Wednesday, January 30, 2019

Google Also Exploiting Enterprise Certificates to Bypass iOS App Store for Data Collection

http://bit.ly/2CU6l9J

Facebook is facing the wrath of Apple today for misusing an enterprise certificate meant for internal use to get Facebook users to sideload a data harvesting "Facebook Research" app that violates App Store policies, and as it turns out, Google has been doing the exact same thing.

According to TechCrunch, Google has been distributing an app called "Screenwise Meter" using the enterprise certificate installation method since 2012.


Google has been privately inviting users aged 18 and up (or 13 for those part of a family group) to download Screenwise Meter, an app that is designed to collect information on internet usage, including details on how long a site is visited to apps that are downloaded.

By asking Screenwise Meter users to download the app using an enterprise certificate, Google is able to bypass App Store rules that prevent apps from gathering this kind of data from iPhone users.

Apple just this morning revoked Facebook's enterprise certificate for this exact same activity, which has rendered all of Facebook's internal apps nonoperational and has created chaos at Facebook's headquarters. Facebook employees are not able to use any of the internal apps that they rely on to get work done.

The Screenwise Meter app that Google uses lets users earn gift cards for sharing their traffic and app data. It is part of Google's Cross Media Panel and Google Opinion Rewards programs that provide rewards to people for installing tracking software on their smartphones, web browsers, routers, and TVs.


According to TechCrunch, Google is more forthcoming about the kind of data that it's collecting than Facebook, but that doesn't change the fact that Google is using an app installation method that appears to violate Apple's enterprise certificate rules in the same way the Facebook Research app did.

Additionally, people who install these kinds of apps for rewards may not fully understand the extent of the data that's collected.
Putting the not-insignificant issues of privacy aside -- in short, many people lured by financial rewards may not fully take in what it means to have a company fully monitoring all your screen-based activity -- and the implications of what extent tech businesses are willing to go to to amass more data about users to get an edge on competitors, Google Screenwise Meter for iOS appears to violate Apple's policy.
Apple and Google have not yet commented on the Screenwise Meter app, but if Apple does decide that Google is also violating its enterprise rules, which clearly state that the enterprise program is for distributing internal employee apps only, Google too could see the enterprise certificate used for the Screenwise app revoked.

Apple could also punish Google in the same way that it punished Facebook by revoking all of the company's internal apps that use the same certificate.

Tag: Google

This article, "Google Also Exploiting Enterprise Certificates to Bypass iOS App Store for Data Collection" first appeared on MacRumors.com

Discuss this article in our forums



from MacRumors: Mac News and Rumors - All Stories http://bit.ly/2GdvvTZ

No comments:

Post a Comment

Leave your thoughts....