privacy concerns

AppWizard
August 9, 2026
Third-party advertising tools embedded in Android applications are automatically collecting location data, often without the app developers' awareness. Software development kits (SDKs) used for advertising come with location data collection enabled by default, unless developers actively disable this feature. Historical location data has been sold to military and intelligence agencies, including the FBI, and used in immigration enforcement actions in the US. The Electronic Frontier Foundation (EFF) reported that app-level location permissions do not provide meaningful consent for location collection by third-party advertising SDKs. The EFF identified four advertising SDKs—InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads—that collect and share location data by default. Two analyzed apps had been downloaded 60 million times without providing a privacy notice or seeking user consent for third-party location sharing. Users can manage location permissions through their device settings, but the EFF emphasizes that developers should ensure user data is not shared by default.
AppWizard
August 9, 2026
Toronto has seen an increase in gunfire incidents aimed at the U.S. consulate, leading to the arrests of a 19-year-old and a 15-year-old. These incidents are linked to alleged gun-for-hire plots that also target Jewish schools, synagogues, and waste management facilities in the Greater Toronto Area. Investigators are facing difficulties in identifying the masterminds behind these operations, partly due to the use of encrypted messaging apps to recruit young individuals. The federal government's Bill C-22 aims to provide law enforcement with tools to address these challenges, but it has faced criticism for potential overreach and privacy concerns. Police Chief Myron Demkiw emphasized the need for effective tools to prevent violence facilitated through encrypted communication. Technology analyst Carmi Levy raised concerns about balancing law enforcement needs with privacy rights. Additionally, there is a societal responsibility to protect children from online recruitment by criminal networks, with calls for proactive conversations between parents and children and educational initiatives in schools.
Winsage
August 7, 2026
Turbo VPN's Windows client has faced significant privacy issues, including active IP leaks and misconfigured protocols. Owned by Innovative Connecting Pte. Limited in Singapore, it has over 500 million downloads on Android. Initial testing revealed that version 3.6.0.0 did not resolve IPv6 address leaks, despite IPv4 addresses being masked. A subsequent update, version 3.7.0.0, successfully blocked unencrypted IPv6 traffic while maintaining IPv4 masking. Testing showed that the proprietary protocol Lepus functions differently from standard VPNs, routing non-browser data through a local proxy without encryption. Turbo VPN's response indicated that the observed issues were limited to specific network configurations, and they have since implemented improvements in the latest version. However, detailed information about their proprietary protocols remains unavailable.
AppWizard
August 6, 2026
A report from the Electronic Frontier Foundation (EFF) highlights concerns about third-party software development kits (SDKs) in mobile applications collecting and sharing user location data with advertising companies, often without user consent. Many developers use these advertising SDKs for monetization, but their default settings allow for location data collection. This data is sent to advertising companies and location data brokers, which can misuse it in sensitive contexts. Users may unknowingly expose their location data when granting permissions to apps, as third-party SDKs can access this information without clear user awareness. The EFF identified several advertising SDKs, including InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads, that collect and share location data by default. Developers are encouraged to review SDK settings to protect user privacy, and the EFF calls for regulatory scrutiny of data harvesting practices.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
August 5, 2026
Developers often rely on third-party software development kits (SDKs) for mobile app monetization, which can compromise user privacy due to invasive data-collection features. The Electronic Frontier Foundation (EFF) has raised concerns about these SDKs' default settings that collect sensitive location data without explicit user consent. Location data is valuable for advertisers, allowing targeted marketing, but permissions granted to apps often extend to SDKs, enabling data collection without informed consent. The EFF emphasizes that app-level location permissions do not signify meaningful consent for third-party SDKs. The location data collected has been used by intelligence agencies and law enforcement, raising ethical privacy concerns. The EFF recommends that developers prioritize user privacy, regulators hold app developers accountable for unlawful data sharing, and legislators consider enacting federal laws similar to the GDPR to protect user privacy and potentially ban behavioral advertising.
Search