Android apps could be leaking your precise location

If you’ve ever granted a weather or fitness app access to your location, you might be surprised to learn that your precise whereabouts could be quietly relayed to advertisers and data brokers. A recent report from the Electronic Frontier Foundation (EFF) reveals that third-party advertising tools embedded in Android applications are automatically collecting location data, often without the app developers’ awareness.

Understanding SDKs and Their Implications

These tools, known as software development kits (SDKs), are pre-packaged code snippets that developers integrate into their apps to facilitate advertising and generate revenue. The inherent challenge lies in the fact that many of these SDKs come with location data collection enabled by default. Unless developers actively disable this feature, users’ location information is shared automatically.

For instance, when you allow a local restaurant app to access your location for personalized dining suggestions, that same data may be harvested by background advertising tools and disseminated to other entities. This raises significant concerns about privacy and data security.

Location histories gathered by the advertising industry have previously been sold to militaries and intelligence agencies like the FBI, and used in immigration enforcement operations in the US | GOOGLE

The implications of this data collection are troubling. Historical location data has previously been sold to military and intelligence agencies, including the FBI, and has been utilized in immigration enforcement actions within the United States. Additionally, if a data broker experiences a security breach, it could expose sensitive information about individuals’ daily routines, increasing the risks of identity theft, scams, and other security threats.

The EFF’s report emphasizes that “app-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” It further asserts that “advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.”

Developer Responsibilities and User Awareness

In the development process, many app creators opt for SDKs to streamline their work, avoiding the need to write advertising code from scratch. While this approach saves time and resources, it also means that once a user grants an app permission to access their location, that permission extends to any embedded SDKs. Unfortunately, there are no distinct location permissions for these SDKs.

The challenge lies in the obscurity of data-sharing settings. Developers must delve into the SDK’s configuration to manually disable unnecessary data collection. If they overlook these settings before launching their app, sensitive location data may be inadvertently harvested and shared.

The EFF warned that developers should also review all third-party SDKs and ensure user data isn’t being shared by default |

The EFF’s investigation identified four advertising SDKs—InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads—that collect and share location data by default. There may be additional SDKs that have yet to be uncovered. To illustrate the scale of this issue, two of the apps analyzed by the EFF had been downloaded a staggering 60 million times, yet neither provided a privacy notice nor sought user consent regarding third-party location sharing.

If you want to protect your location on an Android device, there are a few steps you can take |

For users concerned about their location privacy on Android devices, there are several steps to consider. Begin by navigating to your phone’s Settings, selecting Location, and then App location permissions. From there, you can review and revoke access for individual apps. Alternatively, you can disable Use Location entirely, though this may hinder the functionality of apps that rely on location data, such as maps and weather services.

The EFF advocates for developers to thoroughly assess all third-party SDKs to ensure that user data is not shared by default. As EFF Staff Technologist Lena Cohen stated, “Users can take extra steps to defend their location privacy, but they shouldn’t have to. Developers, regulators, and legislators must act to stop apps from leaking users’ location data to advertising companies and data brokers.” Senior staff technologist Bill Budington added that while the SDKs examined represent only a small segment of the broader advertising ecosystem, they claim to reach billions of users across numerous applications.

AppWizard
Android apps could be leaking your precise location