惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
月光博客
月光博客
博客园 - Franky
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
有赞技术团队
有赞技术团队
V
V2EX
IT之家
IT之家
阮一峰的网络日志
阮一峰的网络日志
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
腾讯CDC
D
DataBreaches.Net
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
WordPress大学
WordPress大学
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
Microsoft Security Blog
Microsoft Security Blog

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
How Uber seems to know where you are – even with restrict...
Tony Anscombe · 2025-10-09 · via WeLiveSecurity

Privacy

Is the ride-hailing app secretly tracking you? Not really, but this iOS feature may make it feel that way.

09 Oct 2025  •  , 3 min. read

How Uber seems to know where you are – even with restricted location permissions

When you land at an airport, you may be greeted with a notification on your phone that reads:

“Welcome to [your location] – Open the app to get directions to the Uber pick-up point.”

For privacy-conscious users who only allow apps to access their location while the app is in use, this can feel unsettling. How could Uber know where you are if you restricted the app to access your location only while in use?

Figure 1. Uber notification iOS

After seeing the message several times, I finally checked Uber’s permissions, certain it was set to only “while using the app” on both my personal and business phone. And indeed, Uber’s location access was set exactly as intended: “while using the app”.

And yet, both devices displayed the same notification whenever I landed, and getting this permission wrong on two devices seemed highly unlikely. (As an aside, why there are other options beyond this one is baffling. Why do any car service or food apps need to know your location when you are not actively using them – other than to track you for commercial reasons?)

Figure 2. iOS location settings

The only other reason for what some might view as a privacy infringement could be a feature called “Background App Refresh”, which allows an app to run and update its content even when you’re not using it. On the other hand, this would be against the principle of limiting location access to only while the app is in use, and it seems implausible that any app, especially on iOS, would be allowed to bypass such a fundamental privacy control.

So, how does Uber (and perhaps other apps) know where you’ve just landed?

The answer lies in a feature called “UNLocationNotificationTrigger” that Apple provides to developers. This feature allows an app to fire a pre-configured notification when the device enters or exits a specified geographic region, such as an airport. That way, it effectively circumvents the intent behind the “while using the app” setting.

So, to answer the question above directly: no, Uber or other apps don’t know your location when you land. The notification is generated locally on your phone when it detects that you’ve entered the pre-defined airport’s geofenced area.

On the other hand, the notification’s wording is misleading: it makes it feel like Uber is actively tracking you and is offering guidance. In reality, it’s only when you tap the notification and open the app that your device shares your location with the app.

There are legitimate reasons for geofencing, of course. For example, a family safety app may notify parents when their child’s device enters or exits a designated safe zone such as a school or home. Or to use another example, a smart-home app could remind you to switch off the lights when you leave the house.

However, using the same mechanism for what can only be seen as advertising is, in my opinion, an overreach. In this instance, Uber is advertising its services as soon as I am within the boundaries of the airport. Imagine walking through a high street and having every retailer’s app ping you to come inside, basically ignoring your decision to share your location only when you’re using their app.

It would seem sensible for Apple to tighten the rules around location-triggered notifications and restrict them to non-advertising purposes. This would ensure that the notifications are limited to functionality that serves the user and is not used for monetization purposes.


Let us keep you
up to date

Sign up for our newsletters