chadcjx
V2EX  ›  iOS

iOS 的 App Store 上有超过 250 个 apps 会窃取用户个人信息,因为用了第三方的 SDK

  •  
  •   chadcjx · Oct 20, 2015 · 4243 views
    This topic created in 3863 days ago, the information mentioned may be changed or developed.

    原文链接: http://arstechnica.com/security/2015/10/researchers-find-256-ios-apps-that-collect-users-personal-info/

    第三方 SDK 应该是 有米的广告 SDK 。 -> https://www.youmi.net

    SourceDNA researchers found four major classes of information gathered by apps that use the Youmi ad SDK. They include:

    A list of all apps installed on the phone

    The platform serial number of iPhones or iPads themselves when they run older versions of iOS
    A list of hardware components on devices running newer versions of iOS and the serial numbers of these components, and
    The e-mail address associated with the user ’ s Apple ID

    16 replies    2015-10-20 10:43:18 +08:00
    egen
        1
    egen  
       Oct 20, 2015 via iPad
    如果是有米的 sdk , app 数量应该远远超过 250 个
    holong2000
        2
    holong2000  
       Oct 20, 2015
    防不胜防啊
    nashsu
        3
    nashsu  
       Oct 20, 2015
    > SourceDNA researchers found four major classes of information gathered by apps that use the Youmi ad SDK. They include:

    > 1. A list of all apps installed on the phone
    > 2. The platform serial number of iPhones or iPads themselves when they run older versions of iOS
    > 3. A list of hardware components on devices running newer versions of iOS and the serial numbers of these components, and
    > 4. The e-mail address associated with the user ’ s Apple ID


    如果是这些信息,那么似乎国内几乎每个 App 都会上传吧....
    taresky
        4
    taresky  
       Oct 20, 2015 via iPhone   ❤️ 2
    DOMAIN-SUFFIX,youmi.net,REJECT


    果然我有这条,先见之明哈哈哈。
    actuallymax
        5
    actuallymax  
       Oct 20, 2015
    @taresky 求个完整的 reject 列表
    GPU
        7
    GPU  
       Oct 20, 2015
    @afterain 还不能用 。 TF 满了。
    evanlyu
        9
    evanlyu  
       Oct 20, 2015
    @taresky 这是啥意思,求解释,要屏蔽某个地址? 需要什么软件或设备啊
    laoyur
        10
    laoyur  
       Oct 20, 2015
    > 4. The e-mail address associated with the user ’ s Apple ID
    这条很感兴趣,不知道对应的 API 是哪个(当然是指动态调用方式)
    zander
        11
    zander  
       Oct 20, 2015 via iPhone
    安全邮箱也有了, apple id 也有了,碰撞一下就能把设备锁上。 apple 还是强制所有人开两步验证吧。
    chadcjx
        12
    chadcjx  
    OP
       Oct 20, 2015
    @egen 不知道安卓平台上会有多么的肆无忌惮?
    justtoxic
        13
    justtoxic  
       Oct 20, 2015 via iPad
    @humiaozuzu 你这没有规则有什么用,要的是那个 reject
    justtoxic
        14
    justtoxic  
       Oct 20, 2015 via iPad
    @humiaozuzu 抱歉,没看全,点开链接才发现了
    taresky
        15
    taresky  
       Oct 20, 2015
    @humiaozuzu 好多啊,谢谢。
    g67261831
        16
    g67261831  
       Oct 20, 2015
    @taresky Surge ?唉。。还没上架。。。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   3691 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 67ms · UTC 04:49 · PVG 12:49 · LAX 21:49 · JFK 00:49
    ♥ Do have faith in what you're doing.