Positioning 36,965,438+0 times a day, once every 23 seconds. How crazy is data leakage?

On May 22nd, 20021year, the National Network Information Office notified a number of apps that illegally collected and used users' personal information, including AutoExpress, Tik Tok, 360 browser and LinkedIn. On July 2, the Network Security Review Office issued an announcement on launching a network security review for Didi Chuxing. The announcement shows that Didi Chuxing stopped registering new users during the review period.

This kind of briefing began at the party on March, 20 1915. Since then, there will be a special topic on how the App abuses personal information and privacy at the 3 15 party every year. In the past two years, the inspection has been strengthened and the analysis method has become more detailed. Of course, big Internet companies should be cautious, but why are they so eager to collect users' personal information?

The reason why App gets user rights.

In June 5438+10, Xiaomi published a set of data collected on the MIUI system, which is the number of times that various apps obtained various permissions. Among them, the most exaggerated is the positioning data. On average, each Xiaomi mobile phone will be located 369 1 time by various apps every day, which means it will be located once every 23 seconds on average. The second place is the right to access the photo album, with an average of 2432 visits per mobile phone every day. The App tried to start quietly in the background and encountered 783 times a day. In addition, about 400,000 applications can read the user's clipboard.

In order for the App to work normally, of course, you have to get some permissions. For example, live broadcast software should have permission to use cameras and microphones, and take-out and map navigation should have permission to locate. But the reality is that a music listening software, a reading software, or just an LED flashlight all applied for several permissions when installing. The most common combination is the collection and use of location information+address book+photo album (storage)+device identification information. This is more difficult for ordinary people to understand.

But in fact, a lot of personal privacy can be analyzed by leaving only one location information, and then users can be classified by various tags. When a user is tagged with hundreds of tags, a portrait of the user will be generated in the system, and the core function of the user portrait is to accurately place advertisements. Advertising is the most important income of internet companies, so even if you can't collect your specific information, try to guess your activity habits, daily life, eating habits, height and weight, health status and so on.

How is the user portrait drawn?

For example, if there is only location information, the location where the user repeatedly appears from 9 am to 6 pm is probably where he works. Relatively speaking, the place where he often appears from 9 pm to 7 am is his residence. The distance this user commutes to and from work every day is the commuting route. Well, this information alone is enough to analyze a lot.

First of all, if he changes his residence every year, he is probably a migrant worker who rents a house, and then according to the average price of the rented community, we can know whether this person's economic situation is improving or declining. If he hasn't changed in a few years, he is probably a local.

The consumption habits of local people and migrant workers are different. Obviously, Sony's 60-inch large-screen TV is unlikely to be bought by migrant workers, because this move cannot be taken away. For computers, migrant workers tend to buy notebooks instead of desktops. If the migrant workers live in a better neighborhood, they can recommend better notebook advertisements, even real estate advertisements. Maybe he has saved enough down payment.

In addition, for example, after 6 pm every day, users will go to a kindergarten and a primary school, which are of course children who go to school. If you go to hospitals and nursing homes regularly, there may be patients at home. The goods that these two kinds of people need are very different. One may be various interest classes and online English training, and the other may be medical care, loans, housing sales and other services. From the commuting route and time, we can also see whether this person takes the subway or the bus, or drives himself or drips. Therefore, advertisements for auto insurance and commercial advertisements for car maintenance should not be pushed to people who never drive by themselves. Do you think this information is valuable? Of course, the price of advertisements pushed by accurate people can be dozens of times and hundreds of times higher than the price of casting nets all over the sky.

So when it comes to this, you can understand why a clean LED flashlight App that doesn't even have advertising function is trying to take away your location information. It may not be designed to directly advertise to you, but it can sell data.

How valuable is personal information?

On 20/KOLOC-0/5, there was an App called Koala Credit Information, which was registered by the central bank. It can carry out corporate credit information and personal credit information business, and then it was investigated and punished for selling personal information on 20/KOLOC-0/8. In three years, he made an illegal profit of 38 million by selling personal information. Therefore, this is why almost all apps are collecting our location information, address book and photo album access rights in various ways. These things are valuable for your own use, even if they are not for takeaway. The bigger the App, the more eager it is for these data, so even if the network office repeatedly warns and publicizes, the effect is not obvious.

Interestingly, some manufacturers will perform very well abroad because the punishment abroad is more severe. For example, the European Union has the General Data Protection Regulations, and the amount of corporate fines violated is 20 million euros, or 4% of the global annual turnover, whichever is the highest. As we often encounter, we registered a house viewing software in the morning and the real estate agent called in the afternoon. The next day, I don't know where the loan platform came from, and even the owner of the stock WeChat group called to join you. This kind of thing won't happen. Otherwise, the App that looks at the house in the second year will disappear because of the huge fine.

If it is difficult to clarify the ownership of resources related to a person's food, clothing, housing and transportation, eating and drinking Lazarus, then those more intangible personal information and privacy are even more unclear. Generally speaking, even the infringed party will not feel the need for heavy punishment. This is also the fundamental reason why every mobile phone locates 369 1 time today.