AccuWeather for iOS Sending Location Data to Monetization Company Even When Location Sharing is Off [Updated]
Tuesday August 22, 2017. 10:52 PM , from MacRumors
Popular and well-known iOS weather app AccuWeather has been caught collecting and sharing user location data even when location sharing permissions are turned off, according to a blog post recently shared by security researcher Will Strafach.
According to Strafach, AccuWeather was partnering with data monetization firm Reveal Mobile to collect GPS coordinates, including speed and altitude, the name and BSSID of a user's Wi-Fi router, and whether a device has Bluetooth on and off, all of which was available to Reveal Mobile when location services were enabled.
Following Strafach's discovery, many people have been uninstalling the AccuWeather app, and given the wealth of weather apps available in the App Store, this is not surprising. AccuWeather does not apparently have plans to end its relationship with Reveal Mobile, so users may want to find another weather app.
Update: AccuWeather and Reveal Mobile have provided a joint statement on the issue: Despite stories to the contrary from sources not connected to the actual information, if a user opts out of location tracking on AccuWeather, no GPS coordinates are collected or passed without further opt-in permission from the user.
Other data, such as Wi-Fi network information that is not user information, was for a short period available on the Reveal SDK, but was unused by AccuWeather. In fact, AccuWeather was unaware the data was available to it. Accordingly, at no point was the data used by AccuWeather for any purpose.
AccuWeather and Reveal Mobile are committed to following the standards and best practices of the industry. We also recognize this is a quickly evolving field and what is best practice one day may change the next. Accordingly, we work to update our practices regularly.
To avoid any further misinterpretation, Reveal is updating its SDK and pushing out new versions of the SDK in the next 24 hours, with the iOS update going live tonight. The end result should be that zero data is transmitted back to Reveal Mobile when someone opts out of location sharing. In the meanwhile, AccuWeather had already disabled the SDK, pending that update.
Reveal has stated that the SDK could be misconstrued, and they assure that no reverse engineering of locations was ever conducted by any information they gathered, nor was that the intent.
AccuWeather will work with Reveal to restore the SDK when it has been amended and will continue to update its ULAs to be transparent and current with evolving standards. AccuWeather and Reveal continue to enhance methods for handling data and strive to provide superior, seamless, and secure user experiences.
We are grateful to have a supportive community that highlights areas where we can optimize and be more transparent.Update 2: AccuWeather has updated its app to remove the Reveal Mobile SDK.Tags: App Store, AccuWeather Discuss this article in our forums
Nov, Wed 14 - 19:10 CET