Uber wants access to browsing history, bookmarks, and running apps
reddit.com
reddit.com
> The permissions you see on the install screen are actually triggered by various permissions in the permission group. I've checked Ubers (there's a button on the web play store and you can see it in the manifest), and the only one from the Device and App History group they actually use is "GET_TASKS", or get a list of recently opened apps.
> Furthermore, on Lollipop this permission doesn't even do anything anymore. The relevant function in the framework has been changed and only returns instances of the caller's own app now. So Uber can see when you last used Uber. Big deal.
> Basically, this is a big fuss for nothing. Uber is not accessing your browser history, and if you're on Lollipop or above they can't access your app history either. They may do that on lower versions, but it's most likely to counter buggy behaviour on those older verions and not to spy on you.
I don't think I've changed my settings from the default and for me at least (Nexus 5, Lollipop) if an app has the same permissions set, it will update automatically, if it requests more it will prompt me to agree.
So even if the use of the permissions is innocuous now, it's bad news for the future to grant it.
If you have a nexus 5 why aren't you on marshmallow?
IIRC it even has some memory leaks ...
It is MUCH better in Marshmallow, so it is definitely worth upgrading because that's another thing where you just need to update the system.
Need to find out when you last opened the app? "Get running apps"...?
But let's say for some reason, you can't collect app-open timestamps. What could you possibly want to do with it locally? Say, "Hey it's been x days since you last used me. Thanks for coming back!"? These are stats you want in aggregate, which means sending the data back to the servers for actual data analysis. You're not going to do that analysis -- or any analysis -- on the device, since there's nothing to compare to.
We could go round and round like this. Give me a concrete use case, because for the life of me I can't come up with one that isn't simply superfluous chrome.
To me, it's pretty obvious they want to find out if you opened the Lyft app recently.
I assume the handoff from Google Maps doesn't require any kind of check to running apps from Uber, but I am curious if it is something along these lines.
The only this would get them is "how many times did a user try to get an uber without data connectivity" ...
I don't really understand the point of having fine-grained permissions (like READ_CONTACTS), when the user only sees broader permission groups. Can someone shed light on this?
I imagine it's because Google recognized the general insanity of the system, and presenting fewer "scary" permissions improved conversion rates.
Then they threw the whole system out with Android 6.0, moving to a much more sane flow for everyone involved, where the user is able to grant or deny individual permissions at runtime.
Because the way to fix "apps can demand a laundry list of permissions and users can only take it or leave it" is to sweep it under the rug?
A sane way to do it would be the way browsers deal with location data: "App [appname] is requesting permission to access [resource]. Allow always / allow / deny / deny always?"
> leave system broken but hide UI so nobody cares.
hopefully, it is just incompetence, not evil.
I won't be using Uber, ever.
Whoever is in charge of the permission system is absolutely nuts. Or it's designed by the committee from hell. Those are the only reasons I can think of. No one sane would create this.
They actually wanted to "simplify" the permissions system and let the user have more control/understanding. You could argue they've done the first... at the expense of everything else. Half of it seems to have been introduced so "it bugs you less", which is not the point, I want to be bugged (by default) so I know what applications are actually doing. If users wants to "not be bugged" let them manually set it, don't make it default.
I've meant to write a post titled "Android 6 permissions: Still pants" after buying a Nexus 5X and being happy with the phone/camera but utterly disappointed with the "revamped" permission systems:
- Yes sure, because I granted an application "Coarse location data", just go ahead and automatically (WTF?) give it "Fine location data" permissions too, because hey, it's all just "location data" right? Not like I might have wanted to give it coarse and not fine on purpose...
- Want to write contacts? Here's reading too! Want to write texts? Here's reading too! Same as above really. Is the use-case of wanting an application to be able to add to my data (at my request) but never-ever read all my data really that hard to predict?
- You get an Internet, you get an Internet, every application gets an Internet. Because every application needs Internet right? It's not like I'd maybe want to install an application to manipulate a specific file type right now but don't want it connecting all over the net right? Maybe I don't have time to verify it's not nefarious. Maybe I just want control over what applications can actually phone home from my device?
- "Runtime permissions" is hit and miss. Some applications ask and then respect the answer. Others will just pop up the dialog over and over and over again until you accept it... which was not the point.
- READ_PHONE_STATE is still terrible. It's used by app/games to pause tasks when the user gets a phone call but... also gives away the number that's calling you! Of course, nearly every application then requests this. I don't get it, it's yet another obvious use case ("Let the application know the user is busy without leaking any data") that seems to have been glossed over. I thought by this point they'd have a proper IS_USER_BUSY permission that tells applications that you're in a phone call/whatever but doesn't leak any of your personal data *whatsoever".
At this point my next phone will be an iPhone/iOS, even though I don't particularly like them as at least security/sane permissions seems to mean something over there...
Does iOS have separate permissions for the different location resolutions or distinguish reading contacts from writing contacts?
No, and why should it? I'm a technical user and I'm not even sure what the different resolutions are. What is important is to know when an application is asking for location data. iOS permissions for location are a) Never b) Always c) While using. Those make complete sense to even normal users.
1) Has permission to read your contacts 2) You can access an OS level contact screen to choose a contact but the app can't read the list of all contacts 3) Has permission to write to contacts (remember when facebook changed contact to have a facebook email address? Would prefer no permission)
Photos. Currently it's all or nothing. I'd prefer
1) can write new photos 2) can read old photos
Taking a photos right now is "can access camera" where as I'd prefer no camera access for most non-camera apps (facebook) and just a way to launch a system camera. I don't want apps to have the ability to keep the camera/mic on without my knowledge but "can access camera" = can use constantly without my knowledge while app is running.
Yes I know I can get around some this by doing it manually (don't give app camera permission, swap to built in phone, take picture, do give permission see 100% of my photos, hope they aren't uploading my private photos, choose photo I just took).
It's not enough IMO especially in this age of the revealtion of all the apps that spy
I think 2 can be integrated into no permission passing some sort of Intent to the iOS address book framework.
Similarly, permission to read photos on a one off basis can be integrated into no permission. The user should get sent to Photos app and the photos app could ask them whether the user would like to share a particular photo or a particular group of photos with the app that sent them there and with the user's permission the iOS system app can pass the data back to the requesting app.
Sort of like what you said with
> Taking a photos right now is "can access camera" where as I'd prefer no camera access for most non-camera apps (facebook) and just a way to launch a system camera. I don't want apps to have the ability to keep the camera/mic on without my knowledge but "can access camera" = can use constantly without my knowledge while app is running.
Yes, I absolutely agree. I'd go as far as to say even Instagram doesn't need camera permission.
On the other hand: Everything can now steal my data "just" so adverts can be shown. Really?!
To me that's more outrageous than the original points I listed. My device and my data are left permanently insecure, all to protect their adverts. Even though I purposefully don't use applications with in-built advertising (because they can't be trusted with permissions), I can't easily turn this off.
This really makes my phone suddenly feel like "A rented device who's main purpose is to deliver advertisements to me" instead of "Owned device that helps me managed my life and communicate".
> its a difficult business decision for Google
It's a really easy business decision: User security, user privacy and user control are king. If each application wants to tie "functionality working" along with "internet access" and "advert was displayed" than each application can implement that for themselves. It's not hard.
That this is all baked into the actual OS instead with no (easy/toggle) method of user override is nuts.
You don't own these devices as long as someone else has root. This kind of crap is evidence that we are loosing the War On General Purpose Computation. A lot of people are scared of the power of a general purpose computer in the hands of the general public. Computers (especially internetworked computers) allow people to see throw scams, remove artificial scarcity, and work past propaganda. When middlemen feel their power is under attack, they tend to lash out in stupid ways to counterattack the perceived threat and reestablish their position.
In the end, the general purpose computer must be made back into an appliance, and the internet back into something closer to cable TV. I don't blame the average person for falling for this scam, as they are often ignorant of the underlying technology. However, a lot of people that really should know better have been distracted with shiny baubles and keep buying into these increasingly locked-down walled gardens, when they should be setting an example and working to educate others so they have the information they need when they vote with their wallet.
I am sure there are people at Google who are tearing their hair, screaming about these issues. But management wants more money, not security or privacy.
As long as people vote with their wallet and buy Google products, they are supporting this. Yes, "I just don't care" is implicit support.
I've configured security for a large variety of systems and I've never heard of a write-only permission. Read-only is often seen as a lesser right than read-write.
"By limiting access to resources on a per-app basis, App Sandbox provides a last line of defense against the theft, corruption, or deletion of user data if an attacker successfully exploits security holes in your app or the frameworks it is linked against."
As such, from the developer's perspective the ideal permissions system should actually be as fine grained as possible to let the developers minimize the exposure of their apps. Android's permissions system was probably designed from this point of view.
This is why such things should be enforced in the OS, with a strict security model, and such shady permission overreach should be frowned upon.
Instead of creating a new 'access contact permission', the permissions are now bundled automatically.
That way the same manifest (where you declare a bunch of things about your app, including its permissions) can be used for both old and new devices.
As far as the manifest is concerned, it would have been easy to automatically generate the old permission list from a new permission list like {Contacts, Calendars, ...} but you would also have to create a new library to translate these new permissions to the old ones in the code (since old OS versions still only understand the permissions that existed with them) ...
It is probably easier to just keep the old permissions.
IIRC, I needed to identify a couple of states :
- when the user is on the lockscreen.
- when the user is in another app.
- when the user is in our app.
- when the screen is off.
There were business reason behind this for a complex feature, nothing to do with the user's data.
The Android team does not want android devs to access to their own app UI state because 'the business logic should not have to depend on that' ...
Fair enough in theory but in practice there are a couple of times when you just need it.
For example even the Chromecast sample uses a ugly hack to access this piece of information (put a timer behind start/stop activity events).
I remember that a coworker had to revamp this piece of code recently for Marshmallow but I don't remember the details.
Google finally has a working permission model with Marshmallow : protect the private data behind popups, everything else is fair game.
It is not perfect by any means since users still tend to click yes on any popup ... but that's the best we can do IMO.
And google is no less: https://www.privateinternetaccess.com/blog/2015/06/google-ch...
Uber doesn't try to pull anything like this on iOS.
It's likely they don't try this on iOS because iOS simply doesn't have the APIs to do this under any permission. It's a philosophical platform difference about what the user should be able to allow apps to do.
What caused the engineer to be mistaken about this? What library?
Considering Uber's history, expecting people to believe a claim like: "one guy acted alone in an oopsy", without providing a more detailed report, is a bit optimistic.
In a company with thousands of employees, already scrutinized for privacy violations, it's hard to believe that a single engineer could ask for the most sensitive of permissions without anyone else reviewing or bumping up the chain first.
2. The change likely would not have been made had people not complained.
This is why I am reporting excessive Android permissions requests, both to developers and publicly. I've succeeded in having several other instances of expansive permissions requests rolled back. Others not so much (e.g., Wikipedia).
3. I'd argue that this only further highlights how broken the Android permissions systems are if applications can request unnecessary and highly dangerous and invasive permissions without the awareness of the authors. I love a few things about my Android device, but few of them specifically pertain to Android.
4. As I've mentioned already: Google need to reintroduce their applications permissions blocking tool which was released AND WITHDRAWN in 2013. For all prior versions of Android.
5. Someone really needs to kick Google's ass with a a) Free Software b) user-first c) privacy-respecting d) security conscious operating system for small mobile devices. Maybe Microsoft can be talked into funding Ubuntu Mobile or FirefoxOS.
The fellows at https://copperhead.co look to be doing solid work.
#AndroidPrivacy #CreepyApps #AppPrivacy
???
The apps on Android should be sandboxed and not be given this kind of permissions, that's all.
This is one reason why i use Firefox on Android (another being the read-it-later feature, and option to add other search engines easily).
The unfortunate thing is that it is bundled in the same group as 'running apps'.
I guess it is because Android's PMs wanted to limit the number of permissions groups but it means that many apps have to request it simply because they need GET_TASKS for old devices.
Just forwarded to some friends, they are uninstalling the rogue app as I type this!
First : sadly most users (and I really mean most) don't even glance at the permission screen.
It makes it hard for us Android devs to push back against the product teams when they want to add a crazy feature needing a ton of permissions (I still do though and the fact that it breaks auto updates at least is a good argument... ).
The weird part of the permission system is that we have to transition from a 'designed by & for engineers system where there were a tons of different permissions that no users ever read to a granular system where you only need to ask user's permission in order to access private data.
IMO the platform is definitely moving in the right direction (if only because it apes the other platforms approach).
