Earlier quoted context omitted.
They can just lie to the old apps. Tell them they're getting the full list when the API is called.
"Yep, this user has exactly one contact, and gee, it happens to be the one they're calling now, how fortuitous! They had a different single contact yesterday, but apparently they've deleted that one and added this one."
Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
141–150 of 206 posts
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#142Every time I open the Snapchat Android app it prompts me with a Snapchat-styled (not the system) dialog to share my contacts. Every time I hit "Don't allow". Every time it prompts me again. This is an inexcusable dark pattern. Two things need to happen: 1. The operating system needs to provide a "screw you, never" option for any permissions. 2. We as engineers need to say "screw you, never" to requests to implement b…
The system does have a "screw you, never" option for all permissions. The issue is that Snapchat (in your case, as I don't have this happen on v11.23.3.36) is told that they wont get the permission and wont be able to ask for it either. And so they perform their own inhouse permission request to you. There is nothing that can be done from the system's point of view for that.
v11.25.0.29 Beta for me
> in house permission request
That's what I had feared. I'd expand the scope of "the system" to include Play store rules.
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#143Every time I open the Snapchat Android app it prompts me with a Snapchat-styled (not the system) dialog to share my contacts. Every time I hit "Don't allow". Every time it prompts me again. This is an inexcusable dark pattern. Two things need to happen: 1. The operating system needs to provide a "screw you, never" option for any permissions. 2. We as engineers need to say "screw you, never" to requests to implement b…
The system does have a "screw you, never" option for all permissions. The issue is that Snapchat (in your case, as I don't have this happen on v11.23.3.36) is told that they wont get the permission and wont be able to ask for it either. And so they perform their own inhouse permission request to you. There is nothing that can be done from the system's point of view for that.
They can ban the app from app stores for using any non-system interface to request permissions, like they do for payments.
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#144Earlier quoted context omitted.
Privacy Guard in Cyanogenmod used to do this I think, at least to fake the list to be empty. It somehow still broke a tiny number of apps (unintentionally, i.e. the app owners didn't purposefully add code to annoy those users) so there seems to have been some flaw between 'empty list with permission granted' and 'empty list with permission not granted'. Regardless, I'm not sure why this didn't become mainline Android…
For backwards compatibility, they could just put in some nonsense entries. If the program can figure out those entries are nonsense, it's no longer out of date and it's on them. Why they didn't do this by default is anyone's guess. Maybe they like app devs more than users. More technology should lie on users' behalf.
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#145Explanation: the toggle to opt out is made available after you log into Google and you must navigate in multiple screens which gives Google ample time to collect hundreds of contact details. Of course, it is not possible to turn on airplane mode during this procedure since the log in requires an Internet connection.
This is 100% against the EU GDPR. I've submitted a complaint to my local privacy regular (French CNIL) but never heard back.
This probably impacts 200+ hundreds millions of EU citizens (since 2/3 of the population must be using an Android phone). I can't imagine a more massive data collection program, since each user must probably have more than 50 people on their device so the total amount of people that is affected exceeds my imagination.
How can Google get such a pass?
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#146There needs to be two lists of contacts. One which I allow to be shared with apps And another which are my contacts I use with my dialer. People don't need their messenger apps knowing the phone number of their doctor
The protection must be set higher up (the law, I guess) since the operating system has become spyware.
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#147Earlier quoted context omitted.
I didn’t login on Wire for 3 months and “for my security” messages that were sent to me during that time were just... lost. I think my history was deleted too. This happened 2 or 3 years ago, but it made me just switch to something else (Telegram).
So you want them to just hold on to your messages on their servers indefinitely? I realize this is the norm nowadays, but is this really what you actually want?
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#148Every time I open the Snapchat Android app it prompts me with a Snapchat-styled (not the system) dialog to share my contacts. Every time I hit "Don't allow". Every time it prompts me again. This is an inexcusable dark pattern. Two things need to happen: 1. The operating system needs to provide a "screw you, never" option for any permissions. 2. We as engineers need to say "screw you, never" to requests to implement b…
The system does have a "screw you, never" option for all permissions. The issue is that Snapchat (in your case, as I don't have this happen on v11.23.3.36) is told that they wont get the permission and wont be able to ask for it either. And so they perform their own inhouse permission request to you. There is nothing that can be done from the system's point of view for that.
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#149Earlier quoted context omitted.
I also like wire and just by chance found it to message my kids on their iDevices that don’t have a phone number like iPads and iPods. It works great and has all the main features. I’m even happier now that you guys inform me it’s secure also.
If they’re Apple devices, why don’t you just use iMessage?
Re: Large-Scale Abuse of Contact Discovery in Mobile Messengers [pdf]
#150Earlier quoted context omitted.
In time I expect all OSes (mobile and desktop) will provide a "give false data" option. So Sandboxed+false inputs, sort of a digital Descartes deceiver. Because you know the slimy app developers will refuse to work if you don't hand over your full contact list. and people will just accept that. So the end game is a completely adversarial relationship, even on your own device.
> In time I expect all OSes (mobile and desktop) How much time? This has been a thing in one form or another since j2me. Some j2me platforms actually supported this kind of behavior, but that was all lost once Android and iOS came along. Same with fine-grained permissions over network access (eg, user having complete control over what networks/etc an app can access). We /had/ all of this in the days of BlackBerry, an…
What social tipping point needs to happen for those to be implemented? How can we lower the social bar for that to happen?
I have no clue. I'm almost always wrong on the social side of things.