Меню
BE

Why Google and Apple App Stores Aren't Effective at Protecting Users Privacy

It's important for users to understand what personal data applications for iOS and Android collect and how the data is used. Apple and Google, as market leaders, have strict and well-developed requirements for app developers in terms of privacy protection; however, incidents with personal data leaks are not becoming rare. In fact, it's safe to say that effective control over privacy is impossible to achieve nowadays when we leave it only up to corporations. Not only do they continue to ignore incidents, they also don't allow third-party developers to give users control.

What’s the problem with Apple's strict control?

From a privacy point of view, Apple’s policies are well defined, and there’s no big difference between the declared and the actual approach. Apple imposes quite stringent restrictions on what user information an app can obtain.

In fact, Apple is limiting iOS app developers to a single way to track a user, with Advertising ID, which the user has control over. Apple’s guidelines clearly state that nothing else can be used for tracking in terms of user data. All large analytical systems are forced to obey this rule. Also, some types of apps impose additional restrictions on what can and can't be collected about the user.

Is it possible to quietly break these rules?
Yes it is, and unfortunately, there are plenty of high-profile examples. Recently it was discovered that Sensor Tower, a popular analytics platform for technology developers and investors, secretly gathers data about millions of people who installed popular VPN and ad-blocking apps for Android and iOS. As BlackBerry states, hundreds of apps circumvented Apple and Google security measures. And the sad part here is that Apple itself can search for these violators, but other researchers experience difficulties in doing so.

Apple mostly does validate apps for compliance with its policies. But Apple’s privacy policy remains...selective. That is, on the one hand, permitted/forbidden actions are indeed described in the guidelines, but one can't be sure that some people aren’t allowed to do more than others.

In 2018, the Uber iOS app suddenly received additional rights to access users’ screen recordings, which is quite an unprecedented step. Private APIs cannot be used in applications on Apple App Store, and the Uber API, which technically could allow them to record the display of the device, was eventually blocked.

Apple's privacy guidelines is tightened year by year, but the interpretation of the rules tends to change over time, and there is also evidence of this.

The case with AdGuard Pro is one of the examples. As a result, we even had to temporarily suspend the development. The reason was: a sudden change in the interpretation of some paragraphs of the App Store rules.

Users of iOS applications themselves don't have any means of control over their data; they simply have to trust the app developer. And Apple has no desire to let third-party developers provide privacy protection tools for end-users; instead, it severely limits the functionality of such applications.

And Apple, in turn, has no desire to provide privacy protection tools to third-party developers; instead, it severely limits the functionality of applications.

It would be more convenient for us, as an app developer, to live without restrictions. We provide a tool that they don't have, but they limit us in functionality and don’t always explain the reason. This isn't very convenient, but, unlike Google, Apple is ready to make contact. Nevertheless, our applications could’ve done so much more if we hadn’t been restricted in functionality.

The problem is also that Apple reviewers may not see what the application actually does with personal data. The number of Apple apps (as well as their developers) is growing rapidly, and in recent years the corporation had to enlarge their staff of reviewers. Unfortunately, new employees don't have the proper experience. They may not fully understand the guidelines, so they interpret the rules in their own way, each time differently. As a result, it can be difficult to agree with them on what's permitted and what's not. On the other hand, they at least explain in detail what the problem is, unlike Google, where you often have to speculate what's meant by a particular requirement.

In conclusion, we would like to say that Apple has very good privacy guidelines, and they try to apply them fairly, but at the same time, they also try to keep all privacy issues under their own control. And they can act quite selectively, and that precisely is the problem. But in general, in terms of privacy, the iOS platform is the most secure for the user.

Wild Wild West Google Play

Applications on Google Play are absolutely disrespectful to users’ personal data. Sad but true. The protection of personal data in Android apps remains surprisingly poor, despite the large number of high-profile incidents.

In 2018 we conducted some research and confirmed that Android applications from the TOP1000 can, without notifying the user, extract email addresses, contacts and text messages, and transfer them to third parties, and there is almost no protection against this. It was especially unpleasant to see that some of the most popular applications (10M+ downloads), award-winning, all those "Editors' Choice" and such on Google Play were doing this.

We found that at least three applications developed by the Chinese company GOMO violated users’; privacy and tried to siphon as much information as possible. The GO SMS Pro app boasts over 100 million installations according to Google Play. Immediately after installing the app, it sends your email to the goconfigsync.3g.cn domain directly in the request URL using regular HTTP. Therefore, your email isn't just sent to their server, but also provided to all intermediate third-party organizations.

