A new analysis of Facebook’s virtual private network (VPN) service Protect has revealed the social networking giant may be using the supposed privacy tool to collect more data from its user base.
Security researcher Will Strafach dove into the code behind the Protect VPN app for iPhone and discovered the service sends a significant amount of data back to Facebook that provides the company with insight into how users are making use of the application.
According to the security expert, Protect VPN—developed by Onavo, which was acquired by Facebook in 2013—uses a “Packet Tunnel Provider” app extension that runs as long as the VPN is connected. This packet tunnel is used to periodically send certain information about app usage to Facebook.
Among the information collected and provided to Facebook:
- When user’s device screen is turned on and turned off
- Total daily Wi-Fi data usage
- Total daily cellular data usage
- Periodic update indicating how long the VPN has been connected
The application also gathers information about the device it is running on and provides that to Facebook. That information includes cellular carrier name, mobile network code, mobile country code, location, language and version of the device’s operating system.
Perhaps most troubling about the data collection identified by Strafach is the fact that Protect VPN gathers some information even when the application itself is turned off.
The security researcher also noted in his research that it was initially difficult to determine what information Protect VPN was collecting and transmitting, as the data uploads appear to occur inside the VPN’s packet tunnel, meaning the data being sent to Facebook is encrypted.
While the data being sent to Facebook may not seem particularly intrusive, even small packets of data can contain revealing or potentially identifying information and especially when paired with some of the unique device identifiers also collected by the app.
More at: http://www.ibtimes.com/facebook-prot...r-data-2660278
Site Information
About Us
- RonPaulForums.com is an independent grassroots outfit not officially connected to Ron Paul but dedicated to his mission. For more information see our Mission Statement.
Connect With Us