For many apps, requesting access to a device's precise location is entirely reasonable. A weather app needs your location to deliver an accurate forecast, and a fitness tracker relies on it to map your running route. However, recent findings reveal a hidden risk: some apps are inadvertently sharing users' location data with third parties—including advertisers and data brokers—because developers may not realize that this data-sharing feature is enabled by default.
New research from the Electronic Frontier Foundation (EFF) warns app developers that the third-party code they integrate into their apps—known as software development kits (SDKs)—may automatically inherit the app's permissions and collect users' precise location data. Unless developers actively disable this collection, the SDKs will silently harvest and share sensitive location information.
The EFF emphasizes that many developers are unaware they are sharing users' location data by default and urges app makers to disable unnecessary data collection whenever possible. While advertising SDKs are marketed as a way to monetize apps, the trade-off is significant: users' location histories are fed to data brokers, who monetize that information and may sell it to militaries, governments, and intelligence agencies, like the FBI. Moreover, this data becomes a security and privacy risk if it gets hacked or stolen, which some data brokers have already experienced.
Among the Android apps the EFF identified as quietly sharing location data were two with a combined 60 million downloads to date. The EFF's tests analyzed the apps' network traffic to determine which services received users' location data.
Bill Budington, a senior staff technologist at the EFF, told TechCrunch that the SDKs they examined represent only a small fraction of the broader advertising ecosystem, yet they claim to reach billions of users across tens of thousands of apps—highlighting the scale of this type of location data collection.
The EFF's report also notes that there are “no SDK-specific location permissions,” meaning once a user grants location access to an app, that permission extends to the embedded advertising SDKs, which are commercially incentivized to encourage more data collection.
“App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs,” wrote the EFF. “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person's location.”
via TechCrunch
