Live data from Hacker News

Popular Google Play store apps are abusing permissions and committing ad fraud

buzzfeednews.com

81–90 of 178 posts

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#81

the locked in store model has completely failed. both for ios and android it is a terrible experience compared to PC. you are stuck with only the search tools the hardware maker gives you, often designed in a user hostile way (ios brings up ads) and no way to bail out to a different store. as well the monoculture leads to a race to the bottom with garbage programs shoving their way to the top via misleading a dishone…

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

It is amazing that we can fly aircrafts to space but cannot solve software installations, in't it? Maybe the software industry as a whole needs a kick in the butt.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#82

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

It is amazing that we can fly aircrafts to space but cannot solve software installations, in't it? Maybe the software industry as a whole needs a kick in the butt.

Flying to the moon isn’t filled with profit motivated bad actors.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#83
The article puts blame on specific apps of Chinese origin, but lot of said in the article can be applied to other apps too, for example:

> Kaltheuner, of Privacy International, told BuzzFeed News the policies are vague about how third parties, including potentially the Chinese government or other authorities, can gain access to the data being collected.

Google's privacy policy [1] is also very vague. Instead of clearly writing technical details, what data they collect and when, they just give a general description. Take this phrase, for example:

> We may also collect information about you from trusted partners, including marketing partners who provide us with information about potential customers of our business services, and security partners who provide us with information to protect against abuse.

Or this:

> We provide personal information to our affiliates and other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures.

Absolutely no details. I don't see how Google hiding its "partners" identity is different from Chinese companies hiding their identity.

The article says that Chinese company can share the data with their government (without any proofs), but doesn't Google share the data too when required by the law?

Also, there is an interesting note hidden in Chrome's policy [2]:

> Chrome won't allow a site to access your location without your permission; however, on mobile devices, Chrome automatically shares your location with your default search engine if the Chrome app has permission to access your location and you haven’t blocked geolocation for the associated web site.

So instead of singling out a Chinese company, we should pay attention to all of the mobile apps and their practices.

Regarding excessive permissions, I think Google could improve the situation by promoting apps with few required permissions in the search results and making permission list more noticeable. For example, currently, if you browse Google Play, permission list is hidden behind a tiny link.

[1] https://policies.google.com/privacy?hl=en-US

[2] https://www.google.com/intl/en/chrome/privacy/

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#84
post #76

> Ad fraud is simply the norm in China Why is that? I can't even imagine what's going on at the meetings leading up to implementing ad fraud in what I presume is a normal company otherwise and not a bunch of gangsters. Is it morally OK to do this in China for some reason?

> While on my most recent flight to Beijing, I sat next to an chatty elderly Chinese woman. We started discussing the topic, and she said that Chinese society lacks su zhi 素质, which translates roughly to manners or etiquette. Before the Cultural Revolution, she explained, Chinese society was guided by the moral lessons of Confucianism, with its emphasis on being a gentleman, respecting one’s elders, and obeying one’s leaders. But during the Cultural Revolution, Mao Zedong put Confucian principles on its head, pitting the Red Guard youth against their parents, the less educated against the educated elite. This chaos tore the social fabric and transformed the society into a survivalist one, a dog-eat-dog world, the vestiges of which are still felt today.

> When Deng Xiaoping implemented the Reform and Opening Up policy in 1978, capitalism was added to the mix of the survivalist culture; in order to get rich, you had to compete fiercely, fend for yourself and take care of your own with no regard for rules. This would also explain the rampant corruption among government officials, who use their position to amass wealth for themselves and their family. And nowadays, a third phenomenon has also added itself to the dangerous cocktail of selfishness and competition: the digital age. Many Chinese young people spend the majority of their days glued to WeChat, or taking selfies everywhere, or shopping at the ubiquitous malls around the country. This “me” culture is certainly not unique to China; indeed, we see the same thing happening to the youth in New York to Buenos Aires to London to Brussels to Moscow. But in China it exacerbates the already self-centeredness brought on by the cruelty of the cultural revolution and the competitiveness of capitalism with Chinese characteristics.

> In other words, China doesn’t just lack common etiquette and basic manners; it lacks a moral compass altogether.

https://thediplomat.com/2016/09/chinas-quest-for-a-moral-com...

