Personal things like messaging history and contact information are certainly enough to build a 'social graph', but what Google does not let apps do is access the information that Google stores about me on their servers just because my friend has both my number and a greedy app on their phone.
Imagine what an app could do if they had access to your entire message history! (Why would anyone give apps access to their messages? So that they can send / receive special emoji, for example.)
Either way, discrete and easy-to-digest information like 'likes' are exactly what they wouldn't have access to from Google, and honestly it seems like automated sentiment analyses are still very error-prone; large corpuses of text don't seem ideal for this sort of targeting.
I don't think Google does that...
It's all privacy leakage but it's not at all the same data. Facebook's graph is still noisy but it's better or at least different data than other companies have.
Also worth considering, Facebook is all about social and preference ("like") data, but live location is something you can get as a mobile app and a lot of stuff can be inferred from where you live/work/visit.
Regardless of how dangerous Android permissions are or aren't, I do agree with the larger point that Google is scared about what will happen to Facebook, because it knows those regulations or even a "privacy revolution" that may come in the wake of this will impact it, too.
It's probably not even just this one event that will hurt Google. This sentiment has been growing over the past few years. If Google hasn't noticed it growing, then they are out of touch. If the anti-privacy trend continues, it will be bad news for Google, Amazon, Microsoft, and even Apple (which seems to be backtracking on some privacy features lately).
I do hope that at the very least the anti-privacy trend pushes companies to limit data gathering and use new privacy-preserving tech that doesn't allow them to look at the data at all. And I hope they do that before it's too late (for them).
Neither does FB I believe. Otherwise their business model of knowing more about you than anybody else would fall apart.
The scummy part was that the data was obtained using an app that’s unrelated to what the data was eventually used for, but Android is totally ripe for that as well.
The additional scummy part was that you could authorize FB to download that data for your friends as well as yourself, so your data might be consumed without you ever being aware of, or giving permission for it. As far as I'm aware Android has no such equivalent.
I don’t believe this is true. You could authorize apps to download a very limited amount of info about your friends. If you have a reference to some authoritative source that proves the opposite, do share.
Extraordinary claims demand extraordinary evidence, and all that.
https://techcrunch.com/2015/04/28/facebook-api-shut-down/
You used to be able to provide access to your friends photos, checkins, posts and more besides.
I've not seen anyone address this, but reading between the lines, many people seem to hold a view that the existence of these finely-grained personal data profiles at this massive scale is fine so long as they exist only on the servers of fb and goog, but why? What makes that acceptable or reasonable, besides the persuasiveness of large amounts of money?
I think the clearest path forward is that no one should be creating these kinds of data profiles.
I don't think a bot learning my route to work, or a doctor's appt(along with a swath of more "monetizable" personal info) so it can alert me to potential traffic delays is a reasonable trade-off for the massive societal problems the behaviour of creating these data profiles poses.
If this data is such a monumental danger when it escapes the permeable confines of the fbs and the googs, then it shouldn't exist within these companies either, not just because as we've seen the confines are quite permeable, but also because the potential for negative use of the data doesn't change depending on who has access to it.
It can be persuasively argued that simply creating and collecting these data profiles is itself a negative use of the data.
Nothing. And for now, Google's services are worth the data they collect. Facebook's value proposition is comparatively laughable, which might be why so many people are so upset with the scope of how their data was used.
And don't even get me started on how users, including those who have not signed up for the service, get tracked on massive swaths of 3rd-party sites if they don't take pains to prevent it - that's downright sinister.
Photos (on Android and iOS) contain a wealth of information, and any app having access to photos, can clearly figure out where you have been (based on photo's metadata containing GPS location), what you like to eat (if you take a lot of photos of food), where you like to hangout, time of day/week you do certain activities, purely based on image recognition.
Any wonder why Google Lens is integrated in the Google Photos app?
Add to that, the ability of identifying people from photos (Apple, Facebook and Google do it very well) and you can easily connect the dots, and it'll be hard to escape this kind of data digging, even if you are Jack Reacher.
Even pro-privacy Apple doesn't do much in terms of access to photos on iOS. If I want to share one image on Whatsapp on iOS, I have to give Whatsapp access to Photo Album. And once the access is given, a superficial scan can provide WhatsApp full info of locations from my photos, in a few seconds (even if it is 20 GB of photos).
Privacy on iOS in this aspect is bad. I can only imagine that Android is much worse.
The worst Android offenders, as always, are the big ad libraries that are installed across a lot of apps. They're able to build a rough personality profile based on the types of apps someone has installed. So they can generally say if a user is into categories like music or politics or comedy. But that problem exists on iOS and the web.
Android has also tightened up its permission model considerably over the last several years.
How do you know that?
I hope that local computing can get strong enough to do the same types of assistant type usefulness through local AI and peer to peer sharing. This will also estimate travel time, recognize appointments, etc etc. Open source to the rescue.
It depends on what you mean by exposed. In the context of Cow Clicker (or even the CA stuff) the data wasn't really exposed, it was shared. Google shares your private data all the time. Ex 1. Google+ APIs. Ex 2. Android APIs. Ex 3. Gmail API.
Allowing app developers access to information about a user is standard procedure (because otherwise apps would be terrible).
Many of these platforms (Android, Facebook, etc.) have, over time, tightened up the access to this information.
You could argue that "adding a browser keybinding" should be a separate API. You're not wrong (I'd love an extension like this to replace Ctrl+Q with Ctrl+Shift+Q), but browser vendors (at least Mozilla) seem to be very reluctant to add more APIs.
I was going to mention how I've been confused by people having overreactions like "it's just an extension to rewrite 'millenials' to 'snake people', why is it stealing all of my data?", equating the permission to read data from webpages with an implication that it will steal all your data. This never made much sense to me, since it seemed obvious to me that the required permissions for those things would have to be the same. In light of the Cambridge Analytica situation, though, I realize these fears were very well-founded.
They do have the technical means to offer more nuanced permissions. Things like "send emails and read replies on email threads it creates" or "access to emails matching this kind of search where new search terms would require a re-auth". It's not a priority though.
In their defense, millions of people were giving away their passwords to a bunch of external apps and the current situation is better than that.
[1] https://www.theverge.com/2017/5/3/15534768/google-docs-phish...
[2] https://lifehacker.com/unroll-me-the-email-unsubscription-se...
I assume that my name and date of birth are already public domain. They are listed publicly when you register a company. Insurance companies already share that information around anyway.
My issue is when Facebook sells my entire internet browsing history.
I doubt that very much. You also seem to ignore the lack of runtime permissions in desktop OS's such as Windows and Mac OS that could easily do the same thing.
>Every single Android app seems to require access to every single thing
This is a lie. The majority of apps ask for only the runtime permissions they need to work. Regardless, you're still in control of the permissions you grant and if you believe an app is asking for permissions which it shouldn't have then you shouldn't grant it.
. Second - if it's an app you already installed that has required new permissions, that app can run (via BroadcastReceiver) when it is updated and before you have a chance to alter the fine-grained permissions.
Separately, the interface for managing fine-grained permissions in Android is weird. You get most of them in one place, but then it seems you have to check a couple of other places for 'special' permissions?
edit: never mind this - it seems like the old version is the one that will get notified, and the permission change only applied ot the new one.
* * * IMO, which stands for In My Opinion. You are welcome to have your own opinion. Don't expect it to change mine. * *