Bitcoin Business Investment Policy & Regulation Tech

Popular Crypto App Found to Have Ties to Data Tracking Company: Report

img-ads

Android versions of popular cryptocurrency app Bitcoin Ticker Widget and a seeming clone of Steemit, Steemit Earn Money, included software development kit (SDK) tools that extract extensive data on users in the past and are potentially linked to location tracking code from X-Mode a notorious data tracking company, according to a new report from Express VPN Digital Security Lab. Two other personal finance apps also have been found to contain these data trackers.  

“We wanted to say to consumers: ‘This is a huge problem; you may not be aware of it,’” said Sean O’Brien, principal researcher at ExpressVPN Digital Security Lab. “Even though these apps aren’t all huge brands, these apps have been downloaded 1.7 billion times, collectively, and millions of times for each individual app. They’re running on people’s phones in their pockets. People are using them for dating and social and finances but they’re not fully aware of the amount of data that’s being scooped up.”

Scooping personal data

While there are many companies that buy and sell access to location data harvested from unsuspecting people’s phones, X-Mode has come under scrutiny after its ties to government contractors and the military were revealed. 

In November 2020, Vice reported X-Mode was getting detailed location data back from multiple Muslim prayer apps, then selling that data “to contractors, and by extension, the military.” 

Read more: From SIM-Swaps to Home-Invasion Threats, Ledger Leak Has Cascading Consequences

This new report, a far more extensive inquiry into this issue, found X-Mode code was in 44% of the 450 apps they analyzed, and those apps had been downloaded at least a billion times. 

“These apps are global and include health as well as weather apps, games and makeup photo filters,’ reads the report. 

“They’re running on people’s phones in their pockets. People are using them for dating and social and finances but they’re not fully aware of the amount of data that’s being scooped up.”

While Steemit Earn Money has only been downloaded about 100 times, Bitcoin Ticker Widget has been downloaded over 1 million times. 

In December, Apple and Google told developers to remove X-Mode from their apps or be banned from their app stores, but by the end of January, the report found, many apps have not yet complied, which was confirmed by TechCrunch in at least one case. 

Overall, the study examined 450 Android apps for data trackers. 

X-Mode’s SDKs and data brokers

SDKs are foundational tools that make it quicker and easier for developers to make apps. That being said, those tools can contain code that isn’t necessary to the core function of an app. This extra code can track location, extract data and generally relay information back to the creator of the SDK. That information can then be shared or sold to be used for a variety of purposes. 

When users download an app and accepts its terms of service and privacy policy, they may be inadvertently opting into these forms of data collection, even if they’re not told exactly whose hands the data may end up in. These sorts of practices are common in the world of targeting advertising but, as has been previously documented, data can also end up in the hands of law enforcement (even without a warrant), bounty hunters and others. 

Read more: How a Lawsuit Against the IRS Is Trying to Expand Privacy for Crypto Users

“Inside the X-Mode SDK, are code references to five data providers,” said O’Brien. “These are other entities that people loosely called ‘data brokers.’ Sometimes they’re doing actual selling of data and sometimes they’re not. While it’s somewhat complex, these five entities are basically well-known brands in this location surveillance space.”

“What seems to be occurring because of what’s in the code is that these data providers have some sort of business relationship with X-mode, either current or prior,” said O’Brien. “And if they are enabled in these apps, then those providers are also getting some information from the app that has the X-mode SDK.”

OneAudience, Opensignal and location data tracking

OneAudience, included in both Bitcoin Ticker Widget and Steemit Earn Money, was one “data broker” tracker referenced in X-Mode’s code as part of the SDK. It was the subject of a ban and lawsuit by Facebook over data privacy violations because of data OneAudience’s SDK was collecting. 

In February 2020 Twitter and Facebook claimed that “OneAudience had been harvesting private data, such as people’s names, genders, emails, usernames and potentially people’s last tweets” to such an extent that it has been compared to the Cambridge Analytica scandal. The SDK was shut down at the end of 2019. 

Another data tracker, Opensignal, primarily functions as a WiFi mapper, through which users’ locations can be determined. 

In its lawsuit against OneAudience, according to Recode, Facebook argued that “OneAudience also paid apps to harvest users’ Google and Twitter information when they logged into one of the compromised apps using their Google or Twitter account information.”

Read more: This Elusive Malware Has Been Targeting Crypto Wallets for a Year

OneAudience, when shutting down the SDK that was the subject of the lawsuit, said, “We were advised that personal information from hundreds of mobile IDs may have been passed to our OneAudience platform. This data was never intended to be collected, never added to our database and never used.”

Opensignal’s business model, on the other hand, is primarily dependent upon its Wi-Fi mapping use case. 

“‘The question is, how much of the Wi-Fi data are they scooping?”’ asked O’Brien. 

In its privacy policy, Opensignal states it gathers geolocation data, “network type, network operator, cellular and WiFi signal strength and quality, and the identifiers of connected cell towers and WiFi routers.”

OneAudience did not respond to a request for comment. Opensignal, in response to a request for comment, directed readers to its Data Privacy Charter. 

A ‘rich amount’ of personal data

Stepping back and looking at the report and network traffic from these apps, O’Brien has two big takeaways when it comes to the impact on your data privacy. 

“Usually the data is not being handled very well,” he said. “And there’s a rich amount of data that can be used as an identifier for a person that’s going through the pipe, even if location is the only named reason the data is being scooped up.”

If you choose to keep using the apps like Bitcoin Ticker Widget and Steemit Earn Money, there are ways to limit their data-tracking capabilities. O’Brien said users should go into settings and check permissions for the app, especially location permissions, and revoke them. 

