Live data from Hacker News

Swype makes almost 4000 location requests every day

forum.swype.com

51–60 of 168 posts

Re: Swype makes almost 4000 location requests every day

#51
post #7

Every time I see something like this come up, it really makes me wonder how many other apps out there are doing the same thing and getting away with it. Unless you root your phone and use something like the mentioned android firewall, or go whole-hog and install Cyanogenmod, what chance do you have to guard against this? I assume ios users are likely in the same boat, but with even less chance of recourse.

Proprietary applications spy on their users constantly. It's no surprise that Swype is making these location requests. Rooting your phone isn't an answer in itself. Rooting allows you to install a more free Android distro like Replicant or CyanogenMod. However, if you're still using proprietary applications then you haven't accomplished too much. iOS users have no chance at all. There is no freedom in the iThings. Ap…

iOS allows users to choose whether or not each individual app can make use of the location services. Cute attempt at FUD though.

Re: Swype makes almost 4000 location requests every day

#52
post #46

Earlier quoted context omitted.

>given that they are clearly working on a solution for this exact problem. Evidence?

The "App Ops" settings that they accidentally released seems evident enough that the feature is forthcoming. Am I missing something?

No it just means that there is permissions infrastructure not that they intend to make it available.

What would show Google working actively would be to modify APIs or provide solid guidelines for developers to ensure that arbitrarily closed permissions didn't cause an app to crash or freeze. Making app privacy a high priority for future Android development would be clearly working towards it.

Having a hidden privacy infrastructure means nothing at all.

[fixed unclear sentences]

Re: Swype makes almost 4000 location requests every day

#53
post #23
post #20

Just about everything I install on my phone is suspect these days with respect to privacy and permissions. Why does BBC weather need to write to my USB storage for example and why do I have to let it? The Nokia C2 I have floating around is starting to look interesting again. It has no idea where it is.

Yes, BBC Weather. That's it. They are part of this mega anti-privacy NSA conspiracy too!

You say this as if it is silly to ask why such an app needs write-access to the USB storage.

Why do you think it is not a legitimate question?

Re: Swype makes almost 4000 location requests every day

#56

Earlier quoted context omitted.

Google seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app…

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

So I have an application which can attach location information to posts made from it. It requests access to location data (as is necessary) when installed, then lets you turn that feature on or off from an internal setting.

The request for location data implies the usage of the location feature, so the Android package manager won't let you install it on devices without a coarse location provider.

Therefore, like most Android apps which lookup location information, it just assumed that it could do location lookups. No point testing for a feature which will always be present, right?

Now guess what would happen if you used AppOps to turn location off? That's right, it would crash.

Not exactly acceptable user experience.

Now, what Google should do is probably: * For apps targetting Android 4.5+, certain features with privacy implications will default to OPTIONAL rather than REQUIRED when implied by a permission request. * AppOps is then able to toggle access to features which are declared optional, which apps must handle the absence of anyway.

Re: Swype makes almost 4000 location requests every day

#57

Earlier quoted context omitted.

The crazy thing about all these rooting methods is that the code is seldom open and in either case they always distribute binaries anyways. Rooting your phone is no guarantee of anything. Edit: think about how this would play out if you were to go on an Apple or Ubuntu forum and someone said "here, run this executable on your laptop to get extra functionality from it. I cannot give you the source because it's secret.…

Most (flagship) phones are rooted using an unlocked boot loader... in which case the "rooting methods" you're refering to is just a script to run a few commands to unlock the bootloader in fastboot mode, boot the phone into a temporary recovery system (which are by the way open source) and then use that to modify the OS. You can do it from a CLI yourself if you like. It's just time consuming. Most people just want th…

You'd still have to hand over root permissions to a random binary just the way grandparent described... Even in the play store, 80% of my apps have no authorship that go beyond a Gmail address.

Re: Swype makes almost 4000 location requests every day

#58
post #29

Earlier quoted context omitted.

Google seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app…

What really disappoints me is the terrible placement Google uses for privacy features in the Play store. They're really hidden away instead of being prominent searchable fields. Microsoft of all companies does far better with their Windows Store.

I would agree with you except for the part where they force you to see them before you're allowed to even install an app. It's hard to get much less hidden than that.

Re: Swype makes almost 4000 location requests every day

#59

Earlier quoted context omitted.

Google seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app…

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

Or, rather, it could be because the feature was unfinished and tended to crash applications when they don't get the stuff that's called for (and the user authorized) on the permission manifest.

http://pocketnow.com/2013/12/17/app-ops

Something something malice stupidity. But no, let's bring out the torches and pitchforks...

Re: Swype makes almost 4000 location requests every day

#60

Earlier quoted context omitted.

Google seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app…

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

I would bet money it has to do with business decisions that relate to carrier demands to support Android. People forget that Android is not in the same position as iOS to impose its will on carriers. Rather, the power dynamics are rather significantly the opposite, Android has to do far more negotiation and accommodating to assuage carriers.

Unfortunately, with the waning and sobering infatuation with iPhones and iOS, I have a sense that iOS will start and maybe even has made concessions that it otherwise would not be willing to. We have to realize that as long as network carriers are not what they should be, dumb pipes for data who make their money simply on competitive network performance, we are all subject to a protection racket type dynamic.

Post reply on HN