Live data from Hacker News

Swype makes almost 4000 location requests every day

forum.swype.com

131–140 of 168 posts

Re: Swype makes almost 4000 location requests every day

#131

Earlier quoted context omitted.

Erm, no they should not. The same breach of privacy will occur when an app just re-implements the demanding of a permission. "This camera app will not run without access to your list of contacts. Enable Contact List Access and restart to proceed". If the phone is mine, then I should be able to easily set it to lie on my behalf to protect my interests.

That's not a breach of privacy. That's the developer enforcing their TOS. It is within my right to say that if you won't give me location information for (ad targeting/basic functionality), you can not use my app. Which is fine, but I'd also expect one-stars for that kind of behavior.

> It is within my right to say that if you won't give me location information for ad targeting, you can not use my app

I disagree. That question is exactly what we're discussing here. What you just said clashes with what you said earlier:

> Apps are guests in the user's back yard, not the other way around.

Either a developer is able to enforce their desired "TOS" on the user's device, or they cannot.

I am on the side of cannot, because attempting to define morals through simple rules ("right to contract") and then asserting that all emergent behavior from those rules is just, fails extremely hard with complexity-induced contradictions. The whole idea behind saying that a user owns the device is to make it clear that the Schelling demarcation point is the protocol, with each party carrying out such in their own best interest. Assuming an ambient authority (a legal contract, in this case) that constrains the behavior of the user's device runs directly counter to this.

Re: Swype makes almost 4000 location requests every day

#132
post #47

Earlier quoted context omitted.

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

That's exactly the reason, and it's more legitimate than you give it credit for. I can foresee numerous situations where users disable location tracking (in the name of saving battery) without realising the effect it will have (rendering a location-based app useless). A nice middle ground would be to keep App Ops, but hidden away somewhere, much like the Developer Tools are.

This is easy to fix. Just have the app notify the user that feature X will break without permission Y. The user can then make the decision.

Re: Swype makes almost 4000 location requests every day

#133
post #47

Earlier quoted context omitted.

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

That's exactly the reason, and it's more legitimate than you give it credit for. I can foresee numerous situations where users disable location tracking (in the name of saving battery) without realising the effect it will have (rendering a location-based app useless). A nice middle ground would be to keep App Ops, but hidden away somewhere, much like the Developer Tools are.

This is easy to fix. Just have the app notify the user that feature X will break without permission Y. The user can then make the decision.

Re: Swype makes almost 4000 location requests every day

#134
post #47

Earlier quoted context omitted.

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

That's exactly the reason, and it's more legitimate than you give it credit for. I can foresee numerous situations where users disable location tracking (in the name of saving battery) without realising the effect it will have (rendering a location-based app useless). A nice middle ground would be to keep App Ops, but hidden away somewhere, much like the Developer Tools are.

This is easy to fix. Just have the app notify the user that feature X will break without permission Y. The user can then make the decision.

Re: Swype makes almost 4000 location requests every day

#135
post #30

Earlier quoted context omitted.

It was never released -- they removed access to a feature that was not intended for the public. That seems well within their right. For you to declare "Google seems to have no interest in protecting android users from this either." seems quite misguided, given that they are clearly working on a solution for this exact problem.

>given that they are clearly working on a solution for this exact problem. Evidence?

Android's source code has been gaining AppOps runtime permission checks for a while now. It really does look like they're moving towards a runtime permissions model.

The AppOps "release" wasn't a release. It was a private screen that accidentally had a public intent filter (default behavior is public, this is an easy thing to miss). The only reason anyone knows about it is because people made "launchers" that opened the screen, it was never reachable by normal means.

Re: Swype makes almost 4000 location requests every day

#136

Earlier quoted context omitted.

Never attribute to malice what could also be attributed to incompetence. All we know is that it makes the location requests, it could just as well be attributed to sloppy programming.

Dunno. How can you inadvertently request location info when you're implementing a keyboard for Android?

I'm reasonably sure that the Google keyboard does. It's used for nearby-city autocomplete, which can be pretty handy.

Re: Swype makes almost 4000 location requests every day

#137
post #61

Earlier quoted context omitted.

If you're on Android and rooted, use App Ops X. It allows the revocation of individual permissions, like location, wake lock (a battery waster), and others. Every time I install a new app, I look at Ap Ops X and see what perms it's using and revoke the ones I don't want it to have.

I'd recommend XPrivacy. It's much more granular (function level ACLs with some argument-level filtering), so one could allow connecting only to specific hosts or opening only allowed file paths on external storage.

Seconded. I've been using XPrivacy for quite a while now, very stable, very useful. It also shows you the last time a call was made, so you can see e.g. that a variety of apps try to access your contacts after asking you if you want to allow it, even when you say "no" (which is not necessarily shady behavior, but still frowny-face inducing).

Re: Swype makes almost 4000 location requests every day

#138
post #35
post #20

Just about everything I install on my phone is suspect these days with respect to privacy and permissions. Why does BBC weather need to write to my USB storage for example and why do I have to let it? The Nokia C2 I have floating around is starting to look interesting again. It has no idea where it is.

Every functional phone knows where it is, in the sense that it knows the signal strength of one or more nearby cell towers. A java app on your Nokia C2 could probably determine its location like this: https://stackoverflow.com/questions/11628648/how-to-find-use...

Yeah but there is no possibility of running one of these on S40 platform as J2ME apps don't run in the background.

Re: Swype makes almost 4000 location requests every day

#139

Actually, to me it sounds like a bug with Swype when location access is blocked. The users in the thread with the large amount of requests all have the location permission blocked. Other users with Privacy Guard installed as well (so they can see the amount of location requests) who have not blocked location access report that it only made the request once. So it just sounds like if it fails the initial request it co…

[deleted]

Re: Swype makes almost 4000 location requests every day

#140

Earlier quoted context omitted.

Google seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app…

Why wouldn't Google want users to have such powerful control over their devices? It's always explained like this: Because it's "simpler." Because "things will break if the user does something wrong." Because "the average user won't need it." Those same poor excuses have been responsible for so much loss of privacy and freedom elsewhere, not just by Google. To me, they're deliberately preventing users from having too…

Because Android isn't the product, you are the product.
Post reply on HN