I'm sure if it was a smaller company doing a similar thing they wouldn't have been given such leeway as Facebook was for so long.
I'm sure if it was a smaller company doing a similar thing they wouldn't have been given such leeway as Facebook was for so long.
Until Apple starts banning all of these types of apps and libraries (which their recently updated policies indicate they just might [2]), I view this as more of a strategic play against Facebook as opposed to in the best interest of users.
[1] https://itunes.apple.com/us/app/my-data-manager-track-your/i...
[2] http://www.integrity-research.com/new-apple-policies-threate...
VPN-based data collection apps could just as easily be cleaned up if there was the will to do so.
It's hardly malware. Users should have the right to trade access to their data for free data compression, whether you personally think that's a good idea or not.
Even if it is clear in the app description that it is collecting data from users, I don't believe that the extent or consequences of such data collection would be considered or understood by the majority of its users.
It's a spyware product, wrapped up as a VPN, relying upon lack of attention from users to succeed.
Merriam-Webster says "software designed to interfere with a computer's normal functioning". Wiktionary: "Software which has been designed to operate in a malicious, undesirable manner". Etymologically, it means software that is malevolent.
This app collects data in a malevolent/undesirable way. It clearly tries to interfere with the personal data of the user and hence the intended functioning of the computer. Hence a malware.
This is utter nonsense. How many users are making an informed decision here? How many understand what their data may be used for or how it may affect their insurance, employment, or housing prospects in the future?
There's a reason some contracts are not legal/enforceable (slavery for example).
You can narrowly define malware by a quick dictionary definition[1]:
> software that is intended to damage or disable computers and computer systems.
However, malware also has a much looser definition[2] if we don't restrict ourselves to a one sentence Google result:
> Programs officially supplied by companies can be considered malware if they secretly act against the interests of the computer user. For example, Sony sold the Sony rootkit, which contained a Trojan horse embedded into CDs that silently installed and concealed itself on purchasers' computers with the intention of preventing illicit copying. It also reported on users' listening habits, and unintentionally created vulnerabilities that were then exploited by unrelated malware.
Now people defend almost the same practices (in a nicer package) on Hacker News.
We are truly fucked.
Google collects a lot of data [3], including app and website usage [2] too. They have full access all the analytics a phone OS can provide, after all.
I'm not saying this is ok, but if we claim this is malware then Android is malware too. I rather reserve the malware label to software that is directly designed to harm.
PS: Apple collects app usage too [1], but IMO they're at least more clear about it.
[1] https://support.apple.com/en-us/HT202100
[2] https://myaccount.google.com/activitycontrols
[3] https://privacy.google.com/your-data.html
EDIT: Why the downvote? Rather than downvoting, some constructive discussion on spyware and business practices would be IMO more welcome.
Sure, it is. Or spyware, at least. So is Windows.
> I rather reserve the malware label to software that is directly designed to harm.
Stealing data is harmful. I mean, consider the OpenSSH user enumeration vulnerability.
It is? Android is completely ridden with dark patterns[1].
> 2.5.14 Apps must request explicit user consent and provide a clear visual indication when recording, logging, or otherwise making a record of user activity. This includes any use of the device camera, microphone, or other user inputs.
So did Onavo "provide a clear visual indication" whenever collecting data? Somehow I doubt that, because it would have been a constant warning.
Do you have any proof of this?