中文 (繁體)

Why Google and Apple App Stores Aren't Effective at Protecting Users Privacy

It's important for users to understand what personal data applications for iOS and Android collect and how the data is used. Apple and Google, as market leaders, have strict and well-developed requirements for app developers in terms of privacy protection; however, incidents with personal data leaks are not becoming rare. In fact, it's safe to say that effective control over privacy is impossible to achieve nowadays when we leave it only up to corporations. Not only do they continue to ignore incidents, they also don't allow third-party developers to give users control.

What’s the problem with Apple's strict control?

From a privacy point of view, Apple’s policies are well defined, and there’s no big difference between the declared and the actual approach. Apple imposes quite stringent restrictions on what user information an app can obtain.

In fact, Apple is limiting iOS app developers to a single way to track a user, with Advertising ID, which the user has control over. Apple’s guidelines clearly state that nothing else can be used for tracking in terms of user data. All large analytical systems are forced to obey this rule. Also, some types of apps impose additional restrictions on what can and can't be collected about the user.

Is it possible to quietly break these rules?
Yes it is, and unfortunately, there are plenty of high-profile examples. Recently it was discovered that Sensor Tower, a popular analytics platform for technology developers and investors, secretly gathers data about millions of people who installed popular VPN and ad-blocking apps for Android and iOS. As BlackBerry states, hundreds of apps circumvented Apple and Google security measures. And the sad part here is that Apple itself can search for these violators, but other researchers experience difficulties in doing so.

Apple mostly does validate apps for compliance with its policies. But Apple’s privacy policy remains...selective. That is, on the one hand, permitted/forbidden actions are indeed described in the guidelines, but one can't be sure that some people aren’t allowed to do more than others.

In 2018, the Uber iOS app suddenly received additional rights to access users’ screen recordings, which is quite an unprecedented step. Private APIs cannot be used in applications on Apple App Store, and the Uber API, which technically could allow them to record the display of the device, was eventually blocked.

Apple's privacy guidelines is tightened year by year, but the interpretation of the rules tends to change over time, and there is also evidence of this.

The case with AdGuard Pro is one of the examples. As a result, we even had to temporarily suspend the development. The reason was: a sudden change in the interpretation of some paragraphs of the App Store rules.

Users of iOS applications themselves don't have any means of control over their data; they simply have to trust the app developer. And Apple has no desire to let third-party developers provide privacy protection tools for end-users; instead, it severely limits the functionality of such applications.

And Apple, in turn, has no desire to provide privacy protection tools to third-party developers; instead, it severely limits the functionality of applications.

It would be more convenient for us, as an app developer, to live without restrictions. We provide a tool that they don't have, but they limit us in functionality and don’t always explain the reason. This isn't very convenient, but, unlike Google, Apple is ready to make contact. Nevertheless, our applications could’ve done so much more if we hadn’t been restricted in functionality.

The problem is also that Apple reviewers may not see what the application actually does with personal data. The number of Apple apps (as well as their developers) is growing rapidly, and in recent years the corporation had to enlarge their staff of reviewers. Unfortunately, new employees don't have the proper experience. They may not fully understand the guidelines, so they interpret the rules in their own way, each time differently. As a result, it can be difficult to agree with them on what's permitted and what's not. On the other hand, they at least explain in detail what the problem is, unlike Google, where you often have to speculate what's meant by a particular requirement.

In conclusion, we would like to say that Apple has very good privacy guidelines, and they try to apply them fairly, but at the same time, they also try to keep all privacy issues under their own control. And they can act quite selectively, and that precisely is the problem. But in general, in terms of privacy, the iOS platform is the most secure for the user.

Wild Wild West Google Play

Applications on Google Play are absolutely disrespectful to users’ personal data. Sad but true. The protection of personal data in Android apps remains surprisingly poor, despite the large number of high-profile incidents.

