network traffic and seeing which services are receiving the users’ location data.

According to Bill Budington, a senior staff technologist at the EFF, the advertising SDKs analyzed represent only a small portion of the overall mobile advertising industry. Even so, these SDKs claim to operate across tens of thousands of applications and reach billions of users, highlighting the massive scale at which location data can be collected.

The EFF also noted that Android does not provide separate location permissions for individual SDKs. As a result, when users grant an app permission to access their location, that permission automatically extends to any embedded advertising SDKs, allowing them to collect the same data. Since companies that provide these SDKs often generate revenue from user data, they have a strong business incentive to encourage developers to gather as much information as possible.

The organization emphasized that granting location access to an app should not be interpreted as informed consent for third-party advertising SDKs to collect and share that information. The EFF argued that advertising SDKs should adopt privacy-friendly defaults instead of automatically transmitting highly sensitive data such as a user's location.

Comments

Popular posts from this blog

CodeCrafters Pauses New Challenges: A Difficult Moment for One of the Best Developer Learning Platforms

YouTube's New AI Labels, Spotify's AI Podcasts, and Apple's Next Audio Mystery Signal a Changing Tech Landscape

How a Former Meta Engineer Tackles an AI Coding Interview in Real Time