privacy issues

Winsage
August 7, 2026
Turbo VPN's Windows client has faced significant privacy issues, including active IP leaks and misconfigured protocols. Owned by Innovative Connecting Pte. Limited in Singapore, it has over 500 million downloads on Android. Initial testing revealed that version 3.6.0.0 did not resolve IPv6 address leaks, despite IPv4 addresses being masked. A subsequent update, version 3.7.0.0, successfully blocked unencrypted IPv6 traffic while maintaining IPv4 masking. Testing showed that the proprietary protocol Lepus functions differently from standard VPNs, routing non-browser data through a local proxy without encryption. Turbo VPN's response indicated that the observed issues were limited to specific network configurations, and they have since implemented improvements in the latest version. However, detailed information about their proprietary protocols remains unavailable.
AppWizard
August 5, 2026
Advertising companies provide software development kits (SDKs) for mobile app monetization, which often automatically transmit users' location data to ad systems and location data brokers, raising privacy concerns. Many developers and users may be unaware of this data sharing. When developers allow SDKs to collect location data, it poses risks beyond targeted ads, including potential misuse by agencies like ICE and global surveillance. Location data brokers harvest precise movements of individuals, often without their consent, through mobile applications. Some apps directly collaborate with data brokers, while others leak data through advertising SDKs during real-time bidding (RTB) auctions. An incident in 2025 revealed that many apps unknowingly contributed to a location data broker's database. Developers must understand their SDKs' location-sharing practices to mitigate risks. Advertising SDKs can collect location data automatically once users grant permission, without specific permissions for the SDKs themselves. Precise location data can be collected when apps have location permissions, leading to potential privacy violations. Several SDKs have been identified as collecting location data by default, increasing the risk of unintentional data leaks. The Electronic Frontier Foundation (EFF) found that four advertising SDKs collect users' location data by default when location permissions are granted. InMobi encourages location sharing for higher revenue, while BidMachine updated its documentation after EFF's inquiry, confirming precise location data collection. Verve's SDK also collects location data by default but presents a cautious narrative in its Play Store guidance. Huawei's SDK recommends obtaining location permissions to enhance revenue, with default location sharing occurring if permissions are granted. Location data can be shared without users' knowledge or meaningful consent, complicating informed consent issues. The focus on four SDKs does not imply that others adequately protect location data, as many have faced criticism for similar practices. Studies indicate that SDKs often encourage increased data collection through design and documentation, leading to minimal control for developers over data transmission. The EFF's analysis highlights that advertising SDKs incentivize location data sharing through default settings and unclear documentation. Developers should assess third-party SDKs and disable unnecessary data collection. Regulators must hold developers accountable for unlawful data sharing, while legislators should enact laws to protect location privacy and address online behavioral advertising, which drives data tracking.
AppWizard
August 4, 2026
Mobile apps often require precise location data for functionality, but there are concerns about the unintentional sharing of this sensitive information with third parties, such as advertisers and data brokers. The Electronic Frontier Foundation (EFF) found that third-party code in apps may collect location data without users' explicit consent due to default settings in software development kits (SDKs). Unless developers disable this feature, SDKs inherit app permissions, leading to the collection of users' location data. This raises privacy issues, as users' location histories can be sold to data brokers and potentially accessed by military and intelligence agencies. The EFF identified that certain Android apps, downloaded over 60 million times, were sharing location data without user awareness. Currently, there are no SDK-specific location permissions, meaning that consent to share location data with an app also extends to advertisers. The EFF calls for a change in industry standards to prevent default data sharing by advertising SDKs.
Winsage
June 5, 2026
In May 2024, Microsoft launched Copilot+ PCs featuring local AI acceleration and Qualcomm's Snapdragon X Elite chips. However, during the introduction of the Surface Laptop Ultra, powered by NVIDIA’s RTX Spark platform, Microsoft did not mention the Copilot+ branding. The Surface Laptop Ultra is described as the most powerful AI-centric Windows laptop, yet it lacks the Copilot+ label, raising questions about the branding strategy. Initially, Copilot+ PCs were marketed as the fastest and most intelligent Windows PCs, requiring specific hardware specifications. The Recall feature, intended as a "photographic memory," faced privacy issues, leading to its retraction and redesign. In 2025, Microsoft integrated Copilot into various Windows applications, resulting in user backlash and a decline in the brand's perception. The Surface Laptop Ultra is confirmed as a Copilot+ PC internally, but Microsoft chose not to use the branding publicly, likely due to NVIDIA's branding interests. Additionally, inconsistencies in hardware requirements for Copilot+ PCs have created confusion among consumers. Microsoft may need to consider a rebranding of Windows as it focuses on local AI development and improving performance.
AppWizard
May 28, 2026
Proton Mail now allows users to import Gmail emails directly into the app, enabling them to send emails from their Gmail address within Proton Mail. This feature removes trackers and ads from emails, enhancing user privacy. Users can link their Gmail accounts through the Easy Switch section in Proton Mail settings, and Proton assures that this connection does not give Google access to their Proton Mail inbox. Emails exchanged between linked Gmail accounts using Proton Mail can achieve end-to-end encryption, preventing Google from using email interactions for advertising profiling. However, Google can still access emails that remain in Gmail inboxes. The rollout of this feature is currently underway for Proton Mail users.
AppWizard
May 27, 2026
Motorola phones experienced an issue where launching the Amazon shopping app caused a browser window to briefly open with a dubious URL before redirecting to an Amazon affiliate link. This behavior was linked to the preloaded Smart Feed app, which was sending requests to devicenative.com, associated with Motorola’s advertising. Motorola confirmed that this behavior was unintended and has since corrected the routing configuration, ensuring that apps now launch directly as intended. The company emphasized its commitment to user experience, privacy, and platform integrity.
Search