These ad blockers and VPNs are spying on you: What to do (2024)

These ad blockers and VPNs are spying on you: What to do (1)

Some widely used best VPN, ad-blocking and utility apps for Android and iOS are secretly collecting user data, BuzzFeed News has found.

The apps, including Luna VPN, Adblock Focus, Mobile Data and Free and Unlimited VPN, were all created by Sensor Tower, a San Francisco data-analytics firm that, according to its website, helps app developers "understand the mobile ecosystem and maximize the potential of mobile advertising in order to efficiently generate quality, high-value users."

  • The best free VPN services: What you can get for (almost) nothing
  • Why you should avoid free Android VPNs
  • Minority Report-like tech could predict mass shootings — but should we use it?

If you install one of these apps on iOS or Android, BuzzFeed News said, the app will add a cryptographic root certificate that, in our understanding, would let it stage a man-in-the-middle attack on encrypted communications. The Sensor Tower app would be able to read all or most of the phone's network traffic.

"Your typical user is going to go through this and think, Oh, I'm blocking ads, and not really be aware of how invasive this could be," Malwarebytes threat analyst Armando Orozco told BuzzFeed News.

What you need to do

Apple has removed Adblock Focus from the App Store, but Luna VPN is still there. The Android version of Adblock Focus was still in the Google Play Store at the time of this writing, along with Luna VPN, Mobile Data and Free and Unlimited VPN. BuzzFeed did not name any other Sensor Tower-associated apps.

These ad blockers and VPNs are spying on you: What to do (2)

If you have one of these apps installed, you should obviously remove it. Our general advice is to not use any VPN mobile app that offers totally free, unlimited service, because it's got to make money some other way, and the quickest is by collecting and selling user behavioural patterns. As the old adage goes, if you're not the customer, then you're the product.

BuzzFeed News said Sensor Tower had created at least 20 smartphone apps with at least 35 million downloads since 2015. An Apple spokesperson told BuzzFeed News that several other apps associated with Sensor Tower had earlier been removed from the App Store, but didn't name them.

Sign up to get the BEST of Tom’s Guide direct to your inbox.

Upgrade your life with a daily dose of the biggest tech news, lifestyle hacks and our curated analysis. Be the first to know about cutting-edge gadgets and the hottest deals.

Breaking the rules

Perhaps surprisingly, a Sensor Tower representative confirmed the apps' hidden abilities, but insisted that all user data fed to Sensor Tower's clients was aggregated and anonymized so that individual users might not be identified.

That might not be enough to keep the apps in the Google Play and Apple App stores. Installing a root certificate would likely violate both stores' terms of use.

Sensor Tower allegedly got past Apple and Google's app screeners by not putting the root certificate in the versions of the apps that users download from the stores. Instead, users are apparently tricked into installing the root certificates after installation.

BuzzFeed News showed how a pop-up window in the Luna VPN iOS app offered to block ads in YouTube; if the user clicked "OK," the app would install the root certificate.

Hiding the apps' true origins

None of the apps mention Sensor Tower in their descriptions in the Android or iOS app stores. Luna VPN's developer is listed as Emban Networks; Adblock Focus by Orbital Software, Inc.; and Mobile Data and Free and Unlimited VPN by Gibli Mobile. Each of these were the only apps associated with those developers.

Both Apple and Google require that all developers have a website to which an app's listing can link to, and all three of these companies presented bare-bones websites, although some of the websites' names didn't match what was listed in the app stores.

BuzzFeed News didn't list any other apps created by Sensor Tower, and we weren't able to tell whether the company had any other apps in either the iOS or Android app stores. However, the Adblock Focus and Luna VPN apps use a lot of the same imagery.

These ad blockers and VPNs are spying on you: What to do (3)

Speaking with BuzzFeed News, Sensor Tower's Randy Nelson defended his company's decision to hide its role in creating and distributing these apps.

"When you consider the relationship between these types of apps and an analytics company, it makes a lot of sense," Nelson told BuzzFeed News.

These ad blockers and VPNs are spying on you: What to do (4)

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

More about vpns

Is your VPN keeping you safe for the future?5 VPN red flags to help you spot a dodgy VPN

Latest

Michael B. Jordan offers 'I Am Legend 2' update — but it's not good news
See more latest►

No comments yetComment from the forums

    Most Popular
    Lululemon's ShowZero golf polos can prevent sweat marks — here's how it works
    How to watch Swiatek vs Gauff live stream — French Open semi-final start time, TV channel
    Apple’s been hiding a Thread radio in iPad Pro 2024, MacBook Pro M3 and more — here’s why that’s a big deal
    How to mirror your iPhone, iPad or Mac to Fire TV
    5 best queer movies from the '80s to watch during Pride Month
    5 best shows like 'Peaky Blinders' to stream right now
    watchOS 11 — everything we know so far about the next Apple Watch update
    NYT Strands today — hints, spangram and answers for game #95 (Thursday, June 6 2024)
    7 new to Prime Video movies with 90% or higher on Rotten Tomatoes
    Samsung just expanded its Micro-LED TV lineup — starting at $110,000
    iPhone 16 and iPhone 16 Pro design — 5 biggest rumors for the new iPhones
    These ad blockers and VPNs are spying on you: What to do (2024)

    References

    Top Articles
    Latest Posts
    Article information

    Author: Msgr. Benton Quitzon

    Last Updated:

    Views: 6246

    Rating: 4.2 / 5 (43 voted)

    Reviews: 82% of readers found this page helpful

    Author information

    Name: Msgr. Benton Quitzon

    Birthday: 2001-08-13

    Address: 96487 Kris Cliff, Teresiafurt, WI 95201

    Phone: +9418513585781

    Job: Senior Designer

    Hobby: Calligraphy, Rowing, Vacation, Geocaching, Web surfing, Electronics, Electronics

    Introduction: My name is Msgr. Benton Quitzon, I am a comfortable, charming, thankful, happy, adventurous, handsome, precious person who loves writing and wants to share my knowledge and understanding with you.