FTC sues data broker for selling millions of people's 'precise' location info
- Reference: 1661810991
- News link: https://www.theregister.co.uk/2022/08/29/ftc_sues_kochava/
- Source link:
The American watchdog alleged in a lawsuit that Kochava's data feeds, which are sold via publicly accessible marketplaces, reveal individuals' visits to reproductive health clinics, places of worship, homeless and domestic violence shelters, addiction recovery facilities, and other sensitive places.
These records, it is claimed, pinpoint – using timestamps and latitude and longitude values – when and where people have been.
[1]
Though this information is ideally supposed to be anonymized, there is a concern it can be used with other data to unmask netizens and discover their identities – or simply studied to figure out who they are from their travels and the addresses they stay at.
[2]
[3]
Kochava can get this data from Android and iOS apps and websites that [4]embed its tracker code. Developers use this toolkit to monitor their users – figuring out what they are interested in, how they use an app, tying their activities to a targeted advertising ID, and so forth – and Kochava would get a real-time feed of information to collect and sell. According to the FTC, Kochava also buys up personal records from other brokers to resell.
"In numerous instances, [the] defendant has sold, licensed, or otherwise transferred precise geolocation data associated with unique persistent identifiers that reveal consumers' visits to sensitive locations," according to the FTC's lawsuit
[5]PDF
filed Monday in a US federal district court.[6]
[7]Selling this type of personal information could cause "substantial injury to consumers" such as stalking, discrimination, job loss, and physical violence, the FTC argues. As such, the regulator claims Kochava is breaking American consumer protection law.
For example, geolocation data [8]could reveal the location of someone involved in domestic violence, and an abuser could use this information to track down a victim at a supposedly secure shelter. It could also show how long someone stayed at a rehab clinic or homeless shelter, which may hurt their future job prospects, the lawsuit stated.
Following the US Supreme Court's decision to [9]overturn Roe v. Wade , and nearly a dozen states' subsequent laws making [10]abortion illegal — some with [11]bounties that incentivize digital witch hunts of women seeking abortions or anyone helping to provide the procedure — this data could also be used to track down and prosecute anyone seeking to end a pregnancy.
[12]
According to the court documents:
The data may be used to identify consumers who have visited an abortion clinic and, as a result, may have had or contemplated having an abortion. In fact, in just the data Kochava made available in the Kochava Data Sample, it is possible to identify a mobile device that visited a women's reproductive health clinic and trace that mobile device to a single-family residence. The data set also reveals that the same mobile device was at a particular location at least three evenings in the same week, suggesting the mobile device user's routine. The data may also be used to identify medical professionals who perform, or assist in the performance, of abortion services.
This info was listed for sale on the AWS Marketplace until June, according to the FTC. For $25,000, anyone with a free AWS account could subscribe to the location data feed, the lawsuit alleges.
Identifying users
A sample of this data examined by the FTC included precise, timestamped location records collected from more than 61 million unique mobile devices in the previous week. When combined with the mobile device's advertising ID (MAID), it would be easy to identify the phone's user, the regulator said.
"The location data sold by Kochava typically includes multiple timestamped signals for each MAID," the lawsuit stated. "By plotting each of these signals on a map, much can be inferred about the mobile device owners. For example, the location of a mobile device at night likely corresponds to the consumer's home address."
In fact, we're told Kochava suggested "household mapping" as a use-case for the data in its AWS Marketplace marketing, or in other words: using the data to figure out who lives with each other.
The lawsuit seeks an injunction to force the data broker to stop selling consumers' geolocation data and require Kochava to delete the sensitive information it has collected.
[13]Sephora to pay $1.2m to settle Cali privacy law claims – and why this is a big deal
[14]FTC ponders proper punishment for commercial data 'surveillance' and shoddy security
[15]Data brokers amass profiles of pregnant women – and, of course, it's all up for sale
[16]Mozilla finds 18 of 25 popular reproductive health apps share your data
"Where consumers seek out health care, receive counseling, or celebrate their faith is private information that shouldn't be sold to the highest bidder," said Samuel Levine, director of the FTC's Bureau of Consumer Protection, in a statement.
The lawsuit also comes about two weeks after Kochava filed a complaint
[17]PDF
against the FTC, which had threatened legal action against the data broker. Kochava sought to head off the FTC at the pass, and foil any court case brought against it by the regulator.In that filing, the biz denied it sold precise location data and that this data could be used to track down individuals to sensitive locations. Kochava also denied allegations it has poor privacy protections, and questioned whether the FTC had the legal powers to take the company to court over geolocation practices.
Kochava also said users opted into having their data collected when they installed or used apps containing tracking code. "Even if an injury to the consumer did indeed occur," the biz added, "it is reasonably avoidable by the consumer themselves by way the opt-out provision to allow the data collection. In other words, the consumer agreed to share its location data with an app developer."
Cracking down on commercial surveillance
While the FTC specifically goes after Kochava with today's lawsuit, the move is part of a larger effort by the consumer protection agency to crack down on [18]commercial surveillance practices that collect, analyze, and profit from personal information.
In July, the FTC [19]put businesses on notice that it intends to enforce the law against the illegal use and sharing of highly sensitive consumer data, including sensitive health data. A month later, it [20]announced an effort to formulate privacy rules to deter unwelcome online monitoring and shoddy privacy protections.
