ON
← Back to feed
Default data leaks: How advertising SDKs lead developers to track
Germany🏛️ PoliticsProgressiveyesterday

Default data leaks: How advertising SDKs lead developers to track

Ein Bericht der US-Bürgerrechtsorganisation Electronic Frontier Foundation (EFF) zeigt, wie Werbe-Softwareentwicklungskits (SDKs) unbemerkt Standortdaten von Nutzern an Datenhändler weiterleiten. Diese Daten werden dann in Marketing-Auktionen genutzt, wobei Datenbroker Bewegungsprofile erstellen können. Die EFF untersucht, wie viele SDKs standardmäßig Standortinformationen erfassen und weitergeben, oft ohne klare Benachrichtigung der Entwickler. Beispiele wie InMobi, BidMachine, HyBid und Petal Ads zeigen, dass einige SDKs voreingestellte Funktionen haben, die präzise Standortdaten oder kontinuierliche Erfassung ermöglichen. Selbst ungenaue Standortangaben können bei ständiger Nutzung Rückschlüsse auf Bewegungen erlauben. Die EFF kritisiert, dass viele Entwickler Standard-Einstellungen nicht überprüfen und Warnungen über die Datennutzung oft versteckt sind.

Smartphone users often assume that granting location access to an app serves only the core function of that application. When allowing a navigation service, weather app, or QR code scanner access to GPS data, users typically expect their position to be used solely for the intended purpose. However, according to a recent analysis by the U.S.-based digital rights organization Electronic Frontier Foundation (EFF), many software development kits (SDKs) automatically forward location data to ad-tech systems. These systems then pass movement profiles into the hands of data brokers who create comprehensive surveillance profiles. The study by EFF researchers Lena Cohen and Bill Budington highlights the central role of real-time bidding (RTB) in this data flow. Once an app receives location permissions at the operating system level, third-party SDKs can access these data as well. During RTB auctions, advertising networks send data packets to thousands of potential advertisers. According to the investigation, data brokers frequently exploit these auctions to intercept movement data included in bid requests. The extent of this issue was demonstrated through the data breach involving broker Gravy Analytics, which revealed that many affected developers were unaware their apps had been used as data providers. Standard settings act as data traps. The problem intensifies due to how advertising SDKs are designed. Developers tend to adopt default settings without scrutiny. The EFF identified four widely used development kits that automatically collect and forward location data once the app permission is granted. For instance, InMobi has forwarding enabled by default and explicitly recommends granting precise GPS and Wi-Fi information to increase ad revenue. Similarly, the advertising service BidMachine initially claimed in its developer documentation that it did not collect precise location data. However, after inquiries from the EFF, the company corrected its documentation. Technical analyses of apps such as “QR Scanner” and “GPS Speedometer” showed otherwise. Likewise, the SDK HyBid from Verve and Petal Ads from Chinese manufacturer Huawei utilize pre-set location permissions and emphasize financial benefits for developers. While Verve stated they process approximate location data upon request, even imprecise location information allows conclusions about movement patterns with continuous collection. Huawei does mention monetization but hides the option to disable data collection deep within specific compliance documents. The risks extend beyond targeted advertising. According to the EFF, the issue goes far beyond these examples. If location data circulates through the advertising market, it creates risks beyond targeted ads. In the past, such datasets have already been used for law enforcement investigations, global espionage tools, tracking union organizers and military personnel, and exposing individuals. Granting location access at the operating system level does not constitute effective consent for sharing with third parties. Therefore, the EFF calls for a shift in thinking at all levels: developers must critically examine advertising SDKs and deactivate data collection. Regulatory authorities should hold not only programmers accountable but also creators of SDKs that undermine data protection. Activists advocate for stricter laws and a ban on behavior-based online advertising to eliminate the financial incentive for trading movement profiles.

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentProgressiveFactual 78Objective 92yesterday
Default data leaks: How advertising SDKs lead developers to track

Ein Bericht der US-Bürgerrechtsorganisation Electronic Frontier Foundation (EFF) zeigt, wie Werbe-Softwareentwicklungskits (SDKs) unbemerkt Standortdaten von Nutzern an Datenhändler weiterleiten. Diese Daten werden dann in Marketing-Auktionen genutzt, wobei Datenbroker Bewegungsprofile erstellen können. Die EFF untersucht, wie viele SDKs standardmäßig Standortinformationen erfassen und weitergeben, oft ohne klare Benachrichtigung der Entwickler. Beispiele wie InMobi, BidMachine, HyBid und Petal Ads zeigen, dass einige SDKs voreingestellte Funktionen haben, die präzise Standortdaten oder kontinuierliche Erfassung ermöglichen. Selbst ungenaue Standortangaben können bei ständiger Nutzung Rückschlüsse auf Bewegungen erlauben. Die EFF kritisiert, dass viele Entwickler Standard-Einstellungen nicht überprüfen und Warnungen über die Datennutzung oft versteckt sind.

Bias read (Progressive): Der Artikel betont die Verantwortung von Entwicklern und Herstellern, die Nutzerdaten ohne Einwilligung weitergeben. Es wird ein System beschrieben, das durch kommerzielle Interessen getrieben wird, was als rechtsliberaler Trend interpretiert werden könnte. Allerdings wird die Kritik an der Privatsp

Why factuality (78): The article accurately summarizes the primary source document's findings about advertising SDKs leaking location data through RTB auctions and default settings. It mentions the Gravy Analytics data breach and the role of data brokers, aligning closely with the source. However, it omits specific deta

Why objectivity (92): The article maintains a neutral tone throughout, presenting facts without overt bias or emotional language. It frames the issue objectively, focusing on the technical mechanisms and consequences rather than taking sides. The only minor deviation is the omission of some specifics, but this doesn't af

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories