All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Android apps may share user location data with advertisers by default

Created at 4 Aug · 8:41 PM1 source↑ Market-relevant
IN SHORT

The Electronic Frontier Foundation (EFF) has warned Android app developers that third-party code, known as software development kits (SDKs), may be collecting and sharing users' precise location data with advertisers and data brokers by default, even when users grant location permissions only to the app itself.

Key Numbers

60 millioncombined downloads for identified apps

Who's Involved

Electronic Frontier Foundation (EFF)
organization warning app developers about location data sharing
Bill Budington
senior staff technologist at EFF
Android apps may share user location data with advertisers by default

↳ Why This Matters

This issue highlights a significant privacy loophole where user location data, granted to an app for specific functions, can be surreptitiously shared with third parties for advertising and other purposes without explicit user consent, posing risks to privacy and security.

Key facts

  • Android apps may be sharing users' precise location data with advertisers and data brokers.
  • This sharing happens by default through third-party software development kits (SDKs) embedded in apps.
  • Developers may not be aware that these SDKs collect and share location data when app permissions are granted.
  • The Electronic Frontier Foundation (EFF) identified this issue and is urging developers to disable unnecessary data collection.
  • Location data shared with third parties can be monetized and sold to various entities, including governments and intelligence agencies.
  • EFF highlighted that app-level location permissions do not constitute meaningful consent for third-party data sharing.

The Electronic Frontier Foundation (EFF) has raised concerns that Android app developers may be unknowingly sharing users' precise location data with advertisers and data brokers. This occurs because third-party software development kits (SDKs) integrated into apps can inherit location permissions by default, a setting many developers might not realize is active.

According to the EFF, once a user grants an app permission to access their location, this data can be automatically collected and shared by SDKs. The organization is urging app makers to actively disable unnecessary data collection by these SDKs. While advertising SDKs are often used to monetize apps, the byproduct is the feeding of user location histories to data brokers, who then monetize and sell this information to entities such as militaries and intelligence agencies. This practice also poses a security and privacy risk if the data is hacked or stolen.

The EFF's findings are based on an analysis of network traffic from various Android apps. Among the apps identified were two that have been downloaded a combined 60 million times. Bill Budington, a senior staff technologist at EFF, noted that while the examined SDKs represent a small portion of the advertising ecosystem, their reach is extensive, potentially impacting billions of users across tens of thousands of apps. The EFF emphasized that app-level location permissions alone do not provide meaningful consent for data collection and sharing by third-party advertising SDKs, advocating that such SDKs should not make personal data sharing the default, especially for sensitive information like location.

Frequently asked questions

The EFF is concerned that Android apps may be sharing users' location data with advertisers and data brokers through third-party SDKs, often without the developer's full awareness or explicit user consent.

When a user grants an app permission to access their location, the SDKs embedded within that app can automatically inherit these permissions and share the data with third parties.

The Electronic Frontier Foundation (EFF) is warning Android app developers about this practice and urging them to take action.

The shared location data can be monetized and sold to various entities, including militaries and intelligence agencies, and also presents a security risk if hacked or stolen.

What Happens Next

01App developers are urged to review and disable unnecessary data collection by SDKs.
02Users are advised to scrutinize app permissions and consider disabling location access for non-essential apps.

How It Developed

The Electronic Frontier Foundation (EFF) identified that some Android apps inadvertently share user location data with third parties.
This occurs because SDKs within apps can inherit location permissions by default, even if developers are unaware.
EFF urges app makers to disable unnecessary data collection by SDKs.
Location data shared with advertisers is monetized and can be sold to governments and militaries.
EFF's tests analyzed app network traffic to identify data recipients.
A senior technologist at EFF noted the broad reach of these SDKs, potentially affecting billions of users.
EFF stated that app-level location permissions do not provide meaningful consent for third-party SDK data sharing.

Sources

T1
Android app developers may be unwittingly sharing their users’ location data with advertisersTechCrunch

Related Stories

Bitcoin Red Team Fights AI-Powered Exploits Amidst Model Restrictions
22 Aug · 3:35 PM
Frontier AI labs lack public containment plans for rogue models, study finds
22 Aug · 4:11 PM
One-Third of Post-ChatGPT Web Content Shows AI Authorship Signs
22 Aug · 1:35 PM
Mysterious Free AI Model 'Ox Alpha' Impresses Developers Amidst Origin Speculation
22 Aug · 8:56 PM
Big Tech's Influence on American Schools Faces Scrutiny
23 Aug · 9:11 AM