“That may mean the app becomes less functional or displays nagging screens asking for permission,” he said. “Otherwise, unfortunately, the only other step is removing the app. If you’re a California or [European Union] resident, there may be some other steps to take regarding requesting information to be deleted or at least requesting a copy of the information they have.”

img-ads

Leave a Comment

Your email address will not be published.

You may also like

Investment Opinion

Here’s how multi-leg options allow traders to profit from $2K Ethereum price

This week Ether (ETH) price finally broke through the $2,000 level as aggressive institutional inflow through Grayscale Investments products and declining exchange reserves signaled that buying pressure was increasing.

While many traders are skilled at using perpetual futures and the basic margin investing tools available on most exchanges, they may be unaware of additional instruments that can be used to maximize their gains. One simple way, albeit expensive, is buying Ether call option contracts.

Ether 60-day historical volatility. Source: TradingView

For example, a March 26 call option with a $1,760 strike trades at $340. In the current situation, the holder would only profit if Ether trades above $2,180 in 39 days, a 21% gain from the current $1,800. If Ether remains flat at $1,800, this trader will lose $300. This is certainly not an excellent risk-reward profile.

By using call (buy) options and puts (sell), a trader can create…

View More Article
Bitcoin

Bitcoin pizza all over again — delivery driver reportedly cashes in on $400 BTC tip

A driver who held $5 in Bitcoin (BTC) as a tip for his pizza delivery services has reportedly resurfaced after seven years.

According to a post from Redditor btcbible, the Bitcoiner ordered a pizza on Dec. 28, 2013 and gave the delivery driver two options for his tip: a $5 bill, or 0.0069 BTC on a paper wallet. The value was roughly the same at the time, given the price of the crypto asset was $774.

However, the driver reportedly contacted btcbible this week for help on getting the funds into a hot wallet. With Bitcoin’s recent rise to a new all-time high of more than $58,000, the BTC is now worth roughly $400, an increase of more than 7,000% since the pizza was delivered hot.

“I let the pizza guy choose between $5 in fiat or BTC,” said btcbible….

View More Article
Bitcoin Business Markets

Former BoE, BoC governor Mark Carney joins Stripe board of directors

After paving the way for digital currency innovation at the Bank of England, or BoE, Mark Carney has officially joined the board of directors at Stripe — a company that’s committed to building new commerce solutions for the internet. 

Stripe introduced Carney as board member on Sunday, where he joins Christa Davies, Diane Greene, Jonathan Chadwick, Sir Michael Moritz and Stripe co-founders Patrick and John Collison. The U.S. digital payments company says it will benefit from Carney’s “extensive experience of global financial systems and governance,” especially as it rolls out new climate efforts.

“The very nature of commerce has changed over the past decade,” Carney said. “Stripe has been at the forefront of enabling this new digital economy, providing innovative and resilient global payment solutions to businesses large and small.”

He continued:

“I look forward to supporting Stripe over the coming years as they build the global infrastructure…

View More Article
Bitcoin Blockchain Business Markets Policy & Regulation Tech

Ripple now registered as a Wyoming business

Blockchain-based payments firm Ripple Labs has now registered a business in Wyoming.

According to records from the Wyoming Secretary of State, Ripple Markets WY LLC’s status as a local business is listed as “active” after an initial filing in February 2020. As a limited liability company in Wyoming, Ripple’s registered agent will be based in Cheyenne.

“More crypto companies are realizing Wyoming is a better domicile than Delaware due to our crypto-friendly laws,” said Caitlin Long on Twitter.

Long is the CEO of digital bank Avanti Bank & Trust and associated with the state legislature’s Select Committee on Blockchain, Financial Technology and Digital Innovation. She said crypto firms like Ripple should consider relocating to Wyoming due to the state not having any corporate or franchise taxes, and cryptocurrencies being exempt from property and sales tax.

In addition, there is the presence…

View More Article
Bitcoin Markets Opinion Tech

Top 5 cryptocurrencies to watch this week: BTC, AAVE, ATOM, NEO, VET

The Purpose Bitcoin (BTC) exchange-traded fund debuted on the Toronto Stock Exchange on Feb. 18 and has quickly ramped up trading volumes of about $400 million worth of shares in two days. This is quite impressive, considering that the equity market in Canada is only a fraction of the size of the U.S. markets. This shows strong demand for Bitcoin and investor’s preference to take the ETF route to establish fresh positions.

Last week, Bitcoin reached another important milestone when it hit the critical $1 trillion market capitalization on Feb. 19, making it the sixth asset on the list of top market cap companies in the world. 

The involvement of institutional investors and a market cap of over $1 trillion could allay the concerns of manipulation and liquidity raised by the U.S. Securities and Exchange Commission in the previous years as it rejected Bitcoin ETF applications. 

Crypto market data…

View More Article
Bitcoin Investment Markets

Canadian Bitcoin ETF predicted to hit $1B AUM by Friday: Bloomberg analyst

With only two full days of trading under its belt, the first Bitcoin (BTC) exchange-traded fund in North America reached more than $400 million in volume and is expected to go even higher.

According to a tweet from Bloomberg analyst Eric Balchunas, the Bitcoin exchange-traded fund, or ETF, recently debuted by Canadian firm Purpose Investments is likely to hit $1 billion in assets under management by Feb. 26. His prediction came prior to Purpose reporting its Bitcoin ETF traded $421.8 million between the time when it was first listed on the Toronto Stock Exchange, or TSX, on Feb. 18 and when markets closed Friday. The ETF is listed under the ticker BTCC.

Balchunas compared the impressive debut of the Purpose Bitcoin fund to other ETFs currently trading on the TSX. At more than $4.6 billion in total assets, the JPMorgan BetaBuilders…

View More Article
%d bloggers like this: