Live data from Hacker News

Many popular iPhone apps are recording user sessions without asking

techcrunch.com

81–90 of 126 posts

Re: Many popular iPhone apps are recording user sessions without asking

#81
post #47

Replaying user behaviour is not a privacy issue. Pretty much every mobile/web app connected to the internet is doing this with varying granularity. AFAIK it's a pretty standard practice in UX and product design. A&F might have analysed hours of your finger gesture activity, but I doubt they're gonna know what brand of toilet paper you wiped with this morning.

> Replaying user behaviour is not a privacy issue

This is a problem with the Silicon Valley bubble. Just because everyone else is in your shit pile doesn’t mean it doesn’t stink. You just can’t smell it.

Re: Many popular iPhone apps are recording user sessions without asking

#82

Earlier quoted context omitted.

I would rather not having an app sending screenshots of the screen / record taps while I input my CC number. Nor of any alerts / notifications that are unrelated to the app itself. So I'd say it can be quite a privacy issue.

Many of these companies (e.g. FullStory, Hotjar) obfuscate all input fields for exactly this reason.

I’m sorry but they don’t, at least in a sensible defaults, easy/reliable way. Unless they’ve changed recently. We did extensive testing and found it was up to the end user implementing the integrations, and their regard for this topic/privacy.

Re: Many popular iPhone apps are recording user sessions without asking

#83
One of the reasons why I switched from iPhone to Android is the firewall.

On my jailbroken i-devices (all of them) I was always installing "Firewall IP", and when an app was running, for any connection not previously (or globally - meaning rule applies for all apps) approved I would get a pop-up message (screenshot of an earlier iOS Firewall IP)[1].

Now with the jailbreaks being less efficient, and the Firewall IP app not been updated for a few years, I switched to Android and I am using "NoRoot Firewall" [2] for the same exactly purpose. I globally block all FB, ads, trackers

There is always the extra option for rooter/jailbroken phones to block things on the hosts file using host file selections from someonewhocares.org [3].

[1]: https://rdsbc.files.wordpress.com/2011/03/wall1.png

[2]: https://lh3.ggpht.com/fXRZfgSmArBemdjABjUDu0ibP9Gis3GV5YXTVj...

[3]: https://someonewhocares.org/hosts/

Re: Many popular iPhone apps are recording user sessions without asking

#84
post #47

Replaying user behaviour is not a privacy issue. Pretty much every mobile/web app connected to the internet is doing this with varying granularity. AFAIK it's a pretty standard practice in UX and product design. A&F might have analysed hours of your finger gesture activity, but I doubt they're gonna know what brand of toilet paper you wiped with this morning.

Funny how it's not a privacy issue for Apple devices, but triggers hundreds of posts of rage and ranting for Google devices.

Corporate cheerleading at its finest.

[Having hundreds of SV companies offer products that track user behaviour in iOS/Android/Web apps is of course a huge privacy concern, since that can very accurately profile you as a person.]

Re: Many popular iPhone apps are recording user sessions without asking

#85

One of the reasons why I switched from iPhone to Android is the firewall. On my jailbroken i-devices (all of them) I was always installing "Firewall IP", and when an app was running, for any connection not previously (or globally - meaning rule applies for all apps) approved I would get a pop-up message (screenshot of an earlier iOS Firewall IP)[1]. Now with the jailbreaks being less efficient, and the Firewall IP ap…

One annoyance is that SafetyNet pretty much prevents using Google Pay on a rooted or modified device.

Re: Many popular iPhone apps are recording user sessions without asking

#86
post #6

A two/three years ago I noticed that inspectlet (similar tech for the web) was happily sending the passwords in clear text to their servers, even though on their website they mentioned that passwords are never sent. I sent them an email and they eventually fixed it, but I wonder how many passwords and credit card CVC data did they collect before that?

A few years ago I was doing a security audit on a site and found this very problem. The marketing department had access to the Google Tag Manager account and added several (!) almost identical user tracking plug-ins. They were capturing all form fields, including credit card numbers, passwords, etc...

