Android Q will kill clipboard manager apps in the name of privacy
androidpolice.com
androidpolice.com
It feels like playing both sides of an issue to generate twice the traffic.
There's some pressure to resolve privacy issues so Google changes (breaks) something minor. Something that in no way impacts the top 10 of privacy and tracking issues, so they can carry on selling ads and using data unaffected.
Harsh considering the fact that Google has been dedicating resources to privacy and took important steps to that affect with Android O [0] and Android P [1] and now with Android Q.
They hosted a invite-only-industry-experts conference to understand the implications of wide-spread security and privacy issues with Android [2][3].
[0] https://android-developers.googleblog.com/2017/12/double-stu...
[1] https://android-developers.googleblog.com/2018/12/android-pi...
[2] https://www.blog.google/technology/safety-security/project-s...
[3] https://security.googleblog.com/2018/12/aspire-to-keep-prote...
You would think with all those privacy resources, Google would be able to stop itself from spying. Perhaps a few more conferences will help?
2.) Try this link then: https://apnews.com/828aefab64d4411bac257a07c1af0ecb (note that these studies don't cover the UI dark patterns encouraging you to give up your privacy 'willingly')
3.) Are we really going to pretend Google's spying is such a fringe idea that it needs a citation to be believed, and not their main business model?
(It seems like collecting information, alone, shouldn't count as harm? It needs to be used for some bad purpose or disclosed to harm anyone.)
First of all, the information is disclosed immediately - to Google. Then it's just a matter of how much more disclosed is gets.
Surveillance has been shown to chill expression (https://www.cjfe.org/how_mass_surveillance_harms_societies_a..., https://www.eff.org/deeplinks/2016/05/when-surveillance-chil...), and even just metadata can be used to easily find whistleblowers (https://www.abc.net.au/triplej/programs/hack/how-team-of-pre...).
Will Google now or in the future offer services to help "secure corporate IP" by finding whistleblowers? Is it wise to assume they won't? Keep in mind all the information they gather now will be kept for when they want to misuse it later. What if they get served with a warrant for that information? Such as by a government agency that's helping to quash unions (https://www.bbc.com/news/uk-43507728)? How certain are you that there's no company that, now or in the future, will offer services to employers to help identify employees with corporate-unfriendly political beliefs?
Then there is the simple fact that information is power, and used to amass even more power, such as when Facebook used data gathered by Onavo to decide which apps to acquire (https://www.fool.com/investing/2018/12/05/facebooks-onavo-sp...). So spying directly helps corporate giants maintain their monopolies.
And all of that harm is without an authoritarian government in place. What about countries that aren't so lucky as to have a mostly freedom-respecting government? How sure are you your own country won't join them in the next ~50 years?
Surveillance is a leash and collar around your neck - just because it's long enough now, doesn't mean you should wait to get it off.
I'm not into guilt by association.
So first show that Google spies, then show that spying is harmful, then show that Google's spying has done specific harms? You sure have high standards.
Now could you explain how the risks and dangers of surveillance don't apply to the surveillance done by Google? Are they somehow immune to government warrants? Are you privy to all of their business decisions, to know that they never abused their vast access to data to enrich themselves at the expense of others? Should we keep handing over all our data to them, and just hope that they'll stay benevolent indefinitely?
It looks to me like you don't want to understand.
They also have a lot of power that could be abused. I like to make a distinction between potential and actual harm, though. Almost everything you do in civilization involves trusting other people to do things for you. Including keeping secrets. Sometimes that trust is broken, but a trustless society isn't possible.
Google's goal isn't to prevent themselves from getting your info, but to prevent random 3rd parties from tricking you out of it. That would seem like a high bar to set a decade ago.
It seems to me Google releases features without privacy protections, which leads to som legitimate use, but also a lot of privacy abuse. People point out the privacy abuse, and they clamp down on those features. Obviously when they do so they are unable to cover all legitimate use cases immediately, so it’s useful to point out the edge cases they missed so they can work on supporting those edge cases going forward.
I'd much rather see background clipboard access as a separate permission classified as "dangerous", but I doubt most people won't just click allow till the prompts stop happening. Maybe things would improve if aside from a permission, a notification would appear each time an app is accessing/has recently accessed the clipboard, with the option to mute notification sounds about specific apps. That way, background clipboard access is discouraged yet still available.
They could remove internet permission from all applications except Google's own Chrome, with that reasoning.
Instead of removing clipboard permissions from all applications, make it a clear option so that the user can give it when needed or only to a specific application, for instance the essential clipboard manager -- that Android incomprehensibly doesn't have and never has, as part of its core. So far only third-party applications have provided this needed feature.
Bundling clipboard with Google's keyboard ( or others like Swiftkey ) that come loaded with unnecessary permissions ( like internet -- I personally never use a keyboard with that permission ! ) and analytics packages is certainly not improving privacy at all.
An alternative would have been to deny all network access to clipboard apps - thereby ensuring that they are not able to steal any data.
Yet they pick on an essential feature for anyone using copy and paste hundreds of times a day.
There is much more danger in rogue browsers, by far, than in a clipboard manager.
The solution is absolutely obvious. It isn't what they decided. It is just the first beta, but we'll see.
It'd be ridiculous to need to have a text file always open in another application with constantly used bits of text, code, or info, and switch back and forth as needed multiplying a simple workflow by who knows how much in operations and time.
The top clipboard manager apps have like 500k installs. Android had 2.7 billion users in 2017. If we assume that the Android install base hasn't grown and that the total base of clipboard managers is 10x larger, we still only get to 0.18% of users...
[1] https://play.google.com/store/apps/details?id=org.rojekti.cl...
What I use is an app called KDE Connect, which provides a shared clipboard with my desktop computer if the phone is on the same WLAN. It's neat. Really neat. And of course it needs network access.
Many require internet permission although it makes no sense. For instance all Google keyboards have internet permission. And most others. That something that can record and transmit every single thing one types has that permission, to me, seems insane and I certainly will use only keyboards that do not have such asinine requirement.
For example, the app could just open the browser set to http://myapp.com/?secretdata=Ultramanoids_password
How are you going to stop that? Have the browser stop and ask before loading the web page?
There are also a bunch of ways of doing it in non-visible ways by using API's of other apps
Otherwise, open source and on F-Droid there's AnySoftKeyboard [2] and even a build of Mozc [3], this last one unfortunately with internet permission.
[1] https://play.google.com/store/apps/details?id=kl.ime.oh
[2] https://f-droid.org/en/packages/com.menny.android.anysoftkey...
[3] https://f-droid.org/en/packages/org.mozc.android.inputmethod...
I guess I will be abandoning the one I wrote.