Live data from Hacker News

Apps sending users’ data to Facebook without their consent

irishtimes.com

11–20 of 26 posts

Re: Apps sending users’ data to Facebook without their consent

#11
Apple needs to ban these SDKs from being included in apps. No one reads the privacy policies and they leak data to another party that the user doesn't have a relationship with.

Provide first party services, intermediate between apps and ad networks and/or white list a handful of companies to provide these services that are audited and have separate contractual relationships with Apple.

I think a good idea would be to stipulate to Facebook, Google, and every purveyor of "analytics" SDKs that they need to serve iOS app developers and their users from EU subsidiaries that are subject to GDPR.

Re: Apps sending users’ data to Facebook without their consent

#12
post #7

So let's see here. There are apps that people download which, in a way, replicate themselves by enticing other people to download them often using some form of psychological engineering. These apps then compromise the person's data by streaming it to a server. The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no?

The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no?

I think that's a pretty profound way to look at it, but under a broader rubric -- perhaps "User-friendly malware" would be a better euphemism. It's also an ideal way to describe things like Windows Update.

It's easy to imagine some of history's most notorious virus authors going straight, working for Facebook and Microsoft. More money, more respect, and the retirement plan beats going to prison.

Re: Apps sending users’ data to Facebook without their consent

#13

Apple needs to ban these SDKs from being included in apps. No one reads the privacy policies and they leak data to another party that the user doesn't have a relationship with. Provide first party services, intermediate between apps and ad networks and/or white list a handful of companies to provide these services that are audited and have separate contractual relationships with Apple. I think a good idea would be to…

The article doesn’t mention Apple. Do these apps also do this on iOS?

Re: Apps sending users’ data to Facebook without their consent

#14
post #7

So let's see here. There are apps that people download which, in a way, replicate themselves by enticing other people to download them often using some form of psychological engineering. These apps then compromise the person's data by streaming it to a server. The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no?

> The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no?

Malware for sure. Like phishing: "fraudulent attempt to obtain sensitive information ..... by disguising as a trustworthy entity in an electronic communication."[0]

[0] https://en.wikipedia.org/wiki/Phishing

Re: Apps sending users’ data to Facebook without their consent

#15

When do we expect the first GDPR challenges to land on Facebook? The law was clearly designed to deal with them. They continue to violate its principles. GDPR delivered tremendous collateral damage to raise these gates. But where is the pay-off? Is there preliminary footwork deploying? Or is Europe distracted by Italy et al ?

Facebook tries to offload the responsibility to developers. This is shady at best and I hope the law catch up.

But there is also the problem of developers that just don't care. Or, developers that think they care but can't even be bothered to research what a library they include in an application actually does. This is is something that the death of facebook will not solve.

GDPR has already been paid off, every day for every user both in the online and offline world is a victory, and examples of it was shown in the talk as well. How GDPR pushed developers to discover this issue and demand solutions for their own apps. How facebook improved the ability for developers to be privacy conscious etc. (hardly by choice, but even they didn't think they could get away with less)

Re: Apps sending users’ data to Facebook without their consent

#16
post #13

Apple needs to ban these SDKs from being included in apps. No one reads the privacy policies and they leak data to another party that the user doesn't have a relationship with. Provide first party services, intermediate between apps and ad networks and/or white list a handful of companies to provide these services that are audited and have separate contractual relationships with Apple. I think a good idea would be to…

The article doesn’t mention Apple. Do these apps also do this on iOS?

Many iOS apps connect to graph.facebook.com without asking.

Re: Apps sending users’ data to Facebook without their consent

#17
post #6
post #3

Simple question: We have firewall capability on every computer. I am surprised that we don't have a FW on a phone - or an app that can be installed which I can force all traffic from the phone to pass through, with source-app and destination IP/App/Service - and choose to block the traffic we would like. Are the devices capable of this?

Check out NetGuard: https://f-droid.org/en/packages/eu.faircode.netguard/

Too bad it works by creating a local VPN - I'm already using "Block This!" to block ads on my device which also works via a VPN, so you can't use both at the same time.

Re: Apps sending users’ data to Facebook without their consent

#18
post #13

Apple needs to ban these SDKs from being included in apps. No one reads the privacy policies and they leak data to another party that the user doesn't have a relationship with. Provide first party services, intermediate between apps and ad networks and/or white list a handful of companies to provide these services that are audited and have separate contractual relationships with Apple. I think a good idea would be to…

The article doesn’t mention Apple. Do these apps also do this on iOS?

Apple has a policy that apps (and their SDKs) must comply with IDFA, so if a user doesn't want to be tracked across the apps they use they can go to settings -> privacy -> advertising to turn off the tracking.

Re: Apps sending users’ data to Facebook without their consent

#19
post #7

So let's see here. There are apps that people download which, in a way, replicate themselves by enticing other people to download them often using some form of psychological engineering. These apps then compromise the person's data by streaming it to a server. The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no?

The word "app" is frequently used, but these sound more like computer viruses with a friendly UI, no? I think that's a pretty profound way to look at it, but under a broader rubric -- perhaps "User-friendly malware" would be a better euphemism. It's also an ideal way to describe things like Windows Update. It's easy to imagine some of history's most notorious virus authors going straight, working for Facebook and Mic…

The established name for this sort of "phishing" malware is "Trojan horse malware" https://en.wikipedia.org/wiki/Trojan_horse_(computing) - a malicious computer program which is designed to appear non-suspicious and mislead users wrt. its malicious activity. The irony is that the complex "app-specific privileges and permissions" system featured on mobile OSs was specifically intended to prevent mobile "apps" being used as dangerous trojan-horses, as was - to a lesser extent - the model of centralized "app store" repositories. It's not working very well.

In this case, we're specifically dealing with spyware - a common sort of malware where the malicious activity is invading the user's privacy.

Re: Apps sending users’ data to Facebook without their consent

#20

When do we expect the first GDPR challenges to land on Facebook? The law was clearly designed to deal with them. They continue to violate its principles. GDPR delivered tremendous collateral damage to raise these gates. But where is the pay-off? Is there preliminary footwork deploying? Or is Europe distracted by Italy et al ?

Yes, Facebook and Google were sued almost immediately by activists after GDPR went into effect [1][2]. Those test cases will take time to play out.

[1] https://www.theregister.co.uk/2018/05/25/schrems_is_back_fac...

[2] https://www.ft.com/content/86d1ce50-3799-11e8-8eee-e06bde01c...

Post reply on HN