Two-thirds of the most widely used iPhone applications transmit personal data to external servers. App developers and advertisers can monitor users.
About 68 percent of the most popular iPhone apps send personal data such as device IDs, as well as full names or location data, to servers run by advertisers or developers. This emerges from research by Eric Smith of Bucknell University. He examined the 57 most-used free apps. By placing a device ID (UDID) in a cookie, it becomes possible to monitor iPhones.
Usernames
According to Smith, an app sending only a UDID is not an immediate cause for alarm. With that number alone, advertisers and developers cannot yet determine a user’s identity. That does become possible if they also transmit other data, such as full names or usernames.
If apps also send those data to an external server, companies not only learn a user’s full name but can also continue to track that user if they switch to another smartphone.
Unsecured
Smith’s research shows that it is not obscure applications that transmit this personal data. Apps from, for example, BBC News and ABC News place cookies with a UDID for their advertisements. ABC’s cookie does not expire for 20 years, and the application also stores location data.
The Amazon iPhone app sends not only the UDID but also the user’s name. The application does so without security, making it possible for eavesdroppers to obtain personal data.
According to Smith, this data transmission is intended to give advertisers insight into the reach and target audience of their application. The researcher believes that the privacy of iPhone users is seriously jeopardized by such practices.
Network analysis tool
Late last week, research by Duke University, Penn State University, and Intel Labs showed that two-thirds of Android apps also transmit private data to advertisers and developers.
The Android research was conducted via a custom application. Smith examined iPhone apps using the network analysis tool TShark.