Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

Do You Realize How Much You Share Your Location?-gctid260048

Started by Ajamu, Feb 13, 2018, 03:28 AM

Previous topic - Next topic
Do You Realize How Much You Share Your Location?
by Cameron Summerson on January 30th, 2018



This app is tracking your every move!—a hyperbolic headline I'm sure we've all seen before. While the sentiment here is a over-the-top, it does raise an important question: do you know how private your location actually is?

Every day it's something new. Today it's headlines about activity-tracking app Strava  (iOSAndroid) and how it "gave away" locations of secret army bases.

Despite my personal feelings on that particular story, it still raises an important question: do you know how private your location data is? Do you even know which apps are tracking your location and sharing it publicly?
Everything Is Public, Until it Isn't
The absolute first and foremost rule where digital privacy is concerned: assume that everything you do is public until you set it otherwise.

Sure, there are apps and networks out there that are private by default, but those are few and far between. So you should always operate as if every app is watching—because they probably are. If you don't like this, it's up to you to either change these settings or stop using the network altogether.

While this is true of everything from the statuses you post on Facebook to the images on Instagram—things you may be okay with showing publicly—location data should require special attention from everyone. For example, if you use a fitness tracking app or device, you can almost guarantee that it's tracking your location, because that's a staple function of such apps. In the case of Strava, which is primarily used by cyclists and runners, location tracking is core to the very heart of its utility as a service. But that doesn't mean you need to share it publicly. And other apps may not be so obvious as to what they're tracking (or why).
You May Not Care Now, But You Might One Day
If you consider the implications of sharing your location across various networks, you may be cool with it. After all, why do I care if my Facebook friends all know where I'm having dinner? I don't, because I know those people.

But you also have to consider future implications, because once location data is attached to a status update or tweet, it's always there (unless you delete that status later on). And if you change your feelings on location privacy, that's a lot of data left out there that you'll have to hunt down and delete.

There are also potentially darker implications here. Let's say you share you location on a fitness tracking app. If you use this app over a period of weeks or months, it wouldn't be difficult for someone to learn your habits—not just where you live, but when you're likely to not be home, or the path you take jogging at night. Someone with ill intentions could easily use this data for very bad things.

For example, maybe you have an ex-turned-stalker—not a likely scenario, but common enough it does warrant at least some consideration. That person knowing your exact location, habits, or where you can be found could be detrimental to your well being, even if it doesn't seem like a likely scenario right now.

Now, am I suggesting that you should constantly look over your shoulder or live in fear of what could happen? Most definitely not. Just that you have to sometimes consider things past the obvious or below the surface. You should start by at least knowing what has access to your location.

And in the end, if you're indifferent about location sharing or don't have a specific reason for keeping it enabled, maybe you should go ahead and turn it off.
What Has Access to Your Location?
Regardless of what platform you use (Android or iPhone), every app that you install and use has to request access to certain features—like Location. But on a long enough timeline, you may stop using certain apps, but they could still be tracking your location. Fortunately, you can easily find a list of all the apps that have access to your location and turn them off as needed.

How to Find Apps with Location Permission on the iPhone

Go ahead and jump into your device's Settings menu, then find the Privacy menu.

 

The top option here is Location Services, which will show a list of every app that has access to your location, and when it can use said feature. For example, if it says "Always", it can track your location at all times; if it says "While Using", it can only grab your location while the app is open.

 

You don't necessarily need to disable location access for all these apps right here—after all, like I said, some of those apps need location to be useful. But make a note of each app that has access, and then skip to the next section, where we'll talk about how to make sure that location isn't being made public.

How to Find Apps with Location Services on Android Oreo

Android Oreo makes it pretty easy to find apps with location access. First, pull down the notification shade and tap the gear icon to open the Settings menu.



From there, find the Security & Location menu, then tap into the Location menu under the Privacy section.

 

Choose App-Level Permissions to see all the apps with location access.

 

You don't need to disable location access for these apps just yet—after all, they may need that feature. But write down the apps that have location permission, since you'll need them in the next section.

How to Find Apps with Location Services on Android Nougat and Below

Older versions of Android have Location Services tucked away in a slightly different menu. Go ahead and pull down the notification shade and tap the gear icon to head into Settings, then jump into the Apps menu.

 

Tap the gear icon in the top corner. Note: On Galaxy devices, you'll tap the three dots in the upper right corner.

 

From there, choose App Permissions, then find the Location option.

 

Disabling these location services could dramatically impact a service's usefulness. For example, fitness trackers or weather applications are going to be mostly useless without proper location tracking. So don't necessarily disable location access here—read on to see how to make sure this information isn't public.
Make Sure Your Location Isn't Being Shared
Checking location services on your mobile device is only half the equation here, of course. You also need to consider your "needs" from particular networks—as I said, disabling location services on mobile can dramatically decrease the usefulness of particular services.

