Live data from Hacker News

Permissions asked for by Uber Android app

gironsec.com

141–150 of 164 posts

Re: Permissions asked for by Uber Android app

#141
post #19
post #7

Earlier quoted context omitted.

Yeah I noticed that as well, it makes me wonder about the rest of his technical assertions that I'm less able to judge. Just in case anyone was wondering here's the HTTP 1.1 rfc: https://www.ietf.org/rfc/rfc2616.txt A simple search will show that it does include PUT and DELETE.

> "... it makes me wonder about the rest of his technical assertions that I'm less able to judge." What technical assertions? From what I can gather, he's just pointing out what he sees in the code and what he thinks it might be doing. None of that feels like technical assertions (apart from the statement about PUT and GET).

He also implied that the presence of PUT and DELETE alone demonstrate that the app is using WebDAV and not a standard REST API via RFC2616 et al.

He also stated that WebDAV isn't a standard (ie RFC).

He also stated that you don't need PUT or DELETE because it can be done 'on the server'. (I'm not sure how you get your data to the server without HTTP verbs, but..)

With that said, his other work looks spot on; you don't always have to know how to architect a service in order to figure out what's broken with it. He's done a service to the community by taking this thing apart and seeing what makes it tick.

Re: Permissions asked for by Uber Android app

#142
post #103
post #81

Earlier quoted context omitted.

> I don't see the big OMG SECRET MALWARE scariness. This is the definition of malware: n. Malicious computer software that interferes with normal computer functions or sends personal data about the user to unauthorized parties over the Internet. I'm all for people taking responsibility for their privacy but this is basically what you are saying to people: "Hey you accepted that list of permissions (or Terms of Servic…

So then, how do you define "unauthorized parties"? All these permissions are explicitly authorized by the user, and I don't see any evidence that they're being used in unreasonable ways by Uber. > The average person doesn't reasonably expect Uber to be mining this information about them. Then it sounds like you would predict that, if you showed this article to the average Uber user, they would be upset and would stop…

"Explicitly authorized" might be debatable. There's no way to pick and choose what permissions to authorize; your choice is solely whether to install the app or not. If you could specify permissions and you did (and opt in, not opt out), then that would be explicit authorization for all of those permissions.

Re: Permissions asked for by Uber Android app

#143
post #81

Earlier quoted context omitted.

> I don't see the big OMG SECRET MALWARE scariness. This is the definition of malware: n. Malicious computer software that interferes with normal computer functions or sends personal data about the user to unauthorized parties over the Internet. I'm all for people taking responsibility for their privacy but this is basically what you are saying to people: "Hey you accepted that list of permissions (or Terms of Servic…

These items are all to allow the app to do it's job and to make using it as simple and as quick as possible for the end users. This is only being turned into FUD because it is now cool to hate Uber and everything they do now Must Be Evil.

It's not a matter of hating Uber.

It's a matter of looking at everything Uber right now with wariness in the light of multiple, public comments that indicate a complete lack of respect for their customers, their privacy, 'oppo' journalists, and even their competitors.

This is not simply a matter of capitalism at its best, or competitive assertiveness. This backlash could be viewed as a market correction against a company that has actually gone out of its way to bully everyone around.

Can you imagine what will happen if Uber gets the monopoly it's after? The entrenched taxi companies will seem positively benign. Even Microsoft never did the things Uber is explicitly stating that it is doing or trying to do.

Re: Permissions asked for by Uber Android app

#144

Earlier quoted context omitted.

I don't use the Uber app at all; I use m.uber.com via Firefox Mobile, and it works just fine.

If Uber is such a bad actor, why are you people using it at all?

Convenience? Price? Lack of competitors (other than Lyft)?

Re: Permissions asked for by Uber Android app

#145
post #37
post #29

Android needs a sandbox, which will provide apps with empty contacts, call history, fake location and so on. Does such sandbox exists?

XPrivacy? https://github.com/M66B/XPrivacy

I'm devastated that it doesn't (and apparently, never will) work with Lollipop.

Re: Permissions asked for by Uber Android app

#146
post #76
post #57

Earlier quoted context omitted.

A lot of apps collect this information. There are flashlight apps that collect the same level. This is nothing new.

That doesn't mean it's good for users or for users or for Android's reputation as an app ghetto. Some means of scoring apps down for needless permissions would be a good thing.

Yeah, it does suck that you need to install the app before you can rate it. I mean...I understand why they would do this in an attempt to limit review gaming but in this case I often have to install something if I want to give it a bad review. In reality, I just don't install it and move on.

Re: Permissions asked for by Uber Android app

#147

Earlier quoted context omitted.

If Uber is such a bad actor, why are you people using it at all?

Convenience? Price? Lack of competitors (other than Lyft)?

> Good question, I may not need to power-on my Uber-only phone any more.

Re: Permissions asked for by Uber Android app

#148
post #5

TLDR : Uber's Android app is literally malware Since the website is currently down, this person reverse-engineered Uber's Android app and discovered it has code that will "call home" aka send data back to Uber with your: - SMS list [edit: see other comments re SMSLog, SMS permission is not currently requested] - call history - wifi connections - GPS location - every type of device fingerprint possible (device IDs) It…

Just for completeness sake and judging from the function names, this is the list, with attributes stored for each: - Accounts log (Email) - App Activity (Name, PackageName, Process Number of activity, Processed id) - App Data Usage (Cache size, code size, data size, name, package name) - App Install (installed at, name, package name, unknown sources enabled, version code, version name) - Battery (health, level, plugg…

Seriously? You mean, information that 1. Google makes available via API and 2. You agreed to when you installed the app is now means for Google to take legal action?

You're deluded. If you don't like this, stop using Android. I did.

Re: Permissions asked for by Uber Android app

#149

Earlier quoted context omitted.

I don't use the Uber app at all; I use m.uber.com via Firefox Mobile, and it works just fine.

If Uber is such a bad actor, why are you people using it at all?

Beats the alternatives. Worlds better than any experience I've ever had with a taxi (and more importantly with trying to obtain one).

Android isn't perfect (case in point: it should support saying "yes I want to install the app, no it can't have the permissions it asked for"), but at least it isn't iOS; I'm not going to stick with a feature phone until someone comes up with the perfect smartphone OS. If someone comes up with a service better than Uber, I'll switch. (For instance, I do plan to try Lyft next time I'm in a city it supports, to see if the experience is better.)

Re: Permissions asked for by Uber Android app

#150
post #78

Pro Tip: Unintall the Uber App, and use m dot uber dot com inside Chrome.

I do this with Facebook also.

Won't that mean that Facebook will know what sites you visit that run FB's beacon/SDK?

Better off using Tinfoil for Facebook (if Android)

https://play.google.com/store/apps/details?id=com.danvelazco...

Post reply on HN