Live data from Hacker News

Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

foundation.mozilla.org

41–50 of 75 posts

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#41

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

The information stored in therapy or prayer apps is much more sensitive than a disposable Reddit account.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#42

I was pleased to see that Hallow earned their seal of approval, or should I say it evaded their badge of shame? Hallow's a good app, professionally developed, and it's marketed tirelessly. I had my friend asking me if it was a good app to install. I don't know; I use other ones but not Hallow. I was also pleased to see that "BetterHelp" earned the badge of shame. BetterHelp is just on this side of an outright scam. T…

While you're not wrong, in many many states in the US, if not a majority of them, finding a therapist that is both a) covered by your insurance and b) accepting new patients can be extraordinarily difficult if not impossible. At the same time, demand for mental health care is steadily rising. That's why these apps do so well.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#43

I was pleased to see that Hallow earned their seal of approval, or should I say it evaded their badge of shame? Hallow's a good app, professionally developed, and it's marketed tirelessly. I had my friend asking me if it was a good app to install. I don't know; I use other ones but not Hallow. I was also pleased to see that "BetterHelp" earned the badge of shame. BetterHelp is just on this side of an outright scam. T…

While you're not wrong, in many many states in the US, if not a majority of them, finding a therapist that is both a) covered by your insurance and b) accepting new patients can be extraordinarily difficult if not impossible. At the same time, demand for mental health care is steadily rising. That's why these apps do so well.

[deleted]

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#44
post #21

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

I don't understand what they mean by strong passwords. From the methodology: > If the product uses passwords or other means of security for remote authentication, it must require that strong passwords are used, including having password strength requirements. What are 'strength requirements'? Is minimum-length-of-X a strength requirement? Apparently not, since Abide failed for the following: > Strong password: No. Al…

[deleted]

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#45
post #38
post #21

Earlier quoted context omitted.

I don't understand what they mean by strong passwords. From the methodology: > If the product uses passwords or other means of security for remote authentication, it must require that strong passwords are used, including having password strength requirements. What are 'strength requirements'? Is minimum-length-of-X a strength requirement? Apparently not, since Abide failed for the following: > Strong password: No. Al…

Passwords tend not to be brute forced one character at a time, but by combinations of common password lists and rainbow tables. The base unit is not character in these cases but entries in the tables. Therefore, a password like "EstablishedCousins" is significantly less secure than "bR^4outc0m3" despite containing more characters. Edit: I actually mean dictionary attack, not rainbow tables, but my point still stands.…

> Therefore, a password like "EstablishedCousins" is significantly less secure than "bR^4outc0m3" despite containing more characters.

And "awn-handsome-dolce-esophagi-radix-lawgiver" is more secure than "Hunter2"…

My point is that their methodology doesn't cover what do they mean by strong passwords. A sufficiently long (and sufficiently random - but how do you check for that?) pass phrase is strong in my view.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#46
post #37

Earlier quoted context omitted.

Why do I need a password at all for 99.99% of apps or websites? If I lose a password, what do I almost always have to do? 1. Email account recovery link. 2. Input auth code sent from text message or authenticator app. [Optional.] 3. Make new random password I'm going to forget or lose. Why bother with this? If email is the reset mechanism why does the industry care so much about getting passwords from users? 1. Email…

> Why bother with this? If email is the reset mechanism why does the industry care so much about getting passwords from users? Because you may not have access to your e-mail from the device where you want to use that service. For example, I don't need to have access to my e-mails from my tablet as I'm always reading/writing them on a computer with a keyboard. So I don't want to setup access to my e-mails from my tabl…

I covered this in my comment with QR login codes.

Plus, if you really want to, you could also have a one-time use 6 digit code for login also sent in the email and it would be better for the majority of people that do not use a password manager.

Or if you really, really, really must have your passwords then please invert the default to where login via link is the primary mechanism and passwords are optional on a per-account basis.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#47

I was pleased to see that Hallow earned their seal of approval, or should I say it evaded their badge of shame? Hallow's a good app, professionally developed, and it's marketed tirelessly. I had my friend asking me if it was a good app to install. I don't know; I use other ones but not Hallow. I was also pleased to see that "BetterHelp" earned the badge of shame. BetterHelp is just on this side of an outright scam. T…

While you're not wrong, in many many states in the US, if not a majority of them, finding a therapist that is both a) covered by your insurance and b) accepting new patients can be extraordinarily difficult if not impossible. At the same time, demand for mental health care is steadily rising. That's why these apps do so well.

I've found that some of the best therapists don't accept any insurance at all, and it'd be foolish to limit one's choices to therapists who are covered by conventional health insurance.

One very good choice in my area is Catholic Charities. They have licensed counselors as well as students under supervision, and they charge a mere $35 per session. This is a great choice for those who are uninsured or have trouble getting in somewhere.

My Christian health sharing ministry shared all costs for a Catholic therapist while I was seeing him. Since this is not a "health insurance" arrangement, I didn't need to worry about whether he was in-network or approved; he just submitted his bills to them. My health sharing ministry also has a service that "reprices" bills, i.e. renegotiates them based on market rates and lops off overcharges that commonly occur.

And yeah, "BetterHelp" has this illusion of availability, and that can be very alluring to people in distress, and that's a dangerous thing. If someone gets mixed up with gig-worker counselors, they may find themselves worse off than when they started. "Good things come to those who wait", as it were.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#49

I was pleased to see that Hallow earned their seal of approval, or should I say it evaded their badge of shame? Hallow's a good app, professionally developed, and it's marketed tirelessly. I had my friend asking me if it was a good app to install. I don't know; I use other ones but not Hallow. I was also pleased to see that "BetterHelp" earned the badge of shame. BetterHelp is just on this side of an outright scam. T…

BetterHelp is terrible. The dehumanizing, exhausting, money-seizing experience of trying to engage with their app was a net negative for my mental health when I tried to use it. They've taken the antipatterns used to extract effective monetization in social media apps and mobile games and applied them to people seeking help with their mental health. I've noticed they ingratiate themselves with corporate health benefits providers, etc too. I firmly believe someone in severe need of assistance would only feel worse after seeking help from that app.

I got as far as the conversation with my "onboarding coach", the licensed therapist who was supposed to find me a "good match" - and it became apparent she was either a bot or attending so little to the conversation she was unable to recognize information my earlier messages and apply it to later messages - it was like an automated customer support/service flow, but asking me highly personal questions about my mental health.

There's plenty of mediocre apps out there, but nothing has produced a simmering rage in me like the knowledge that BetterHelp exists and takes advantage of people who need help every day so their leadership and investors can try to get rich.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#50

iOS or Android, both get your data. What is the difference in privacy? Please use actual examples and not boogeymen 'Google is an ad company'. I personally have seen iphones(or at least iphone users) have far more intrusive and customized ads to the point where saying a word in a home puts you at risk of getting physical mail related to that word. (It was dog food, and a dog food ad.) I've come to the conclusion that…

FWIW, I don't have any pets (and haven't for some time), but I receive physical mail regarding dog food, dog toys, etc, all the time. There's a chance you've been fooled by randomness here.

That said, there's certainly no harm in treating your device as compromised. I do the same. "Better safe than sorry."

Post reply on HN