For example, Facebook, Twitter, Instagram, and a slew of other services probably have access to your location on an account basis, which goes beyond individual app permissions. You'll want to check your account settings on all these services and turn them off if it isn't necessary.

In Facebook, head into Settings > Account Settings > Location to find out if it's keeping track of where you go.

 

For Twitter, you'll find this info in Settings and Privacy > Location and Proxy (Android Only).

 

Some apps—like Instagram—rely on your device's permission system to track your location, so disallowing in on the device level will block this info from being shared.



Go through the account settings of every app you found in the last step and try to find a similar toggle—either for making that information private, or disallowing location access altogether.

You may find that some services have really granular settings. Strava, for example, offers an Enhanced Privacy setting that gives you even more settings to tweak. That way, I can pick and choose who is allowed to see my activities; if I don't know someone (or at least know who they are), then they don't get to see what I'm doing or where I'm riding. it also offers a feature called "Hidden Locations," which allows users to hide specific addresses within a certain radius, so people can't see where I live.



 

But that's the thing: both of these features are disabled by default. It's my responsibility as a user of the service to enable these features—I have to take the privacy implications and my own needs personally. You'll need to do the same with all the apps and services you use.

This thought process should extend past apps, too. Fitness trackers and smartwatches are also key tools in keeping up with your activities, and while they're generally governed by some sort of companion app on your smartphone, they also have to be considered. For example, if you passively use a step tracker on a smartwatch, or a fitness tracker, but never open the companion app on your smartphone, it could be "silently" uploading your tracked data somewhere. Is it public? Do you know? Now might be time to take a closer look.

So, all this is to say one thing: you can't expect privacy, because we live in an "opt-in by default" world. As users of specific devices and services, it's our individual responsibility to do our due diligence here and protect what is rightfully ours. As represented by the recent military base debacle, sometimes the implications are more serious than you may realize.

Hundreds of Smartphone Apps Are Spying on Your TV Watching. Here's How to Disable Them
by Michael Crider on January 4th, 2018



If you're afraid that your smartphone is spying on you...well, you're right. But that's kind of a non-optional part of modern living: amassing huge amounts of consumer data is how companies like Google operate. But recently some third-party apps have been found taking a few more liberties than they should, like a HAL 9000 in your pocket.

The New York Times reported in late December that hundreds of Android apps have been found snooping on their users with the built-in microphones on smartphones. Specifically, these apps are listening for TV show broadcasts, commercials, and even movies you watch in the theater, amassing information on what kind of things you like to watch. The third-party software, from a company called Alphonso, has been embedded in many Android apps available for free on the Play Store. Some of the apps are also available on the iPhone, and their App Store entries claim to use the same technology and snooping habits.
Why Listen to TV Broadcasts?
Alphonso's software uses the same technology that Shazam and similar servicesemploy to automatically detect the song you're listening to. It samples small bits of audio, creating a digital "fingerprint" of it, and comparing it against a a database on their server to identify the show or movie. In fact, Alphonso's CEO says they have a deal with Shazam, and use their specific technology to do this. But this embedded software can even be listening even when your phone's screen is turned off and it's ostensibly idle.
Amazon's system-generated links at the bottom of each page are a fairly benign form of targeted, profile-based advertising.
Why? It's all about the advertising. Marketing firms know that people who watch certain TV shows are more likely to buy certain products. For example, if you're binge-watching the latest Marvel Comics show on Netflix, it's reasonable to assume you'd click on an ad for an Avengers Blu-ray sale the next time you're browsing Amazon. If you watch Hawaii Five-0 on CBS, you might be a little more interested in a cruise line package vacation than, say, airfare to New York City. If you watch NBC Nightly News, you might be more likely to want a subscription to the Wall Street Journal.

These minor connections and thounited snakesnds more like them build up a profile of you as a consumer, connected to your digital identities on Google, Amazon, Apple, Windows, Facebook, Twitter, and more or less every major mobile and web hub out there. It's not exactly insidious—you're not being forced to do anything you don't want to—but every piece of data and every connection made in these profiles serves a single purpose. That purpose is to make you more likely to buy stuff, and that makes the data collected incredibly valuable.
Based on my user data and tracking cookies, advertisers target me on Facebook with relevant ads I'm more likely to click on.
Hence the somewhat sneaky methods companies like Alphonso are reaching for to get even more data about your life and your desires. The more data they collect, the more complete the picture they can form of you as a consumer, and the more advertisers will pay them. It's not illegal, and some of them are toeing some very thin lines to keep it that way. Alphonso claims it never records the voice data of human speech from people, only the audio coming from TVs and other electronic devices. But there's no denying that the idea of your phone listening to what's going on around you is creepy, especially if you haven't specifically asked it to do so.

