Uploaded February 2019 | Updated September 2026, 1 week ago
Websites, apps, and even your desktop applications may be tracking a how lot more of your behaviour than you think. The reason in most cases is simply to deliver a better application from a technical perspective. But sometimes, it's more insidious.
The Wall Street Journal recently called out a few applications for sending sensitive information to Facebook without their users being aware. Facebooks App Events service is geared around building advertising profiles but what about other popular telemetry services like Hockeyapp.net from MIcrosoft, Apple's TestFlight, Google Analytics, just to name a few.
How should developers balance the need to support their creations with user awareness of telemetry and user privacy?
References;
- original call out by the Wall Street Journal, wsj.com/articles/you-give-apps-sensitive-personal-information-then-they-tell-facebook-11550851636?mod=article_inline
- follow-up by the WSJ, wsj.com/articles/eleven-popular-apps-that-shared-data-with-facebook-11551055132?mod=searchresults&page=1&pos=4
- details on Facebook's App Events, developers.facebook.com/docs/app-events
- Apple's TestFlight, developer.apple.com/testflight
- Microsoft's HockeyApp, azure.microsoft.com/en-ca/services/hockeyapp
- Google Analytics as a local telemetry service, developers.google.com/analytics/devguides/reporting/core/v4/quickstart/installed-py
- Little Snitch is an outbound firewall for macOS, https://www.obdev.at/products/littlesnitch/index.html
// MWM Y2 no. 015
Websites, apps, and even your desktop applications may be tracking a how lot more of your behaviour than you think. The reason in most cases is simply to deliver a better application from a technical perspective. But sometimes, it's more insidious.
The Wall Street Journal recently called out a few applications for sending sensitive information to Facebook without their users being aware. Facebooks App Events service is geared around building advertising profiles but what about other popular telemetry services like Hockeyapp.net from MIcrosoft, Apple's TestFlight, Google Analytics, just to name a few.
How should developers balance the need to support their creations with user awareness of telemetry and user privacy?
References;
- original call out by the Wall Street Journal, wsj.com/articles/you-give-apps-sensitive-personal-information-then-they-tell-facebook-11550851636?mod=article_inline
- follow-up by the WSJ, wsj.com/articles/eleven-popular-apps-that-shared-data-with-facebook-11551055132?mod=searchresults&page=1&pos=4
- details on Facebook's App Events, developers.facebook.com/docs/app-events
- Apple's TestFlight, developer.apple.com/testflight
- Microsoft's HockeyApp, azure.microsoft.com/en-ca/services/hockeyapp
- Google Analytics as a local telemetry service, developers.google.com/analytics/devguides/reporting/core/v4/quickstart/installed-py
- Little Snitch is an outbound firewall for macOS, https://www.obdev.at/products/littlesnitch/index.html
// MWM Y2 no. 015

![Do You Control the Rights to Your Face? #shorts
Biometrics are a critical tool in information security and of particular interest to cybercriminals but the biggest issues remain with how we train machine learning model and how we get that data.
A fascinating study by Raji & Fried points out that the way these data sets have been gathered has become increasingly problematic. Gone are the days of explicit consent to participate as data is simple vacuumed up from the internet.
The consent issue is huge but so are the bias and discrimination issues introduced with these methods.
Coverage of the research and inspiration for this short via Karen Hao writing for the MIT Technology Review, https://www.technologyreview.com/2021/02/05/1017388/ai-deep-learning-facial-recognition-data-history/
Index:
- The question [0:00]
- Raji & Frieds study [0:08]
- Bias & discrimination in data [0:23]
- Call to action [0:35]
#shorts Do You Control the Rights to Your Face? #shorts](https://i.ytimg.com/vi/og3ZpUagvzg/mqdefault.jpg)
![Can You Train Someone To Spot a Phishing Attack? #shorts
Phishing is a major cybersecurity problem. Most malware infections start through email and phishing sent by cybercriminals and hackers. But is the current solution worse than the problem?
We take a look in this short...
Index:
- The question [0:00]
- Phishing? [0:06]
- Stop testing [0:17]
- Educate [0:43]
#shorts Can You Train Someone To Spot a Phishing Attack? #shorts](https://i.ytimg.com/vi/owT3L5xiSEk/mqdefault.jpg)