The documentation talked about how to block this capture but that involved a developer getting involved and the developers didn't even know about the plug-in.

Basically, don't add a third party service to any app or website without doing a secuity review, especially if marketing, product or UX have suggested it!

Re: Many popular iPhone apps are recording user sessions without asking

#87

One of the reasons why I switched from iPhone to Android is the firewall. On my jailbroken i-devices (all of them) I was always installing "Firewall IP", and when an app was running, for any connection not previously (or globally - meaning rule applies for all apps) approved I would get a pop-up message (screenshot of an earlier iOS Firewall IP)[1]. Now with the jailbreaks being less efficient, and the Firewall IP ap…

I think for most users Apple does a good job protecting them, but this is definitely one significant area of weakness for the platform. There are ways to implement similar controls using a VPN service[0], but of course then you need to trust the VPN operator.

[0]https://techcrunch.com/2018/10/24/smart-firewall-guardian-ip...

Re: Many popular iPhone apps are recording user sessions without asking

#88

One of the reasons why I switched from iPhone to Android is the firewall. On my jailbroken i-devices (all of them) I was always installing "Firewall IP", and when an app was running, for any connection not previously (or globally - meaning rule applies for all apps) approved I would get a pop-up message (screenshot of an earlier iOS Firewall IP)[1]. Now with the jailbreaks being less efficient, and the Firewall IP ap…

My favourites are:

- Blokada (https://blokada.org/): Does DNS-based blocking, good for blocking ads/trackers generally

- NetGuard (https://www.netguard.me/): With Pro, has traffic logging and the ability to filter by address or app. My approach for most apps is to disable all access then selectively whitelist as necessary to make it functional again.

Re: Many popular iPhone apps are recording user sessions without asking

#89
post #47

Replaying user behaviour is not a privacy issue. Pretty much every mobile/web app connected to the internet is doing this with varying granularity. AFAIK it's a pretty standard practice in UX and product design. A&F might have analysed hours of your finger gesture activity, but I doubt they're gonna know what brand of toilet paper you wiped with this morning.

I would rather not having an app sending screenshots of the screen / record taps while I input my CC number. Nor of any alerts / notifications that are unrelated to the app itself. So I'd say it can be quite a privacy issue.

I agree that sensitive data should be handled much better, but - at least in a webapp - they don't capture screenshots, they just only capture mouse movements, clicks and scrolling and then rerender that on the html.

Re: Many popular iPhone apps are recording user sessions without asking

#90
post #60

Earlier quoted context omitted.

I've been seeing the same sensationalist language even in "respected" publications like the NYT lately. For example, they recently published a story where it was implied that because Spotify's Messenger plugin has standard read/write permissions (necessary to ensure basic functionality like sharing songs) that it could also actively monitor, store, and modify your private messages. In smaller publications, some shodd…

I doubt the sinister / political motives - these headlines and articles are nothing more than to drive traffic / revenue. Pick a popular company / product / service, find something that they could be doing, throw up an article suggesting that's what they could be doing but have the title inferring that it is what they are actually doing. Rinse / repeat.

I'm not going to get into the subjectivity of what is or is not "sinister", but there's a more fundamental issue with the pattern you've described. Increasingly often today headlines are defacto articles. They get shared on various social media outlets and then people start discussing the title, filling in the body themselves. When the title is 'fake', it leads to mass disinformation. This gets even worse when the title and lead paragraph say one thing and it's only later in the article that the more nuanced reality is revealed. In that case you not only mislead the 'titlers' but also the skimmers.

I imagine readers on HN actually read articles at a vastly higher rate than e.g. Reddit or Facebook, yet on reading the comments it often becomes quickly apparent that many users, even here, do not bother reading articles before commenting on them. In an ideal world I wouldn't mind seeing misleading headlines put in the same bucket as false or misleading advertising. Of course in practice that'd be a terrible idea since this rule would simply be used for the powers that be to litigate against anything they don't like being published.

Post reply on HN