Ironically, Facebook has been repeatedly accused of this same snooping behavior, despite zero evidence that it was actually going on. Security researchers still haven't found any evidence that the Facebook app activates your phone's microphones without telling you...but it's entirely possible that Facebook's advertising partners are using data collected by other apps that use Alphonso and other data collection companies to serve you relevant ads.
How Do They Listen In?
You let them. No, seriously: these apps have to ask your permission to listen to you. But they're not entirely honest about when they're listening, what they're listening to, why they're listening at all, and what they do with the data they collect.

Let's have a practical demonstration. I've downloaded one of the applications identified in the New York Times article on my Android phone. It's a free-to-play darts game known as Darts Ultimate. After running the app for the first time, it asks for permission to access your location and microphone. This one actually explicitly tells you it's listening to your TV as well.



Think about it: what possible need could a simple game about darts need to have access to your phone's location? Why would it need to listen to the microphone for anything? It doesn't: this is information it passes along to marketing and advertising firms. And now, through the Android permissions system and a single pop-up—those things that the vast majority of users will simply tap "OK" on without thinking—it has your permission to do so.

What the app isn't telling you is that it's using software embedded in the game and APIs in Android's operating system to listen in to television and streaming broadcasts even when the phone isn't on. In addition to being unsettling, the app's developer is making money off of you and your phone without you even playing the game, not to mention using your phone's processing power and battery on things you'd probably prefer it wasn't.
How Can You Stop Them?
The easiest way to stop these apps from snooping in on your TV binging is simply to uninstall them, or never install them in the first place. Keeping a ton of unnecessary apps on your phone, especially from the kind of unscrupulous developers who'd take a kickback for putting extra advertising software in their ad, is a good way to kill its performance.



RELATED ARTICLE


How to Manage App Permissions on Android
?

The next best thing is to keep an eye on those permissions as you use apps. In Android 6.0 and above, an app has to manually request permission from the user to access hardware like the microphone, and ask it at the first point of use. iOS now works the same way. Simply tap "Don't Allow" in the permission pop-up for anything that you don't think the app really needs to use. This is a good general policy, in fact, and games and other simple apps shouldn't be asking for these permissions in the first place. Here are few of the more risky ones to look out for:
  • Microphone
  • Phone
  • SMS
  • Location
  • Contacts
  • Camera
  • Cellular Data
Some apps might have a legitimate use for a permission that isn't immediately obvious. For example, plenty of apps request access to the Phone permission just so they can save or pause if you get an incoming call. But there's rarely reason for a simple game to need access to your SMS texting capability. Some apps might cease working altogether if one or more permissions are denied—for example, Pokemon GO can't work without knowing your location. You'll have to decide for yourself how much access is appropriate based on the app.

If you want to remove permission from any apps, here's how to do it.
On Android
If you have an Android device, go to the main Settings menu, then tap Apps. Tap the specific app you want to adjust.



Tap "Permissions." This will show you a list of permissions that the app has requested, and which ones are currently enabled. Simply tap the slider on the right side of the screen to enable or disable permissions individually.



For more details about handling Android app permissions, check out this guide.
On the iPhone and iPad
RELATED ARTICLE


How to Manage App Permissions on Your iPhone or iPad
?

On iOS, the Settings menu allows access to a master list of which apps have access to specific permissions (called "Access" in the interface). These are broken up into different sections, though. In the main Settings menu, tap "Privacy." Each of the sub-sections in this screen will list all of the apps using their respective permissions, allowing you to selectively disable them one by one.



If you're more concerned about a single app, go back to the main Settings menu and scroll down until the app appears in the list. Tap it and you'll see all the permissions it's requested and been granted under "Allow [app] To Access." You can tap each individual permission to enable or disable it.

You can read up on managing permission access in iOS here.


Again, the best way to retain your privacy from apps like this is to not use them in the first place. Pay attention to every popup you see, think about why an app may be requesting the permissions it does, and if anything seems fishy, look it up on the app's store page or website—or ignore it entirely.

https://www.msn.com/en-us/money/companies/your-location-data-is-being-sold-often-without-your-knowledge/ar-BBJRhew?li=BBnbfcN

 

 

Your location data is being sold -- often without your knowledge
3 / 28


The Wall Street Journal

Christopher Mims36 mins ago

 

 

 

?

 
© Kenneth Bachor/The Wall Street Journal Location-based ads are growing, which means the industry has more ways than ever to track...
 

