Advertising Software Development Kit (SDK): serving up more than just in-app ads and logging sensitive data. [Research Saturday]
On August 24, 2020, Snyk announced the discovery of suspicious behaviors in the iOS version of a popular advertising SDK known as Mintegral. At that time, they had confirmed with partners in the advertising attribution space that at minimum, Mintegral appeared to be using this functionality to gather large amounts of data and commit ad attribution fraud. Their research showed that Mintegral was using code obfuscation and method swizzling to modify the functionality of base iOS SDK methods without the application owner’s knowledge. Further, their research proved that Mintegral was logging all HTTP requests including its headers which could even contain authorization tokens or other sensitive data.
Since that time Mintegral announced that they were opening the source of their SDK to the market. While the SDK can only be downloaded by registered partners, a major game publisher shared the source code with Snyk for further analysis. They also continued their research by digging deeper into the Android versions of the SDK in which they hadn’t found similar behaviors at the time of the initial disclosure.
This has resulted in some significant discoveries that necessitate an update to the previous disclosure. Additionally, Mintegral and the community at large have responded to the situation, and Snyk felt a summary of the events was a good way to finalize their research into this SDK.
Joining us on Research Saturday to discuss their research is Snyk's Alyssa Miller.
The original blog and Snyk's update can be found here:
Available Results
Generated results are saved to your library for reuse and search.
Choose Template
Pick the result you want. You can review provider and model before generating.
A concise first-pass summary for understanding the episode quickly.
A comprehensive, source-grounded extraction of the reusable knowledge in an episode.
Scientific findings, mechanisms, studies, hypotheses, and the limits of the evidence discussed.
A dedicated analysis of warnings, limitations, trade-offs, weak evidence, and uncertainty.
Memorable statements and important claims with attribution and source context.
Technologies, AI models, technical methods, capabilities, limitations, and adoption implications.
A concise first-pass summary for understanding the episode quickly.
A detailed readable summary organized by chapter or topic.
A navigable map of subjects, topic flow, and suggested chapters.
A comprehensive, source-grounded extraction of the reusable knowledge in an episode.
Reusable atomic knowledge units extracted from the episode.
A comprehensive extraction focused on health practices, protocols, claims, and safety caveats.
A comprehensive extraction focused on opportunities, strategy, markets, and company building.
Explicit actions, next steps, habits, recommendations, and things to avoid.
A dedicated inventory of concrete resources named in the episode.
A dedicated analysis of warnings, limitations, trade-offs, weak evidence, and uncertainty.
A concise first-pass summary for understanding the episode quickly.
A detailed readable summary organized by chapter or topic.
A navigable map of subjects, topic flow, and suggested chapters.
A comprehensive, source-grounded extraction of the reusable knowledge in an episode.
Reusable atomic knowledge units extracted from the episode.
A comprehensive extraction focused on health practices, protocols, claims, and safety caveats.
A comprehensive extraction focused on opportunities, strategy, markets, and company building.
Scientific findings, mechanisms, studies, hypotheses, and the limits of the evidence discussed.
Technologies, AI models, technical methods, capabilities, limitations, and adoption implications.
Investment theses, assets, catalysts, valuation reasoning, time horizons, and risks.
Chronologies, actors, causes, consequences, turning points, and competing historical interpretations.
Policies, proposals, stakeholders, arguments, implementation constraints, and predicted effects.
Career paths, skills, hiring signals, workplace decisions, transitions, and limitations of the advice.
Behavioral mechanisms, biases, motivation, habits, emotions, interventions, and evidence limitations.
Economic mechanisms, incentives, indicators, market structure, forecasts, and uncertainty.
Leadership principles, team systems, organizational design, culture, feedback, and failure modes.
Audience, positioning, messaging, acquisition, retention, experiments, metrics, and failed approaches.
Teaching methods, learning strategies, practice, feedback, assessment, and effectiveness evidence.
Theses, premises, arguments, objections, values, thought experiments, and unresolved questions.
Communication patterns, conflict, boundaries, expectations, repair methods, and contextual limitations.
Books, papers, authors, courses, and other learning resources mentioned in the episode.
Repeatable methods, frameworks, mental models, processes, and systems.
Explicit actions, next steps, habits, recommendations, and things to avoid.
Memorable statements and important claims with attribution and source context.
A dedicated inventory of concrete resources named in the episode.
A dedicated analysis of warnings, limitations, trade-offs, weak evidence, and uncertainty.