Live data from Hacker News

Virtual Keyboard Developer Leaked 31M Client Records

mackeepersecurity.com

1–10 of 77 posts

Re: Virtual Keyboard Developer Leaked 31M Client Records

#2
Note: This story was co-published with ZDNet. I know "MacKeeper" is not a brand loved by all, but I chose to link the version from the MacKeeper Security blog rather than ZDNet, because of how the latter blasts users with an autoplay video: http://www.zdnet.com/article/popular-virtual-keyboard-leaks-...

Re: Virtual Keyboard Developer Leaked 31M Client Records

#5
>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet?

I have a suspicion that due to how cheap bulk storage is these days, that companies collect as much information as they can get away with in hopes that _maybe_ it will be useful one day. That mixed with poor security practices is just going to keep leading to these sorts of events happening.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#6
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

I thought most keyboards at least ask for Full Access, though may not necessarily mandate it:

https://techcrunch.com/2014/10/04/everything-you-need-to-kno...

I was never sure what "Full Access" meant, other than keyboard data (including keystroke recording if the dev wanted it) going forward. But surely it doesn't mean everything, as in access to keyboard-non-related data (user photos, etc).?

Re: Virtual Keyboard Developer Leaked 31M Client Records

#7
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

This is why I'm a believer in this type of regulation - you have two options:

1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some small to moderate fines, depending on each case.

2) Collect whatever you want (while still mentioning it in your Privacy Policy, and the whole thing). But if you suffer a data breach, and that data is exposed, you should need a big fat banking account to survive the fine that will be imposed on you. The fines should be big enough that they should deter even the big players from collecting too much of the data they don't need.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#8
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

"all keyboard data". for a keyboard app? seems right on point. why wouldn't it want it?

Re: Virtual Keyboard Developer Leaked 31M Client Records

#9
post #6
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

I thought most keyboards at least ask for Full Access, though may not necessarily mandate it: https://techcrunch.com/2014/10/04/everything-you-need-to-kno... I was never sure what "Full Access" meant, other than keyboard data (including keystroke recording if the dev wanted it) going forward. But surely it doesn't mean everything , as in access to keyboard-non-related data (user photos, etc).?

The documentation for that is here:

https://developer.apple.com/library/content/documentation/Ge...

The gist of it is that requesting "full access" allows them to access the internet and some other bits automatically, but they need to ask for further permissions for photos, location, contacts, etc.

Re: Virtual Keyboard Developer Leaked 31M Client Records

#10
post #7
post #5

>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet? I have a suspicion that due to how cheap bulk storage is these days, that companies collect…

This is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some sma…

Absolutely. Good regulation is that which effectively disincentivises anti-consumer behavior. Businesses are playing risk/reward games all the time, and regulation should just pile on some huge extra risk in places where it's needed to protect consumers, and the health of the market as a whole.
Post reply on HN