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#85

the locked in store model has completely failed. both for ios and android it is a terrible experience compared to PC. you are stuck with only the search tools the hardware maker gives you, often designed in a user hostile way (ios brings up ads) and no way to bail out to a different store. as well the monoculture leads to a race to the bottom with garbage programs shoving their way to the top via misleading a dishone…

But Linux is not better. Android at least has permissions for apps and allows you to deny some of it; on a typical desktop Linux distribution or on Windows every app has full access to all of your data: a calculator can read your browser history. If you install the Slack app from Deb package on Linux, it will add its repository into APT sources list which means that Slack Inc. can now "patch" any program on your system, for example, sshd or Firefox. Also, it will add a daily cron task that checks that added configuration is not commented out (they explain that it is necessary for the case of upgrading a distribution). Such behaviour is simply impossible on Android.

So I think it is the opposite: mobile OS provide better security than desktop OS.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#86
post #41

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

The problem with early 2000's-style software delivery wasn't that you could choose which software to install, it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc. If iOS or Android made it easier to install apps outside the store, I highly doubt you'd see anywhere near the same level of problems, since everyth…

> it was that there was no separation between programs, so that any random program you installed could add toolbars to your browser, steal all your passwords, etc.

And for Linux or Windows this is still true.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#87
post #65

People think I'm weird for not installing whatsapp because it downloads all my contacts and I can't prevent that in this version of android which I can't update because I can only do that through at&t while on their network but I get service through someone else because at&t doesn't cover my area. It's absurd.

Just get a written permission from all of your contacts that you're allowed to upload their data to WhatsApp, like the rest of us clearly have. Or make it so that no one has anything against you ever. Because people have been sued already for uploading their contacts' information to WhatsApp without permission. I really don't want to encourage you to use WhatsApp, but one possible solution would be to use this app: h…

Isn't exporting a contact list a violation under GDPR? Contact names and their phone numbers are a personal information and the app must get that person's consent to process their data.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#88
post #44

Earlier quoted context omitted.

The solution is what has been suggested earlier: allow users to choose their own 'store', don't lock them to a single vendor. This is already possible with Android where F-Droid is a good example of a 'store' where the chance of being exposed to these shenanigans is close to zero. Currently iOS users lack this option so for them the only way out is to change platform.

Anything that became popular would be targeted just the same. The solution is more secure OSes, not distribution filtering. I should be able to put a gelatinous abomination from hell on my phone and be okay. Mobile OS sandboxing is better than older PC OSes but it's still not perfect.

The problem is that nobody except end users wants more secure OS. And end users do not matter.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#89
post #49

Earlier quoted context omitted.

I would find it acceptable if side loading apps was allowed by default but sideloaded apps are blocked from the dangerous permissions like device admin and draw over screen. Apps that really do require this have to be checked by a maintainer or require the device to be in developer mode. This way almost everyone is happy because most apps don't really require anything other than internet, camera and GPS which can be…

This. Google and Apple should make it easy for computer literate people to use something more advanced. Have the unwashed massed version sure, but then let us override it in a graceful manner instead of having to jump through hoops. Would lead to all kinds of free innovation etc. that they could then take over and profit from. Use the computer literate! WE WILL FIX IT FOR YOU

The problem with this is that waaaay too many people consider themselves computer-literate.

Re: Popular Google Play store apps are abusing permissions and committing ad fraud

#90

Earlier quoted context omitted.

> and yea i know you can sideload on android, but the unwashed masses don’t know that so it doesn’t matter. Then what is your solution? The unwashed masses tried the wild wild west of digital software delivery back in the 2000s. It ended with tears, viruses, UAC and SaaS. Even today, most sideloading, for general consumers, begins with trying to pirate apps and ends with even more invasive spyware. The locked in stor…

I'd say that the sandboxing introduced by mobile OSes today solves the vast majority of the problem. By isolating applications and introducing permissions, malware that can steal or encrypt user data isn't possible even for people installing those pirated APKs.

But in the end the software running on our phones is mostly crap.

I doubt user data being protected by these mechanisms helped people to guard their data.

Post reply on HN