I use Android Lollipop and even if the permission didn't allow them to see I was using Lyft, I wouldn't be suprised if they're trying to re-engage "hesitating" users and are snooping for whatever data they can.
What we desperately need is a UL for privacy. Just like UL tests electronics, we need a lab to test these apps for what data they access and how they make use of that data. Then assign a score so consumers can chose not to use services that request unnecessary permissions and misuse your data.
Look at how popular adblock's becoming.
If you treat a smartphone as a normal computer, you would expect to be able to use a service such as Uber by means of a modern web browser providing a sandbox for their web application, like you do on Linux, Mac OS X, or Windows. Installing someone's stand-alone software only to access an on-line service would probably seem invasive and absurd.
Broadly speaking, on a smartphone people probably accept this because of the trade-off. Apple and Google keep your mobile computer stable, fast, and free from viruses and malware by managing your operating system and vetting the software you can install through their app-stores. For a lot of people this trade-off seems preferable to an alternative.
I can't find a page from the official docs from my phone, but there's a list of permissions on Stack Exchange: http://android.stackexchange.com/a/38389/150855
Just say no to an Uber install, even with a throwaway (TOS-violating) Google account.
We know they can do this. We also know they don't care.
The challenge is to make them care.
https://www.eff.org/deeplinks/2013/12/google-removes-vital-p...
http://android-developers.blogspot.com/2015/08/building-bett...
That's precisely the current problem.
Which is why Google needs to fucking fix this retrospectively.
It's possible that these permissions are used in some obscure place in the app. With the new permissions system, you can progressively request permissions when you need them, so it's possible it will request these at some point in the future, but the app seems to run OK without them.
I also disabled access to contacts, which the app does request for some reason.
They request 'running apps' only from this particular subgroup. Notice the wording on the original screenshot: 'one or more of'.
TLDR they don't request browsing history, the Android permissions screen on update is confusing
EDIT: There's another comment in the thread that indicates that this retrieve running apps permission actually doesn't do anything on Lollipop+: it just returns the app's own windows. Which would explain why it was moved to the "Other" category.
There's a standard intent to select a contact for purposes like that, and then the app only gets access to the information of that contact. Apps requesting access to contacts get all contacts.
On IOS, yes, uber asks for access to my contacts list, I click 'no' and uber works just fine (modulo the 'spam my friends' feature, which I didn't want anyhow.)
On an android, my understanding is that I've gotta chose between giving uber permission to spam my contacts list and simply not using uber, which is sad, because uber is way more convenient than a yellow cab.
This contributes to the perception that because IOS is paid for up-front, apple is willing to do things that might make apps less profitable, if it makes those apps better for the users, but that Android, because it is paid for by advertising, is less willing to side with the user against the app providers/advertisers.
Unfortunately apps have to be build against the new API, so it does not happen automatically for old apps.
hm. Perhaps I ought to research this; the gear VR does seem really great, especially if you can somehow wire a text editor into it. (I already have a bluetooth mechanical keyboard)
[1]https://www.eff.org/deeplinks/2013/12/google-removes-vital-p...
One time bookmark import is a thing I suppose, but that's different than gaining permanent access once granted.
I use two phones, but I have both apps on both.
And then of course they have their twitter phone, and their facebook phone and...
-------
Android Uber app code has many suspicious places. For example, it contains a namespace "com.baidu.frontia" and classes there include such code as:
localObject = ((TelephonyManager)localObject).getSubscriberId(); // gets IMSI
((TelephonyManager)localObject2).getDeviceId(); // gets IMEI
localObject1 = ((WifiInfo)localObject1).getMacAddress();
public static void makeCall(String paramString)
public static void sendSMS
Also there is the code that collects information about cell towers, mcc and mnc codes, scans wifi networks.I looked quickly through the code and it seems that those methods are never called. They are probably just a part of a library not used in this app. Uber mostly uses baidu maps, authorization and payment API.
Uber also does UnionPay as a payment option...again, same app.
On the google store site.. when browsing apps, there should be a tab on every app page, where i can see a sample of what it collects and a declaration of what it does with that data.
after installing the app, in the app manager, i should get a tab where i can see what its grabbing from me.
right now we got strangers going into our bedrooms borrowing something they wont tell us what it is.
and really permissions dont help a lot when it comes to this. Yeah my bookmark dup cleaner has to access my bookmarks to clean.. so i give it the permission, but does it keep them? does it sell them? i dont know permissions arent that detailed. if there was a privacy tab that i could check...then i would know.
