Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy

Report: Apps Give Facebook Sensitive Health and Other Data

Several phone apps are sending sensitive user data, including health information, to Facebook without users’ consent, according to a report by The Wall Street Journal.

An analytics tool called “App Events” allows app developers to record user activity and report it back to Facebook, even if the user isn’t on Facebook, according to the report .

Several phone apps are sending sensitive user data, including health information, to Facebook without users’ consent, according to a report by The Wall Street Journal.

An analytics tool called “App Events” allows app developers to record user activity and report it back to Facebook, even if the user isn’t on Facebook, according to the report .

One example detailed by the Journal shows how a woman would track her period and ovulation using an app from Flo Health. After she enters when she last had her period, Facebook software in the app would send along data, such as whether the user may be ovulating. The Journal’s testing found that the data was sent with an advertising ID that can be matched to a device or profile.

Although Facebook’s terms instruct app developers not to send such sensitive information, Facebook appeared to be accepting such data without telling the developers to stop. Developers are able to use such data to target their own users while on Facebook.

Facebook said in a statement that it requires apps to tell users what information is shared with Facebook and it “prohibits app developers from sending us sensitive data.” The company said it works to remove information that developers should not have sent to Facebook.

The development comes as Facebook is dealing with increased scrutiny over how it handles user data. Last week, British lawmakers issued a scathing report calling for tougher privacy rules for Facebook and other tech firms.

Criticisms over privacy intensified nearly a year ago following revelations that the now-defunct Cambridge Analytica data-mining firm accessed data on some 87 million Facebook users without their consent. The U.S. Federal Trade Commission has been investigating that flap as well and is reportedly in negotiations with Facebook over a multibillion dollar fine.

The data-sharing is related to a data analytics tool that Facebook offers developers. The tool lets developers see statistics about their users and target them with Facebook ads.

Advertisement. Scroll to continue reading.

Besides Flo Health, the Journal found that Instant Heart Rate: HR Monitor and real-estate app Realtor.com were also sending app data to Facebook. The Journal found that the apps did not provide users any way to stop the data-sharing.

Flo Health said in an emailed statement that using analytical systems is a “common practice” for all app developers and that it uses Facebook analytics for “internal analytics purposes only.” But the company plans to audit its analytics tools to be “as proactive as possible” on privacy concerns.

Hours after the Journal story was published, New York Gov. Andrew Cuomo directed the state’s Department of State and Department of Financial Services to “immediately investigate” what he calls a clear invasion of consumer privacy. The Democrat also urged federal regulators to step in to end the practice.

Securosis CEO Rich Mogull said that while it is not good for Facebook to have yet another data privacy flap in the headlines, “In this case it looks like the main violators were the companies that wrote those applications,” he said. “Facebook in this case is more the enabler than the bad actor.”

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Application Security

Open banking can be described as a perfect storm for cybersecurity. At one end, small startups with financial acumen but little or no security...

Government

The proposed UK Online Safety Bill is the enactment of two long held government desires: the removal of harmful internet content, and visibility into...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...

Cloud Security

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.