![Stop Apps From Tracking You in iOS 14.5...Mostly #shorts
iOS 14.5 is finally here and along with some minor improvements, it introduces App Tracking Transparency (ATT). This feature requires that apps ask permission BEFORE using your devices unique identifier to track you.
Its not perfect but its a huge step forward for privacy and a big blow to Ad Tech.
Learn more in this short...
Learn more about this feature from Apple at https://youtu.be/Ihw_Al4RNno
Index:
- [0:00] iOS 14.5 is here!
- [0:08] App Tracking Transparency
- [0:16] IDFA
- [0:26] Facebook doesnt like this
- [0:39] Stop all tracking...mostly
#shorts Stop Apps From Tracking You in iOS 14.5...Mostly #shorts](https://i.ytimg.com/vi/pBmA0f5EOyM/mqdefault.jpg)
![Can We Improve How Civitas Learning Batch Processed PII in 2017? (Reaction)
In late 2017, Civitas Learning did an AWS This is My Architecture video. It was one of the first. The video walks through how they handled processing personally identifiable information at scale using batch processing.
Now, a few years later, I react to that video and see whats stood the test of time, what could be done simpler given todays technology, and generally critique the design against the AWS Well-Architected Framework in a mini AWS Well-Architected Review.
The original video: https://youtu.be/-S5gs8AGKCw
More on the AWS Well-Architected Framework is at https://aws.amazon.com/architecture/well-architected/
Follow me on Twitter at https://twitter.com/marknca
Read my AWS Hero bio at https://aws.amazon.com/developer/community/heroes/mark-nunnikhoven/
Learn more about the AWS Well-Architected Framework in my course on A Cloud Guru at https://markn.ca/courses/#mastering-the-well-architected-framework
Index:
- [00:00] Intro
- [00:40] Problem statement
- [01:30] Batch processing
- [02:26] AWS services used
- [03:36] Data isolation
- [04:42] EMR limitations
- [06:21] Predictive analytics
- [07:21] Improvements?
- [16:23] Review
- [16:55] Can we improve? Can We Improve How Civitas Learning Batch Processed PII in 2017? (Reaction)](https://i.ytimg.com/vi/q2xevUNOr5c/mqdefault.jpg)


![Do App Stores Help Your Privacy & Security? A Cybersecurity Expert Weighs in on Epic vs. Apple
Epic Games is current waging war on Apple and Google over the right to distribute apps to mobile users. Theres been a ton of excellent coverage of the issues, but its usually missing one key perspective; what do we as users get from the App Stores?
This episode if Impact Assessment looks at the cybersecurity and privacy impacts of the App Store model. Do App Store delivery do anything to improve the security of our devices? Can Apple or Google help protect our privacy? Will they?
- The question [00:00]
- Epic Games vs Apple & Google [00:26]
- Apples App Store Review Guidelines [01:53]
- Googles guidelines [05:40]
- Granting permissions [07:19]
- App Store ecosystems [09:12]
- The impact [11:10]
References:
- The Fortnite Mega Drop - Permanent Discounts Up to 20%, https://www.epicgames.com/fortnite/en-US/news/the-fortnite-mega-drop-permanent-discounts-up-to-20-percent
- Fortnite Usage and Revenue Statistics (2020) - Business of Apps, https://www.businessofapps.com/data/fortnite-statistics/
- The EPIC TRUTH About Fortnite’s WAR on APPLE - YouTube, https://www.youtube.com/watch?v=sM4QmEw6QDM
- App Store Review Guidelines - Apple Developer, https://developer.apple.com/app-store/review/guidelines/
- Children’s Online Privacy Protection Rule (“COPPA”) | Federal Trade Commission, https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule
- Apple Developer Documentation, https://developer.apple.com/documentation/uikit/protecting_the_user_s_privacy
- Privacy - Apple, https://www.apple.com/privacy/
- Developer Policy Center, https://play.google.com/about/developer-content-policy/
- Apple rips into Epic Games in a court filing about the Fortnite saga, https://thenextweb.com/apple/2020/08/21/apple-rips-into-epic-games-court-filing-about-fortnite-saga/
- Review, Refocus, and Recalibrate: The 2019 Mobile Threat Landscape - Security Roundup - Trend Micro USA, https://www.trendmicro.com/vinfo/us/security/research-and-analysis/threat-reports/roundup/review-refocus-and-recalibrate-the-2019-mobile-threat-landscape
- Unprecedented new iPhone malware discovered - Malwarebytes Labs | Malwarebytes Labs, https://blog.malwarebytes.com/mac/2019/08/unprecedented-new-iphone-malware-discovered/ Do App Stores Help Your Privacy & Security? A Cybersecurity Expert Weighs in on Epic vs. Apple](https://i.ytimg.com/vi/r0nk-Z35UCA/mqdefault.jpg)
![AWS re:Invent 2020 - Session Catalog & Hero Guide Introduction
The session catalog and Hero Guide information was just published on the official event website (https://reinvent.awsevents.com).
As with previous years, more and more sessions will be added as we get closer to the event.
Unlike previous years, theres no rush to book a seat in the sessions you want. AWS re:Invent 2020 is a free, digital event and youll be able to watch any session you want...either live or on-demand.
This years AWS Hero Guides were also announced today. They will be live sometime soon in the session catalog but in the meantime you can read about each Heros chosen topic and their approach to picking sessions that will help you get a better understand on that topic.
If you want to know more about the free, 3 week show, check out my guide post at https://acloudguru.com/blog/engineering/the-ultimate-guide-to-reinvent-2020
- Intro [00:00]
- The event website [00:13]
- AWS Hero Guides [00:23]
- The session catalog [01:44] AWS re:Invent 2020 - Session Catalog & Hero Guide Introduction](https://i.ytimg.com/vi/r1pZWTUo9lY/mqdefault.jpg)