People hide nanny cams to watch the nanny. Its because they gave her permission to have access to the house and kid and such.. the cam is like my privacy tab. it makes sure she doesnt abuse the permissions. We KNOW she needs access to the house and kid to do her job.. we just dont want the kid molested. well I dont want my data molested.. So google please give me an app nanny cam.
Another example is phone state https://arnowelzel.de/wp/en/android-and-read_phone_state (games use this to adjust volume to not drown out calls). There is a replacement, but it's not well known.
If I want to keep control of my privacy there are so many apps that I can't trust to install. Even little dinky games are asking for access to contacts and messages and all sorts of other things.
An application on a desktop computer that steals data from your email application and sends it back to base is called "Malware". On Android, this is called "business as usual" from what I can tell. I don't know the app developers' reputation, I don't know anything... Except that someone in some other country has unbridled access to my phone.
As a result there are many applications I want to use and I just don't install.
It's not very cool.
What's the saying? Never attribute to malice with what can be explained by stupidity?
That way, you are neither under-trusting nor over-trusting.
Hanlon's razor
EDIT: On second thought, if it is a logical argument, it's a specific case of Occam's Razor. Which is more likely? Someone made a mistake, or there is a grand conspiracy?
- a mistake where misaligned incentives are against fixing it
- a questionable decision exacerbated by a mistake
- malice on the part of an external actor plus internal incompetence (essentially all data breaches)
Add it to your homescreen and you even get the glorious U logo back!
Frankly, a vast majority (99.99%+) don't care.
What's the thought on Uber having access to such data as browsing and passing that along to the feds too?
Care about privacy. Use Google products. Pick one.
other than that, i could not make these new permissions to trigger.
If the tactics are not shady, come out and plainly state it. No such statement has been made that I can see.
They are simply revolutionizing the old-fashioned and corrupt HN commenting industry.
Sure, malice does sometimes exist on these things, but most instances of this stuff in major apps turn out to be entirely benign. Ill-planned perhaps, but not malicious.
So it's not people with tin foil hats speculating that shills might exist - we know shills exist and are pervasive. Given that, we should have a certain non zero belief that any given poster is a shill. Not sure what is the best way to proceed when you know for sure that there are spies around you all the time. That's a bigger discussion. But jumping on people as if we should have to prove beyond a reasonable doubt that there's a shill is really counter productive and helping "them" win.
It's not only irresponsible but dangerous to take a guilty until proven innocent approach. You should expect somebody to prove it if they're making a claim. That's not letting anyone "win".
Look at profiles. Look for unusual voting patterns. Is it more likely that Uber is secretly watching and manipulating a forum for hackers, or could it be that a lot of people here actually quite like Uber as a company? Occam's razor suggests the latter.
Or maybe - like me - this story just seems shaky as hell with people not understanding that Android permissions (like license agreements) often over-extend themselves. That a permission requiring X doesn't mean X is being used. All the time we see things like "App requires contacts list" where it's only grabbing the owner's info.
Honestly, playing the shill card is lazy and irrelevant. If you have proof, show it -- otherwise you're just spreading FUD.
Why do Uber need that permission in the first place? What exactly are they doing with the permissions that are granted?
https://news.ycombinator.com/item?id=11465215
From myself in the past week. I've lobbied several app devs to remove/reduce permissions. I've uninstalled others.
Android's privacy model sucks. It needs retroactive fixes. Highlighting the problems is how that gets fixed.
They were lucky they didn't try the beta version of the new forthcoming uber app - that version wants access to the phones of all your friends, family, neighbours, your postman, the sister of the locksmith that helped you get the spare key last year, and the chap you met on the train to work last week called Brian. Still, go uber!
-iOS App Permissions https://www.uber.com/legal/other/ios-permissions/
-Android App Permissions https://www.uber.com/legal/other/android-permissions/
Question: http://i.imgur.com/K1mAtiH.png
Scripted reply that didn't answer question: http://i.imgur.com/m9sWJZR.png
Also, as mentioned in the post, https://www.uber.com/legal/other/android-permissions/ doesn't mention the new permissions.