First Android, now iPhone apps have sprung a data leak

US— iPhone apps have been discovered sharing unique device identifiers (UDIDs) with remote servers, sometimes with an iPhone user’s name attached in breach of Apple’s developer rules.

An evaluation of 57 of the most popular free apps found 67% were transmitting UDIDs between applications and remote servers owned either by application developers or their advertising partners, while “a substantial number” were found to collect both UDID and “some form of user login data which ties to a stored user account”.

Study author Eric Smith, assistant director of information security and networking at Bucknell University, Pennsylvania, tracked an exchange between Amazon.com’s iPhone app and the company’s servers, in which the UDID was transmitted and a reply made which contained his real name.

Apple warns app developers they “must not publicly associate a device’s unique identifier with a user account”. The most recent version of the company’s developer rules states that user and device data can be collected “to provide a service or function that is directly relevant to the use of the application, or to serve advertising” but not without obtaining prior user consent.

But according to Smith, “there is no ability to block visibility of the iPhone’s UDID to any installed applications, nor is there a mechanism to prevent the transmission of the UDID to third parties”.

He adds: “iPhone users are helpless to prevent their phones from leaking this information”. Download Smith’s paper here.

Last week, a study of 30 popular Google Android apps also uncovered instances where potentially sensitive device information and location data was being leaked by applications without user permission.

We hope you enjoyed this article.
Research Live is published by MRS.

The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.

Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.

For example, there's an archive of winning case studies from over a decade of MRS Awards.

Find out more about the benefits of joining MRS here.

0 Comments


Display name

Email

Join the discussion

Newsletter
Stay connected with the latest insights and trends...
Sign Up
Latest From MRS

Our latest training courses

Our new 2025 training programme is now launched as part of the development offered within the MRS Global Insight Academy

See all training

Specialist conferences

Our one-day conferences cover topics including CX and UX, Semiotics, B2B, Finance, AI and Leaders' Forums.

See all conferences

MRS reports on AI

MRS has published a three-part series on how generative AI is impacting the research sector, including synthetic respondents and challenges to adoption.

See the reports

Progress faster...
with MRS 
membership

Mentoring

CPD/recognition

Webinars

Codeline

Discounts