Why does it seem like browser extensions are ignored in all of these discussions? For example, right now the Honey Chrome extension has permission to "Read and change all your data on the websites you visit". They could be doing anything with that, I'm just crossing my fingers that they find me good deals and don't abuse my data. Chrome actually acknowledges this: "Warning: Google Chrome cannot prevent extensions fro…
>Related question: why can't we restrict the domains that Chrome extensions can read data from? The extensions can do this. E.g. a Strava extension would on install say it has access to *.strava.com (and possibly other domains).
Popular iPhone apps caught sending user location data to monetization firms
151–160 of 261 posts
Re: Popular iPhone apps caught sending user location data to monetization firms
#152Earlier quoted context omitted.
It's hardly doable in practice. For example, certificates have to be updated at least yearly, leaving your app completely broken unless updated.
1a. You don't have to pin the leaf. You can pin an intermediate 1b. Or you can pin the public key and ignore the certificate altogether, new certificates for the same key can be obtained as necessary. 2. The maximum certificate lifetime is currently 825 days, which, unless you're on another planet, is not "yearly". 3. If you're pinning for an application (not a generic website accessible in browsers) you don't need a…
Re: Popular iPhone apps caught sending user location data to monetization firms
#153Earlier quoted context omitted.
>There are so many good apps on the store made by good developers. It’s amazing how much better your experience is if you just avoid free apps when possible. Yes. It cannot be emphasized enough. Go pay for apps that are good.
Others have pointed out that there are good free apps. But more interestingly, there are bad paid apps. Take this paid Mac app for instance: https://gizmodo.com/top-apple-mac-app-secretly-sends-your-br... What I’d really like to know is whether anybody has any evidence whatsoever that paid apps in these same categories don’t do exactly the same things in exactly the same percentages.
The safest assumption to make is that if you give an app permission to access information from your device that the information will be shared with a nefarious actor.
From there, if you want to get benefits from uploading your information, you can make adjustments like "Oh, I know this guy, he's been making apps for a long time and seems trustworthy." or "This is a larger company and isn't likely to be bought just to strip mine their customer data. Additionally they probably have safeguards in place to keep rogue employees from running off with it."
None of those is fail-proof, but it's all about risk.
Re: Popular iPhone apps caught sending user location data to monetization firms
#154Systemic problems are where everybody is acting in good faith, trying to do the right thing, yet the system overall is in a state that's unacceptable. And the harder they work at their little piece, the worse the system gets.
Governments aren't at fault. They clearly are working on enacting privacy laws. OS vendors aren't at fault. They clearly are working on making sure apps behave within some defined behaviors set by the user. Walled Gardens aren't at fault, they are working on rooting out bad actors. App makers might not be at fault. They simply might be monetizing traffic using generic services that only take what the user has already agreed to. Even the services themselves can claim to be working on solutions. After all, didn't the user approve this? And aren't the rest of the food chain approving of this kind of thing? That's the thing: certification systems, whether they mean to or not, end up being a kind of blanket approval. They passed the tests, aren't they okay?
When news breaks, the public immediately wants to find a bad actor and bash them over the head, not wanting to admit or think about the fact that the entire system is at work. So controls are tightened on one bunch and the rest of them make statements (and efforts) about trying harder.
At root is probably something simple like "Don't track user's locations. Ever." I don't know. But I know the desire to simplify the story can lead to a lot of heat and noise -- and not much progress. Any certification system that says that a particular piece of code passes some kind of test can be construed that it passes all kinds of other tests -- and you can never lock up code, no matter how hard you try. This faith in certification systems is misplaced and very well may be a multi-billion-dollar fool's errand.
Re: Popular iPhone apps caught sending user location data to monetization firms
#155Earlier quoted context omitted.
There is no way to control the iOS firewall via extensions in iOS. Meaning, it's still not supported, and what you see as "essentially" the same misses the point. I want to block connections of specific apps. What iOS can do is reveal connections made by the network device to the outside. Duh. Set up Wireshark on some AP and get the same info.
Niche startup idea, VPN for your mobile device that can analyze and block traffic. Block entire countries, 3rd parties, etc. Give realtime feedback on their dashboard as applications are loaded. Could also be useful as a developer application profiling tool.
This is indeed what we (originators of this location tracking research) do.
Re: Popular iPhone apps caught sending user location data to monetization firms
#156Re: Popular iPhone apps caught sending user location data to monetization firms
#157No surprise to see a number of weather apps on here. Seems to be such an incredibly scummy category. The built in Apple app is fine for basic information. There are plenty of high-quality third-party apps. Weather Line (my fav) is $2. DarkSky is $4. Instead people go for these weird free apps covered in ads with terrible UIs. The NOAA one isn’t made by the government, seems like using that name should be some kind of…
The app is currently listed on Apple's Mac App Store as the company's fourth-highest "Top Paid" software programs, behind Final Cut Pro, Magnet and Logic Pro X. It is also the store's No. 1 paid utility.
The app currently costs $4.99, is validly signed by Apple, and its listing on the Mac App Store is accompanied a majority of lavishly positive five-star reviews.
Re: Popular iPhone apps caught sending user location data to monetization firms
#158I think that the business model needs to be changed starting all the up at places like Facebook and Google. At some point these products are going to be perhaps even under our skin and if they are still 'free' and needing to resort to dirty methods to turn a profit by invading our privacy, it will just be the inevitability of the way things are now.
Re: Popular iPhone apps caught sending user location data to monetization firms
#159Earlier quoted context omitted.
Others have pointed out that there are good free apps. But more interestingly, there are bad paid apps. Take this paid Mac app for instance: https://gizmodo.com/top-apple-mac-app-secretly-sends-your-br... What I’d really like to know is whether anybody has any evidence whatsoever that paid apps in these same categories don’t do exactly the same things in exactly the same percentages.
It is a simple rule and there are definitely exceptions in both directions. (Good free apps, bad paid apps) The safest assumption to make is that if you give an app permission to access information from your device that the information will be shared with a nefarious actor. From there, if you want to get benefits from uploading your information, you can make adjustments like "Oh, I know this guy, he's been making app…
If an app is paid, there is at least the possibility you aren’t the product. But you still might be.