In 2018 we conducted some research and confirmed that Android applications from the TOP1000 can, without notifying the user, extract email addresses, contacts and text messages, and transfer them to third parties, and there is almost no protection against this. It was especially unpleasant to see that some of the most popular applications (10M+ downloads), award-winning, all those "Editors' Choice" and such on Google Play were doing this.

We found that at least three applications developed by the Chinese company GOMO violated users’; privacy and tried to siphon as much information as possible. The GO SMS Pro app boasts over 100 million installations according to Google Play. Immediately after installing the app, it sends your email to the goconfigsync.3g.cn domain directly in the request URL using regular HTTP. Therefore, your email isn't just sent to their server, but also provided to all intermediate third-party organizations.

Plus, we have found two more apps: Z Camera - Photo Editor, Beauty Selfie, Collage and S Photo Editor - Collage Maker, Photo Collage with more than 100M installations each. Both apps send your email address together with other various information to the domain zcamera.lzt.goforandroid.com. Ironically, GOMO likes to focus on privacy when describing their apps.

And nothing has really changed over the past two years. News about incidents regarding Google Play applications is still appearing. It's also impossible to be completely sure that security apps are not involved in unauthorized tracking.

The question is, why do such cases go unnoticed by Google?

In the meantime, the privacy situation on the Play Store can be described as the “Wild Wild West.” It would seem that Google sets the right requirements for mobile application developers, but the struggle to enforce them remains the task of “lone sheriffs.”

What does it amount to?
Google's declared privacy protection guidelines are milder than Apple's. Google doesn’t have restrictions on user identification, for instance. Plus, they have the appropriate restrictions on certain information, such as location, date, and contacts. According to the guidelines, personal data can only be requested from a user if the app actually uses it. Here's what's forbidden: “Apps that steal user authentication information (such as usernames or passwords) or imitate other apps or websites to trick users into revealing personal information or authentication information.”

Despite these restrictions, unfortunately, it's very easy not to follow them. Any developer can ignore the requirements, and there are dozens of examples of it. However, when new high-profile cases become public, Google may not even pay attention. Like they say, when a product is free, you are the product.

Users' data protection needs run contrary to the corporation's advertising business model. And it's not profitable for corporations to remove ads from their closed platforms, so they staunchly defend them.

If Google didn't restrict the functionality of third-party apps, the situation might not be so deplorable. Android app users’ sensitive information remains unprotected from unrestricted access by third parties. Google isn’t trying to solve this problem, nor does it allow third-party developers to do it, nor does it take responsibility for the inevitable incidents.

Gradually, Google is forcing developers to ask the user to grant access to certain data, and this helps a little with privacy protection. At the same time, they’re trying to solve all the problems in one fell swoop without using “manual force,” such as the App Store, which is a highly inefficient method. In our view, the ideal solution would be for Google to take control of user data and to give the users control via third-party developers.

In the meantime, Google is trying to automate all the processes of interaction with developers. But as a result, the procedure for interaction remains completely opaque, inconvenient, and constantly requiring further clarification.

Why do incidents occur?

Unfortunately, Apple and Google's policies actually have little in common with real security and privacy. Developers of privacy protection solutions are not comfortable working with either Google or Apple. Apple gives some opportunities, but at the same time it clamps users in the jaws of restrictions and approaches different companies selectively. Google allows developers to do anything… but not on Google Play.

Of course, there are many more incidents of personal data leaks ahead, and as more and more users become interested in the topic of privacy, this problem will be dealt with more actively.

