Live data from Hacker News

Google to ban financial lending apps from accessing user photos, contacts

pcmag.com

71–80 of 165 posts

Re: Google to ban financial lending apps from accessing user photos, contacts

#71

I never understood why Program permissions is such a big deal on Android and IOS, but not on Desktop Windows/Linux, where any application can to everything .

That’s sort of like saying seatbelts shouldn’t be required in cars because you don’t need one on a motorcycle.

Re: Google to ban financial lending apps from accessing user photos, contacts

#73

I never understood why Program permissions is such a big deal on Android and IOS, but not on Desktop Windows/Linux, where any application can to everything .

It's just that innovation on the desktop side died years ago.

Re: Google to ban financial lending apps from accessing user photos, contacts

#74
post #50

This feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged…

Additionally there should be a sandbox mode. While you give the app access to Photos and Contacts, it's an actual sandbox not containing any photo nor any contact. So the app gets what it asks for (the permission) while the user can still control the data.

This is the obvious solution, it’s really annoying that it is not available for every permission. (Contacts is the big missing one in iOS, but you could even have a fake GPS that returns random positions.)

Re: Google to ban financial lending apps from accessing user photos, contacts

#75

This feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged…

I seem to remember this worked a lot better a few years ago. Nowadays you can't even deny an app permission to access the internet.

Re: Google to ban financial lending apps from accessing user photos, contacts

#76
post #50

This feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged…

Additionally there should be a sandbox mode. While you give the app access to Photos and Contacts, it's an actual sandbox not containing any photo nor any contact. So the app gets what it asks for (the permission) while the user can still control the data.

GrapheneOS supports this with a feature called Storage Scopes. Instead of giving an app access to your entire photo library and files, you can limit its scope to an individual folder of your choice.

That way the app still gets the permissions it asked for, but they're specifically what you want it to see.

Re: Google to ban financial lending apps from accessing user photos, contacts

#77

I never understood why Program permissions is such a big deal on Android and IOS, but not on Desktop Windows/Linux, where any application can to everything .

Depending on the scope of "everything", Windows may pop up a dialog box asking for permission, and Linux will return error to the application.

I believe most modern operating systems will not just grant blanket permissions to every application, except maybe single user systems like BeOS.

Re: Google to ban financial lending apps from accessing user photos, contacts

#78

They need to ban that Dave app. I signed up because it offered a loan for $500, but when I got in the app they forced me to "connect" my checking account, sucked up all the data, then offered me only $20. With a daily notification to setup one of their "checking accounts". The app was advertised as a short-term loan with borrower-friendly terms ("give us a tip!") -- yeah right. Come to find out it's just a new accoun…

There is no universe where I'm connecting my bank account to some ghetto ass app for a seemingly too good to be true loan.

Me neither, but the banks are probably selling all your data to the same clearinghouses anyways… we need banking secrecy laws like the Swiss used to have, AML be damned

Re: Google to ban financial lending apps from accessing user photos, contacts

#79
post #56

Earlier quoted context omitted.

Why would the unfriendlessness of payday lenders be essential to the business model?

Because the type of people who have no choice but to resort to payday lenders are the same type of people who need men with guns to visit their in their house at 2 am in order to pay back their debts.

You are confusing payday lenders (who use the courts and high interest rates to make up for defaults) and loan sharks (who use violence).

Re: Google to ban financial lending apps from accessing user photos, contacts

#80
How about we leave access to Contacts only to apps that, you know, allow you to contact other people and legitimately need either the email or number? Make it a global XOR: you can ask for Contacts OR credit card/financial data, but not both.

In any case, there is never a legitimate need to know the entire address book to "send money to your contacts": mobile OSes could just offer an interface to manually pick a single contact and return it to the app, which could then validate it as a financial partner

Post reply on HN