Will Strafach is best known for being an early and frequent jailbreaker of Apple’s iOS operating system for iPhones and iPads. But Strafach has always aimed for the white-hat side of the hacking ethical divide. He’s in favor of people having more control of what apps they use–and receiving better disclosure about where information on their phones winds up.
Many privacy organizations have raised red flags about unwanted, if not quite illegal, leakage of location information, online behavior, and other personal details from smartphone apps. A New York Times report in December focused on location data being shared with third-party organizations and tied to specific users; in February, a Wall Street Journal investigation reported that app makers were sharing events as intimate as ovulation cycles and weight with Facebook. But no matter how alarmed you are by such scenarios, there hasn’t been much you could do. Mobile operating systems don’t let you monitor your network connection and block specific bits of data from leaving your phone.

That led Strafach and his colleagues at Sudo Security Group aim to take practical action. “We are aware of almost every active tracker that is in the App Store,” he says. Building on years of research, Sudo is putting the finishing touches on an iPhone app called Guardian Mobile Firewall, a product that combines a virtual private network (VPN) connection with a sophisticated custom firewall managed by Sudo.
It looks like Guardian will be the first commercial entry into a fresh category of apps and services that look not only just for malicious behavior, but also what analysis shows could be data about you leaving your phone without your explicit permission. It will identify and variably block all kinds of leakage, based on Sudo’s unique analysis of App Store apps.
Sudo is taking preorders for the app in the Apple Store and plans a full launch no later than June. It will debut on iOS, and required some lengthy conversations with Apple’s app reviewers as Sudo laid out precisely what part of its filtering happens in the app (none of it) and what happens at its cloud-based firewall (everything). The price will be in the range of a high-end, unlimited VPN—about $8 or $9 a month. Sudo plans an expanded beta program in April, followed by a production release that will be automatically delivered to preorder customers.
Trackers in your apps
Some app developers do make an affirmative effort, in statements and actions, to avoid including any tracking elements that aren’t necessary and fully disclosed, such as Marco Arment’s Overcast podcast app. Arment even blocks images that provide tracking data in podcast show notes.
On the flip side, other apps intentionally and underhandedly track your location and other private details—and when discovered by mobile OS makers or researchers, tend to get knocked out of app stores, often permanently. Adware Doctor was dumped by Apple after a noted iOS security guru Patrick Wardle found it engaged in a variety of undisclosed and guideline-breaking data extraction. Embarrassingly, Facebook pulled its own security app, Onavo, from Apple’s App Store (but not Google Play) after Apple required it obtain affirmative consent for tracking. (Facebook re-released it quietly by violating Apple’s terms for distributing apps to company employees and contractors and was found out.)