19,182 19182 使用者評論

AdGuard for Windows

Windows 版 AdGuard 不只是廣告封鎖程式,它是集成所有讓您享受最佳網路體驗的主要功能的多用途工具。其可封鎖廣告和危險網站,加速網頁載入速度,並且保護兒童的線上安全。
19,182 19182 使用者評論

AdGuard for Mac

Mac 版 AdGuard 是一款獨一無二的專為 MacOS 設計的廣告封鎖程式。除了保護使用者免受瀏覽器和應用程式裡惱人廣告的侵擾外,應用程式還能保護使用者免受追蹤、網路釣魚和詐騙。
19,182 19182 使用者評論

AdGuard for Android

Android 版的 AdGuard 是一個用於安卓裝置的完美解決方案。與其他大多數廣告封鎖器不同,AdGuard 不需要 Root 權限,提供廣泛的應用程式管理選項。
19,182 19182 使用者評論

AdGuard for iOS

用於 iPhone 和 iPad 的最佳 iOS 廣告封鎖程式。AdGuard 可以清除 Safari 中的各種廣告,保護個人隱私,並加快頁面載入速度。iOS 版 AdGuard 廣告封鎖技術確保最高質量的過濾,並讓使用者同時使用多個過濾器。
19,182 19182 使用者評論

AdGuard 內容阻擋器

AdGuard 內容阻擋器將消除在支援內容阻擋器技術之行動瀏覽器中的各種各類廣告 — 即 Samsung 網際網路和 Yandex.Browser。雖然比 AdGuard for Android 更受限制,但它是免費的,易於安裝並仍提供高廣告封鎖品質。
19,182 19182 使用者評論

AdGuard 瀏覽器擴充功能

AdGuard 是有效地封鎖於全部網頁上的所有類型廣告之最快的和最輕量的廣告封鎖擴充功能!為您使用的瀏覽器選擇 AdGuard,然後取得無廣告的、快速的和安全的瀏覽。
19,182 19182 使用者評論

AdGuard 助理

AdGuard 桌面應用程式的配套瀏覽器擴充功能。它為瀏覽器提供了自訂的元件阻止的功能,將網站列入允許清單或傳送報告等功能。
19,182 19182 使用者評論

AdGuard DNS

AdGuard DNS 是一種不需要安裝任何的應用程式而封鎖網際網路廣告之極簡單的方式。它易於使用,完全地免費,被輕易地於任何的裝置上設置,並向您提供封鎖廣告、計數器、惡意網站和成人內容之最少必要的功能。
19,182 19182 使用者評論

AdGuard Home

AdGuard Home 是一款用於封鎖廣告 & 追蹤之全網路範圍的軟體。在您設置它之後,它將涵蓋所有您的家用裝置,且為那您不需要任何的用戶端軟體。由於物聯網和連網裝置的興起,能夠控制您的整個網路變得越來越重要。
19,182 19182 使用者評論

AdGuard Pro iOS 版

除了在 Safari 中之優秀的 iOS 廣告封鎖對普通版的用戶為已知的外,AdGuard Pro 提供很多功能。透過提供對自訂的 DNS 設定之存取,該應用程式允許您封鎖廣告、保護您的孩子免於線上成人內容並保護您個人的資料免於盜竊。
19,182 19182 使用者評論

AdGuard for Safari

自 Apple 開始強迫每位人使用該新的軟體開發套件(SDK)以來,用於 Safari 的廣告封鎖延伸功能處境艱難。AdGuard 延伸功能可以將高優質的廣告封鎖帶回 Safari。
19,182 19182 使用者評論

AdGuard Temp Mail

19,182 19182 使用者評論

AdGuard Android TV 版

Android TV 版 AdGuard 是唯一一款能封鎖廣告、保護隱私並充當智慧電視防火墻的應用程式。取得網路威脅警告,使用安全 DNS,並受益於加密流量。有了安全性和零廣告的使用體驗,使用者就可以盡情享受最喜愛的節目了!
已開始下載 AdGuard 點擊箭頭所指示的檔案開始安裝 AdGuard。 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,拖曳 AdGuard 圖像到"應用程式"檔案夾中。感謝您選擇 AdGuard! 選擇"開啟"並點擊"確定",然後等待該檔案被下載。在被打開的視窗中,點擊"安裝"。感謝您選擇 AdGuard!
在行動裝置上安裝 AdGuard