Last year, the agency [21]issued a policy statement warning health apps and connected devices that collect or use consumers' health information that they must notify people when a security or privacy breach occurs, and it also [22]took action against fertility-tracking app Flo for sharing sensitive health data with Facebook, Google, and other third parties. ®
Get our [23]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yw2LWiFVzkctuCeyAhdchAAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw2LWiFVzkctuCeyAhdchAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw2LWiFVzkctuCeyAhdchAAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://support.kochava.com/sdk-integration/android-sdk-integration/
[5] https://www.ftc.gov/system/files/ftc_gov/pdf/1.%20Complaint.pdf
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yw2LWiFVzkctuCeyAhdchAAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/08/01/pregnant_womens_data_sold/
[8] https://www.theregister.com/2022/06/14/airtag_tracking_murder_charge/
[9] https://www.theregister.com/2022/06/24/big_tech_post_roe_wade/
[10] https://reproductiverights.org/maps/abortion-laws-by-state/
[11] https://www.npr.org/2022/07/11/1107741175/texas-abortion-bounty-law
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yw2LWiFVzkctuCeyAhdchAAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2022/08/27/sephora_ccpa_privacy_settlement/
[14] https://www.theregister.com/2022/08/11/ftc_personal_data_rules/
[15] https://www.theregister.com/2022/08/01/pregnant_womens_data_sold/
[16] https://www.theregister.com/2022/08/17/mozilla_pregnancy_app/
[17] https://www.bloomberglaw.com/public/desktop/document/KochavaIncvFederalTradeCommissionDocketNo222cv00349DIdahoAug12202?1661787915
[18] https://www.ftc.gov/legal-library/browse/federal-register-notices/commercial-surveillance-data-security-rulemaking
[19] https://www.theregister.com/2022/07/12/ftc_anonymized_data/
[20] https://www.theregister.com/2022/08/11/ftc_personal_data_rules/
[21] https://www.ftc.gov/news-events/news/press-releases/2021/09/ftc-warns-health-apps-connected-device-companies-comply-health-breach-notification-rule
[22] https://www.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google
[23] https://whitepapers.theregister.com/
Android's missing firewall
Users are told they are giving an app permission to use the data. The app is designed to do something useful with that data, so they give THE APP permission. But they are not giving the app permission, they are giving the company and its partners permission.
You might give a messaging app, access to your contacts, thinking it will only request a contact when sending a message. Instead the app promptly slurps down all the contacts and sends them off to the company server to stich up a map of who is in contact with whom. Your contact may not have given permission to the company to have their name, but from *your* phone contact they will extract it from the phone number and the contact detail.
There is nothing wrong with giving an app GPS location, there is everything wrong when that GPS location is remotely sent off and logged. It's the "app" that is granted permission but the "company" that is misusing it.
Android is missing a firewall.
Android is missing a firewall because the company that controls it, is king of the data slurpees.
Re: Android's missing firewall
I also ask you to take a good look at what Google is doing with Google Play and permissions.
There's an upcoming one, I'll use as example: Apps that need to do something regularly call an API to set an alarm to wake them up. Google split that alarm into two, "exact" alarms for apps that need a specific wakeup and normal alarms that may be a little late or early to improve battery performance. So far so good. The new change is to break the "exact" timers if the app doesn't have an extra permission and force it to be inaccurate.
So the app needs an exact time, it requested an exact time, it will be refused an exact time. Of course the user won't know the details of the change, it is fine detail, only that the app doesn't run properly. Notifications are late etc.
That permission will likely be turned on by default for Google Play sourced apps that request it as other permissions have.
I suspect that Google Play Services will turn it off for non Google Play apps, as it appears to be doing for other critical permissions (USB access and Accessibility Permssions). In effect, if the app doesn't come from Google Play, rather some other store or direct from the company, your app software is under attack from Google Play. Here I suspect you'll miss critical timing things that the app needed.
This pattern, coupled to the other thing they're doing... forcing all transactions, even third party ones through Google Play Store. It gives them a cut of the fee, sure, but it also gives them the identity details of every Android user. Even ones that don't want to be customers of Google. Things like gift cards are being phased out, and you are being force to reluctantly get a Google Play account, simply to get software not to break, which in turn is forcing financial ID details linkable to the magic cookie (the tracking ID Android phones send as a unique device ID).
Four other things: changing the magic cookie 'ad ID' on Android does not help. Google had your session data, you change the cookie, it now has the new cookie for that session data. It can link the two, and given Google's behavior it certainly will be doing that.
Opting out of customized advertising is not the same as "DO NOT SEND THE UNIQUE ID". It's worded to make you think it is, but I think it still sends the ID, I believe Google still *tracks* the ID, it just doesn't serve the adverts with the same level of personalization.
The ID is obsfucation. At any time, Google can link that ID to an account, but chooses to present you a fake view of the data it has slurped as if it cannot.
Course position, is a lie, Google has your location to metres, the course position is sent back to you and your apps. It is not the phone that is sending a course location, it is sending the exact location to Google, Google is getting the exact position. What would you bet that the exact position is also logged against Google's magic cookie? 0.9999.... probability.
Re: Android's missing firewall
So yeah:
Tune Out and Turn OFF.
Re: Android's missing firewall
Thank you, Captain Obvious. We never would have known had you not typed up such an ineloquent essay.
Liar!
From article "Kochava also said users opted into having their data collected when they installed or used apps containing tracking code."
That's a lie, the user is giving the app permission to access data, not the developer to collect and share data. The popup on install does not ask to collect and share data* just that the app requires access to the data.
The user has not opted into having their data collected and shared as they were never asked for permission.
*I am not a google android user, so I am assuming that is so.
In the age of high tech tracking...
...People are better off leaving their devices at home. If you don't have a home to leave it at then turn it off and remove the battery. The "Always On" culture can only be defeated by "Tuning Out and Turning Off."