These ad blockers and VPNs are spying on you: What to do (2024)

These ad blockers and VPNs are spying on you: What to do (1)

Some widely used best VPN, ad-blocking and utility apps for Android and iOS are secretly collecting user data, BuzzFeed News has found.

The apps, including Luna VPN, Adblock Focus, Mobile Data and Free and Unlimited VPN, were all created by Sensor Tower, a San Francisco data-analytics firm that, according to its website, helps app developers "understand the mobile ecosystem and maximize the potential of mobile advertising in order to efficiently generate quality, high-value users."

  • The best free VPN services: What you can get for (almost) nothing
  • Why you should avoid free Android VPNs
  • Minority Report-like tech could predict mass shootings — but should we use it?

If you install one of these apps on iOS or Android, BuzzFeed News said, the app will add a cryptographic root certificate that, in our understanding, would let it stage a man-in-the-middle attack on encrypted communications. The Sensor Tower app would be able to read all or most of the phone's network traffic.

"Your typical user is going to go through this and think, Oh, I'm blocking ads, and not really be aware of how invasive this could be," Malwarebytes threat analyst Armando Orozco told BuzzFeed News.

What you need to do

Apple has removed Adblock Focus from the App Store, but Luna VPN is still there. The Android version of Adblock Focus was still in the Google Play Store at the time of this writing, along with Luna VPN, Mobile Data and Free and Unlimited VPN. BuzzFeed did not name any other Sensor Tower-associated apps.

These ad blockers and VPNs are spying on you: What to do (2)

If you have one of these apps installed, you should obviously remove it. Our general advice is to not use any VPN mobile app that offers totally free, unlimited service, because it's got to make money some other way, and the quickest is by collecting and selling user behavioural patterns. As the old adage goes, if you're not the customer, then you're the product.

BuzzFeed News said Sensor Tower had created at least 20 smartphone apps with at least 35 million downloads since 2015. An Apple spokesperson told BuzzFeed News that several other apps associated with Sensor Tower had earlier been removed from the App Store, but didn't name them.

Sign up to get the BEST of Tom’s Guide direct to your inbox.

Upgrade your life with a daily dose of the biggest tech news, lifestyle hacks and our curated analysis. Be the first to know about cutting-edge gadgets and the hottest deals.

Breaking the rules

Perhaps surprisingly, a Sensor Tower representative confirmed the apps' hidden abilities, but insisted that all user data fed to Sensor Tower's clients was aggregated and anonymized so that individual users might not be identified.

That might not be enough to keep the apps in the Google Play and Apple App stores. Installing a root certificate would likely violate both stores' terms of use.

Sensor Tower allegedly got past Apple and Google's app screeners by not putting the root certificate in the versions of the apps that users download from the stores. Instead, users are apparently tricked into installing the root certificates after installation.

BuzzFeed News showed how a pop-up window in the Luna VPN iOS app offered to block ads in YouTube; if the user clicked "OK," the app would install the root certificate.

Hiding the apps' true origins

None of the apps mention Sensor Tower in their descriptions in the Android or iOS app stores. Luna VPN's developer is listed as Emban Networks; Adblock Focus by Orbital Software, Inc.; and Mobile Data and Free and Unlimited VPN by Gibli Mobile. Each of these were the only apps associated with those developers.

Both Apple and Google require that all developers have a website to which an app's listing can link to, and all three of these companies presented bare-bones websites, although some of the websites' names didn't match what was listed in the app stores.

BuzzFeed News didn't list any other apps created by Sensor Tower, and we weren't able to tell whether the company had any other apps in either the iOS or Android app stores. However, the Adblock Focus and Luna VPN apps use a lot of the same imagery.

These ad blockers and VPNs are spying on you: What to do (3)

Speaking with BuzzFeed News, Sensor Tower's Randy Nelson defended his company's decision to hide its role in creating and distributing these apps.

"When you consider the relationship between these types of apps and an analytics company, it makes a lot of sense," Nelson told BuzzFeed News.

These ad blockers and VPNs are spying on you: What to do (4)

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

More about vpns

Popular VPN disappears off the face of the EarthNordVPN vs Private Internet Access – which provider is best?

Latest

Blackmagic Camera app arrives to make Android phones into cinema-worthy cameras
See more latest►

No comments yetComment from the forums

    Most Popular
    OnePlus' new 'Glacier' battery tech promises 36 minute charging — here's how it works
    Latest 'House of the Dragon' episode features one of the best 'Game of Thrones' scenes ever — and it's not the one you think
    Popular VPN disappears off the face of the Earth
    How to watch 'Dua Lipa: My Glastonbury' online from anywhere
    'Bridgerton' season 4: Everything we know so far
    France vs Poland live stream: How to watch Euro 2024 online and for free
    Hume AI brings its creepy emotional AI chatbot to iPhone
    Will Stingray be back for 'Cobra Kai' season 6? Here's what actor Paul Walter Hauser says
    OnePlus Nord CE4 Lite could be the best value phone of the year — what you need to know
    Prime Video is losing one of the best horror thriller movies ever — stream it before it leaves this week
    Leaked iPhone 16 case video reveals new iPhone design from every angle
    These ad blockers and VPNs are spying on you: What to do (2024)
    Top Articles
    Latest Posts
    Article information

    Author: Margart Wisoky

    Last Updated:

    Views: 6057

    Rating: 4.8 / 5 (78 voted)

    Reviews: 93% of readers found this page helpful

    Author information

    Name: Margart Wisoky

    Birthday: 1993-05-13

    Address: 2113 Abernathy Knoll, New Tamerafurt, CT 66893-2169

    Phone: +25815234346805

    Job: Central Developer

    Hobby: Machining, Pottery, Rafting, Cosplaying, Jogging, Taekwondo, Scouting

    Introduction: My name is Margart Wisoky, I am a gorgeous, shiny, successful, beautiful, adventurous, excited, pleasant person who loves writing and wants to share my knowledge and understanding with you.