Plus, we have found two more apps: Z Camera - Photo Editor, Beauty Selfie, Collage and S Photo Editor - Collage Maker, Photo Collage with more than 100M installations each. Both apps send your email address together with other various information to the domain zcamera.lzt.goforandroid.com. Ironically, GOMO likes to focus on privacy when describing their apps.

And nothing has really changed over the past two years. News about incidents regarding Google Play applications is still appearing. It's also impossible to be completely sure that security apps are not involved in unauthorized tracking.

The question is, why do such cases go unnoticed by Google?

In the meantime, the privacy situation on the Play Store can be described as the “Wild Wild West.” It would seem that Google sets the right requirements for mobile application developers, but the struggle to enforce them remains the task of “lone sheriffs.”

What does it amount to?
Google's declared privacy protection guidelines are milder than Apple's. Google doesn’t have restrictions on user identification, for instance. Plus, they have the appropriate restrictions on certain information, such as location, date, and contacts. According to the guidelines, personal data can only be requested from a user if the app actually uses it. Here's what's forbidden: “Apps that steal user authentication information (such as usernames or passwords) or imitate other apps or websites to trick users into revealing personal information or authentication information.”

Despite these restrictions, unfortunately, it's very easy not to follow them. Any developer can ignore the requirements, and there are dozens of examples of it. However, when new high-profile cases become public, Google may not even pay attention. Like they say, when a product is free, you are the product.

Users' data protection needs run contrary to the corporation's advertising business model. And it's not profitable for corporations to remove ads from their closed platforms, so they staunchly defend them.

If Google didn't restrict the functionality of third-party apps, the situation might not be so deplorable. Android app users’ sensitive information remains unprotected from unrestricted access by third parties. Google isn’t trying to solve this problem, nor does it allow third-party developers to do it, nor does it take responsibility for the inevitable incidents.

Gradually, Google is forcing developers to ask the user to grant access to certain data, and this helps a little with privacy protection. At the same time, they’re trying to solve all the problems in one fell swoop without using “manual force,” such as the App Store, which is a highly inefficient method. In our view, the ideal solution would be for Google to take control of user data and to give the users control via third-party developers.

In the meantime, Google is trying to automate all the processes of interaction with developers. But as a result, the procedure for interaction remains completely opaque, inconvenient, and constantly requiring further clarification.

Why do incidents occur?

Unfortunately, Apple and Google's policies actually have little in common with real security and privacy. Developers of privacy protection solutions are not comfortable working with either Google or Apple. Apple gives some opportunities, but at the same time it clamps users in the jaws of restrictions and approaches different companies selectively. Google allows developers to do anything… but not on Google Play.

Of course, there are many more incidents of personal data leaks ahead, and as more and more users become interested in the topic of privacy, this problem will be dealt with more actively.

Liked this post?
18 307 18307 водгукаў
Выдатна!

AdGuard для Windows

AdGuard для Windows - гэта больш, чым блакіроўшчык рэкламы. Гэта шматмэтавы інструмент, які блакіруе рэкламу, кантралюе доступ да небяспечных сайтаў, паскарае загрузку старонак і абараняе дзяцей ад недапушчальнага кантэнту.
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

AdGuard для Mac

AdGuard для Mac - унікальны блакіроўшчык рэкламы, распрацаваны з улікам спецыфікі аперацыйнай сістэмы macOS. Ён не толькі бароніць вас ад раздражняльнай рэкламы ва ўсіх браўзерах і праграмах, але і бароніць вас ад сачэння, фішынгу і махлярства.
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

AdGuard для Android

AdGuard для Android - ідэальнае рашэнне для Android-прылад. У адрозненні ад іншых блакіроўшчыкаў, AdGuard не патрабуе поўнага доступу, а таксама дае шырокі спектр магчымасцей па кіраванню праграмамі.
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

AdGuard для iOS

Лепшы блакіроўшчык рэкламы iOS для iPhone і iPad. AdGuard ліквідуе ўсе віды рэкламы ў Safari, абараняе вашу прыватнасць і паскарае загрузку старонак. Тэхналогія блакіроўкі рэкламы AdGuard для iOS забяспечвае высокую якасць фільтрацыі і дазваляе выкарыстоўваць некалькі фільтраў адначасова
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

