Earlier quoted context omitted.
Another key paragraph is this one: “This gives Air Canada employees — and anyone else capable of accessing the screenshot database — to see unencrypted credit card and password information,” he told TechCrunch. The takeaway is that some companies are capturing things that they shouldn't be storing, and the article has exposed atleast one instance where this information has been sent to a third party without masking.…
Could they lose PCI compliance then?
Many popular iPhone apps are recording user sessions without asking
61–70 of 126 posts
Re: Many popular iPhone apps are recording user sessions without asking
#62This is horrible reporting if by “record” they mean “log meta data like swipe coordinates and recreate it.” That is not the same as record.
Is there much of a practical difference here? Employees at the company can essentially watch a video-like recreation of how you went through and used their app. This includes details that you might not expect such as which email you typed into a field before backspacing and choosing another to sign up with.
I want to believe that a product owner at companies like Tinder aren't watching videos of me sexting someone to "learn how we can improve the user experience". If the response is then to say "don't use Tinder!", start considering the alternatives - you end up having to trust someone, or do nothing digitally.
Re: Many popular iPhone apps are recording user sessions without asking
#631. As the article mentions, in some cases these apps end up leaking sensitive data like credit card detail and passwords. Generally, if you are taking snapshots of the user's screen instead of sending text metrics, it becomes much harder to mask sensitive data at all times.
2. The bigger issue is that these services generally use third parties to record this, and their privacy policy is a big problem. For example, Glassbox explicitly mentions that it will share end user personal data with their "enterprise" clients (which I am guessing are basically ad companies):
> From time to time, GLASSBOX grants certain of its enterprise clients a license or other rights to GLASSBOX’s proprietary software products and solutions (the “GLASSBOX Solutions”). Through their use of these GLASSBOX Solutions and/or through other means, enterprise clients of GLASSBOX may get access to, collect and use: (i) End User non-personally identifiable information; and (ii) End User Personal Data.
> There are also times when we will combine such information with additional non-personal or de-identified information we obtain from other companies as well as End User Personal Data, in order for our enterprise clients to market directly to a certain person subject to requirements of applicable law. We typically analyze this information and organize it into user groups and audiences, based on factors such as age, gender, geography, interests and online actions. We and our enterprise clients then use these user groups and audiences, along with information about the possible relationships among different browsers and devices, to design and deliver customized advertising campaigns or other relevant content.
Re: Many popular iPhone apps are recording user sessions without asking
#64> Many major companies, like Air Canada, Hollister and Expedia, are recording every tap and swipe you make on their iPhone apps. In most cases you won’t even realize it. And they don’t need to ask for permission. The key phrases here are "recording every tap and swipe" and "on their iPhone apps". I'm not saying it is okay, but the sensationalist headline takes away from the real issue.
Also, as I recall, banks legitimately "track" user interactions as a means of fraud detection.
Re: Many popular iPhone apps are recording user sessions without asking
#65Re: Many popular iPhone apps are recording user sessions without asking
#66> Many major companies, like Air Canada, Hollister and Expedia, are recording every tap and swipe you make on their iPhone apps. In most cases you won’t even realize it. And they don’t need to ask for permission. The key phrases here are "recording every tap and swipe" and "on their iPhone apps". I'm not saying it is okay, but the sensationalist headline takes away from the real issue.
I've been seeing the same sensationalist language even in "respected" publications like the NYT lately. For example, they recently published a story where it was implied that because Spotify's Messenger plugin has standard read/write permissions (necessary to ensure basic functionality like sharing songs) that it could also actively monitor, store, and modify your private messages. In smaller publications, some shodd…
Re: Many popular iPhone apps are recording user sessions without asking
#67Ok. So what? Software and services have kept usage metrics and clickstream data for decades. They have privacy policies saying that they may collect data about how you use their product. This is that data. So, is this a surprise? If you don't want Abercrombie to know which items you looked at, don't look at them on the Abercrombie app, or at the Abercrombie store, or on the Abercrombie website.
I do not expect Abercrombie to "see what I do in real time," including where I position my mouse on my screen, text I type and then choose to delete, my physical location, etc.
Re: Many popular iPhone apps are recording user sessions without asking
#68Replaying user behaviour is not a privacy issue. Pretty much every mobile/web app connected to the internet is doing this with varying granularity. AFAIK it's a pretty standard practice in UX and product design. A&F might have analysed hours of your finger gesture activity, but I doubt they're gonna know what brand of toilet paper you wiped with this morning.
Re: Many popular iPhone apps are recording user sessions without asking
#69Earlier quoted context omitted.
I've been seeing the same sensationalist language even in "respected" publications like the NYT lately. For example, they recently published a story where it was implied that because Spotify's Messenger plugin has standard read/write permissions (necessary to ensure basic functionality like sharing songs) that it could also actively monitor, store, and modify your private messages. In smaller publications, some shodd…
But you do agree that Spotify can read private messages, if it wants to. The news may not be clear about this, but we do need tighter permissions.
https://newsroom.fb.com/news/2018/12/facebooks-messaging-par...
I don't want this to devolve into an argument of semantics, but given NYT's editorial resources there's no doubt they carefully scrutinized how the "read" and "write" would be interpreted by their readership in the context of a negative report about Facebook.
Re: Many popular iPhone apps are recording user sessions without asking
#70> Many major companies, like Air Canada, Hollister and Expedia, are recording every tap and swipe you make on their iPhone apps. In most cases you won’t even realize it. And they don’t need to ask for permission. The key phrases here are "recording every tap and swipe" and "on their iPhone apps". I'm not saying it is okay, but the sensationalist headline takes away from the real issue.
I've been seeing the same sensationalist language even in "respected" publications like the NYT lately. For example, they recently published a story where it was implied that because Spotify's Messenger plugin has standard read/write permissions (necessary to ensure basic functionality like sharing songs) that it could also actively monitor, store, and modify your private messages. In smaller publications, some shodd…