15 hours ago
- A massive geolocation data leak from Gravy Analytics exposed over 2000 apps collecting location data without consent.
- The author tracked their own data by analyzing requests from a simple game app, finding IP, location, and device details sent to Unity Ads, Facebook, and others.
- Real-time bidding (RTB) protocols like OpenRTB enable extensive data sharing, including screen brightness, volume, and battery level, beyond just geolocation.
- User consent settings like 'Ask App Not to Track' only limit IDFA sharing, but IP and location still leak to third parties via various identifiers.
- Data brokers such as Redmob and AGR Marketing Solutions sell location data and MAID-to-PII mappings, making it possible to link device IDs to real identities.
- The author concludes that combining leaked ad bid data with purchased datasets allows anyone to track individuals, highlighting the systemic privacy risks.