AdGuard VPN

74 лакацыі па ўсім свеце

Доступ да любога кантэнту

Моцнае шыфраванне

Без лагавання

Самае хуткае злучэнне

Цэладзённая падтрымка

Паспрабуйце бясплатна
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

Блакіроўшчык кантэнту AdGuard

AdGuard Content Blocker ухіляе ўсе аб'явы ў мабільных браўзарах, якія падтрымваюць тэхналогію блакавання кантэнту — да прыкладу, Samsung Internet і Яндэкс.Браўзар. Ён валодае меншай колькасцю функцый, чым AdGuard для Android, але пры гэтым дармовы, просты ва ўсталёўцы і па-ранейшаму забяспечвае высокая якасць блакавання рэкламы.
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

Браўзернае пашырэнне AdGuard

AdGuard — самае хуткае і лёгкае браўзарнае пашырэнне для блакавання ўсіх тыпаў рэкламы! Абірайце AdGuard для хуткага і бяспечнага сёрфінга без рэкламы.
18 307 18307 водгукаў
Выдатна!

Памочнік AdGuard

Дапаможнае браўзернае пашырэнне для AdGuard настольных праграм. Дае доступ у браўзеры да такіх функцый, як блакіроўка асобных элементаў, уключэнне вэб-сайта ў белы спіс або адпраўка справаздачы.
18 307 18307 водгукаў
Выдатна!

AdGuard DNS

AdGuard DNS – гэта альтэрнатыўны спосаб заблакаваць рэкламу, абараніць асабістыя дадзеныя і ахаваць дзяцей ад дарослых матэрыялаў. Ён просты ў наладзе і выкарыстанні і забяспечвае патрэбны мінімум абароны ад рэкламы, трэкінгу і фішынгу, незалежна ад платформы.
18 307 18307 водгукаў
Выдатна!

AdGuard Home

AdGuard Home — магутная прылада для сеціва супраць рэкламы і трэкінгу. З узмацненнем ролі інтэрнэту рэчаў робіцца ўсё больш і важнейшым кіраваць усiм вашым сецівам. Пасля налады AdGuard Home будзе ахапляць УСЕ вашы хатнія прылады і для гэтага вам не спатрэбіцца праграмнае забеспячэнне на боку кліента.
18 307 18307 водгукаў
Выдатна!

AdGuard Pro для iOS

AdGuard Pro прапануе значна больш чым проста блакаванне рэкламы ў Safari, якая ёсць у звычайнай версіі. З дапамогай адмысловых налад DNS вы зможаце блакаваць больш рэкламы, абараніць вашы асабістыя дадзеныя і ахаваць дзяцей ад дарослага кантэнту.
Спампоўваючы праграму, вы прымаеце ўмовы Ліцэнзійнага пагаднення
Чытаць далей
18 307 18307 водгукаў
Выдатна!

AdGuard для Safari

Пашырэнні, што блакуюць рэкламу ў Safari, перажываюць не лепшыя часы з той пары, як кампанія Apple вымусіла ўсіх выкарыстоўваць новы SDK. Пазнаёмцеся з нашым лёгка наладжвальным і імгненным дадаткам!
18 307 18307 водгукаў
Выдатна!

AdGuard Temp Mail

Ваш часовы паштовую скрыню, каб на асноўную пошту не прыходзіў спам
18 307 18307 водгукаў
Выдатна!

AdGuard для Android TV

AdGuard for Android TV is the only app that blocks ads, guards your privacy, and acts as a firewall for your Smart TV. Get warnings about web threats, use secure DNS, and benefit from encrypted traffic. Relax and dive into your favorite shows with top-notch security and zero ads!
Спампоўка AdGuard Каб усталяваць AdGuard, пстрыкніце файл, пазначаны стрэлкай Выберыце «Адкрыць» і націсніце «ОК», затым дачакайцеся спампоўкі файла. У акне, якое адкрылася, перацягніце значок AdGuard у папку «Праграмы». Дзякуй, што выбралі AdGuard! Выберыце «Адкрыць» і націсніце «ОК», затым дачакайцеся спампоўкі файла. У акне, якое адкрылася, націсніце «Усталяваць». Дзякуй, што выбралі AdGuard!
Усталюйце AdGuard на мабільную прыладу