Live data from Hacker News

Google to ban financial lending apps from accessing user photos, contacts

pcmag.com

151–160 of 165 posts

Re: Google to ban financial lending apps from accessing user photos, contacts

#151
post #97

Earlier quoted context omitted.

It's the same with location data. iOS allows you to restrict apps to only approximate location, but apps like YouTube TV and ESPN require precise data just to do region checking. I wish iOS just wouldn't allow apps to figure out if they're getting precise vs. approximate location.

It’s incredibly confusing when apps do this. Often, the symptom is that GPS looks broken. GrapheneOS’s location services have a similar issue, but 100x worse. There, apps can definitely have lat/long, but not full Google location service, and all sorts of proprietary software ends up with no/wrong location dots on their maps. Open source apps, and Google maps competitors work well, so I know it isn’t a hardware or ra…

> GPS looks broken

It’s a failure both on the app and Apple side to convey this information properly. Approximate location should be shown with a large circle and the user could be told explicitly about this.

Some apps really need exact location (think Uber and Google Maps) but many don’t (any social network)

Re: Google to ban financial lending apps from accessing user photos, contacts

#152

Earlier quoted context omitted.

I wish you’re right but I don’t see how what you’ve mentioned stops most malware.

In a nutshell, because an application won't be able to do anything evil. We're already halfway there on mobile devices. An Android app cannot access system files or files of other apps, period. "Run as admin" doesn't exist. It can't access shared files like camera photos or documents without explicit user permission. This is mostly accomplished using SELinux, which is an afterthought slapped onto the original OS arch…

These are, quite frankly, easy protections to put up. I know a lot of work is invested into them but it’s pretty clear that apps shouldn’t be able to scribble all over the address space of other processes, or just have access to all system devices. The hard part is when you actually have a legitimate need to do certain things but not every app should be granted this permission. For accessibility reasons some apps should be able to simulate user input. Obviously, giving this permission to every app is not good. Some apps should be able to know where you are. The one that your spouse installed on your phone secretly to track you? Probably not. This is where the challenge is these days.

Re: Google to ban financial lending apps from accessing user photos, contacts

#153
post #133

Earlier quoted context omitted.

And if you tell me now, that it works without having access to contacts, its lightyears ahead of WhatsApp. But still, these moaning dialogs aren't trust-building. I wish there would be better guidance with UX in the industry.

WhatsApp works without access to contacts now, no?

No, you can't initiate a session with someone you know the number of, it demands access to contacts so "you can stay in contact with your friends". The usual weasel words.

Re: Google to ban financial lending apps from accessing user photos, contacts

#154
post #153

Earlier quoted context omitted.

WhatsApp works without access to contacts now, no?

No, you can't initiate a session with someone you know the number of, it demands access to contacts so "you can stay in contact with your friends". The usual weasel words.

It was the case before, but I can do it now. It says "enable contact access to make it easier" but I can also just punch in a number and start chatting... Contact access is off.

Re: Google to ban financial lending apps from accessing user photos, contacts

#155

This feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged…

#1 is a nice recommendation, but not trivial.

You've got three major systems for detecting policy violations: static analysis, dynamic analysis, and human interaction. You don't want too many false negatives or else you get bad media coverage complaining that you aren't doing enough to enforce policy. You don't want false positives or else you hurt benign users.

Static tooling will be able to detect specific kinds of ways that an app might refuse to work if you don't have a permission, but will struggle mightily in general. Dynamic analysis needs to be driven to the specific feature that triggers the behavior. Both will struggle if the app's response is something like returning to a home screen with a custom message. And good luck teaching one of these systems what "disabling unrelated functionality" looks like.

Human interaction works better but is a gazillion times more expensive. Training people is also harder than one might think. You can train humans to identify "disabling unrelated functionality" but that's fuzzy enough that there are going to be some errors. Doable, but every single new policy costs significant amounts of money.

Policy overload is also a problem for developers. There are already a lot of rules on both app stores. Developers get a new "hey this is a new rule you need to comply with" email all the time. You can only roll things out so fast or developers will get overwhelmed with just validating that their apps remain in compliance.

These are often solvable problems in isolation, but when taken as part of the overall effort of policy enforcement on app stores they become quite a bit more challenging.

Re: Google to ban financial lending apps from accessing user photos, contacts

#156
What we really need is finer-grained permissions like “let the OS pick a photo and hand it to the app” and “let the OS pick a contact and hand it to the app” and then require that most apps use that instead of overly-broad permissions that will be abused.

Re: Google to ban financial lending apps from accessing user photos, contacts

#157

Earlier quoted context omitted.

Regretfully, it seems on iOS apps can tell they’ve been given access to only specific photos. Googles Photo app refuses to work unless it gets access to all photos.

This was an annoying issue with one of the Twitter competitors a while ago; their app asked for photo access, I gave it partial access, it grumbled that it needs ALL of it, and refused to let me upload any photo. I thought it was a "total photos < X" heuristic, so I went back and picked like 30 old photos, and it still knew that wasn't all of it.

Probably because it's file based. Don't they have a feature to paste a picture from clipboard or photocamera?

Re: Google to ban financial lending apps from accessing user photos, contacts

#158

Earlier quoted context omitted.

>2. Make Android present convincing fake data to apps when permissions are denied GrapheneOS can do this. I believe you can even choose to make only chosen photos visible to a certain app

This functionality is built into iOS as well.

iOS implements access permissions, GrapheneOS implements sandboxing.

Re: Google to ban financial lending apps from accessing user photos, contacts

#159

This feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged…

I seem to remember this worked a lot better a few years ago. Nowadays you can't even deny an app permission to access the internet.

I can deny the internet to individual apps on my Pixel 7 running Android 13. I can even deny just mobile data.

I often do it when I first install an app that shouldn't need internet access.

Re: Google to ban financial lending apps from accessing user photos, contacts

#160

They need to ban that Dave app. I signed up because it offered a loan for $500, but when I got in the app they forced me to "connect" my checking account, sucked up all the data, then offered me only $20. With a daily notification to setup one of their "checking accounts". The app was advertised as a short-term loan with borrower-friendly terms ("give us a tip!") -- yeah right. Come to find out it's just a new accoun…

Never give your bank info to a third party. Never. No good will come. You could offer me $1000 cash and I wouldn’t do it. It’s just not worth the hassle as setting up and establishing a new bank account is a bit of a hassle.

> Never give your bank info to a third party. Never. No good will come.

How do you pay for your electricity? I set up a direct debit with my utility company. That involves handing over bank details.

Post reply on HN