 

As location-aware advertising goes mainstream—like that Jack in the Box ad that appears whenever you get near one, in whichever app you have open at the time—and as popular apps harvest your lucrative location data, the potential for leaking or exploiting this data has never been higher.

It's true that your smartphone's location-tracking capabilities can be helpful, whether it's alerting you to traffic or inclement weather. That utility is why so many of us are giving away a great deal more location data than we probably realize. Every time you say "yes" to an app that asks to know your location, you are also potentially authorizing that app to sell your data.

Dozens of companies track location and/or serve ads based on this data. They aim to compile a complete record of where everyone in America spends their time, in order to chop those histories into market segments to sell to corporate advertisers.

Marketers spent $16 billion on location-targeted ads served to mobile devices like smartphones and tablets in 2017. That's 40% of all mobile ad spending, research firm BIA/Kelsey estimates, and it expects spending on these ads to double by 2021.

The data required to serve you any single ad may pass through many companies' systems in milliseconds—from data broker to ad marketplace to an agency's custom system. In part, this is just how online advertising works, where massive marketplaces hold ongoing high-speed auctions for ad space.

But the fragmentation also is due to a very real fear of the public backlash and legal liability that might occur if there were a breach. Imagine the Equifax breach, except instead of your Social Security number, it's everywhere you've been, including your home, your workplace and your children's schools.

The fix, at least for now, is that with most individual data vendors holding only parts of your data, your complete, identifiable profile is never all in one place. Giants like Google and Facebook, who do have all your data in one place, say they are diligent about throwing away or not gathering what they don't need, and eliminating personally identifying information from the remainder.

Yet as the industry and the ways to track us expand, the possibility that our whereabouts will be exposed multiplies.

If you've ever felt clever because an app on your phone asked to track your location and you said no, this should make you feel a little less smug: There are plenty of ways to track you without getting your permission. Some of the most intrusive are the easiest to implement.

Your telco knows where you are at all times, because it knows which cell towers your phone is near. In the U.S., how much data service-providers sell is up to them. 

Another way you can be tracked without your knowing it is through any open Wi-Fi hot spot you might pass. If your phone's Wi-Fi is on, you're constantly broadcasting a unique MAC address and a history of past Wi-Fi connections. Retailers sometimes use these addresses to identify repeat customers, and they can also use them to track you as you go from one of their stores to another.

WeatherBug, one of the most popular weather apps for Android and iPhone, is owned by the location advertising company GroundTruth. It's a natural fit: Weather apps need to know where you are and provide value in exchange for that information. But it also means that app is gathering data on your location any time the app is open—and even when it isn't, if you agreed to always let it track your location. That data is resold to others.

GroundTruth also gathers location data from "over a hundred thounited snakesnd" other apps that have integrated bits of its code, says company president Serge Matta, who declined to disclose which apps. App makers agree to harvest location data because it grants them access to GroundTruth's mobile advertising network.

This data is what enables marketers like Jack in the Box to push an advertiser's message to potential customers near its restaurants. A typical engagement includes pushing location-based promotions or coupons through mobile ads, says Iwona Alter, Chief Marketing Officer of Jack in the Box.

Every month GroundTruth tracks 70 million people in the U.S. as they go to work in the morning, come home at night, surge in and out of public events, take vacations, you name it.

Companies like GroundTruth try to ensure they aren't tracking or storing data on individuals. Most of what they sell are anonymous blobs of people who fit particular descriptions—"soccer moms who intend to buy an SUV," for example. But they also occasionally hand off location data to a third party, such as LiveRamp, owned by data broker Acxiom, before it's matched up with potentially personally identifying information, such as your complete shopping history at a retailer. LiveRamp is almost like an escrow company for data.

Companies like Acxiom could be prime targets for hackers, said Chandler Givens, chief executive of TrackOff, which develops software to protect user identity and personal information. LiveRamp goes to great lengths to mathematically obfuscate our individual identities, said Sheila Colclasure, chief data ethics officer at LiveRamp and Acxiom. But some security researchers fear data brokers like Acxiom may be compromised already, or could be someday.

Acxiom and LiveRamp in the U.S. are governed by federal and state laws that regulate the collection and use of data in the particular businesses their clients are involved in, Ms. Colclasure said. Nearly every year, a bill comes up in the Senate or House that would regulate our data privacy—the most recent was in the wake of the Equifax breach—but none has passed. In some respects, the U.S. appears to be moving backward on privacy protections.

There might never be a breach of our location data. But given the drumbeat of hacks of both companies and governments, it's hard to believe hackers aren't at least trying to compromise such a high-value target.