Anyone affected by this should be suing twitter for even collecting this information! My friend can give away my phone number because of this data collection.
Anyone affected by this should be suing twitter for even collecting this information! My friend can give away my phone number because of this data collection.
Generally what I see happening is apps will ask the user if it's okay, and only when the user says yes will they execute the necessary system call to request access. In iOS at least, if a user clicks No the app can never prompt for that permission ever again. Until the app makes this formal request to the operating system, it does not show up under privacy (as the app had never asked for it in the first place).
The native prompts don't allow for app specific explanatory text to be presented. I haven't reviewed iOS guidelines, but Google provides guidance to inform users of why you're asking for permissions before you do it, and I would guess Apple would suggest the same as well. Pestering people for access once a day is probably not within the scope of the guidelines though.
There is no good reason for Apple to allow apps to mask permission requests with their own dialogs, it’s just a case of not bothering to fix this loophole.
Not true. iOS apps can specify explanatory text to be included in the native prompt. In fact they are required to do this, since at least two years ago.
The NSContactsUsageDescription string (in the Info.plist file) is the place to specify this.
https://developer.apple.com/library/archive/documentation/Ge...
I would love a version of privacy.com for phone numbers..
> I would love a version of privacy.com for phone numbers..
I've used google voice and twilio for something similar, though nowhere near as plug and play as a privacy.com-like solution.
A cell phone number does not equal your kitchen phone in terms of access to information. The whole this is moot. The issue now is that this is my personal phone number, me, personally, and is being used as a piece of validating information in a variety of compromises databases.
I used it at a summer job in the late 80’s. You could order reverse lookup books for anywhere you wanted, and of course could get that data electronically too. You could also call information for anywhere you could think of by dialing the area code plus 555-1212.
With the twitter leak millions of phone numbers/names are available for free instantly, and the technology to do some harm with them is readily available.
Phone numbers used to be really public. As in "Someone has collected your phone number, your address and family name and put it in this huge book they update every year. And they drop a copy of this book on everybody's porch.".
You could always ask your friend to relay a message right?
It's not like I had glimpsed someone's shoulders and wanted to cold call them to pitch them my startup idea of the week or creepily ask for a date (I remember it was to follow through with a conversation about DIY hydroponic with one and coffee brewing with another). Friend got tired of relaying messages at some point :). We rarely got to the point of giving out contact information on the moment though (that was the flow of those meetings and I think it's not a cultural thing to exchange business card in such settings in my country). Also, we are not the kind of people to hang on facebook, so discovery is weak.
Totally agree it is correct behaviour with strangers though.
And it was only a minor annoyance at some point so well... no biggie. (Except that time he divorced and he wouldn't give me his ex-wife's number so I could get back some DVD she had borrowed)
edit: also, I wouldn't ask for contact info if I wasn't confident that it was okay for the person to get a call from me and I am confident that my friend knows I won't mess up things by being inappropriate.
I've had several friends ask if it's okay to give out my contact information to third parties who were interested in acquiring this information to continue conversations through more private channels.
But there was always an element of consent involved on my part.
The message your friend could have relayed could have been “hey is it ok if I get your contact info?”.
What your friend isn’t getting right is that maybe you and his friends DO want to contact each other. He is deciding for both parties that they don’t. He could adjust his behaviour on that front a bit.
Is there a reason you do not ask those people for their contact information directly?
As long as one of your friends or relatives has and accepts to upload their contact list (with your number included).
I don't share my contacts with any app, and I hate being asked again and again for every single new app. No means no.
Given the ramifications on leaking Name with phone number of people who didn't agree directly anything with Twitter and just had there contact details trawled by any of their friends signing up. Not good as with that, hijacking phone numbers has been done many ways and times, even the CEO of Twitter had that stunt pulled upon him. What with 2FA for many being a text message sent to your phone number. The ramifications of this could be bigger than they first appear and remember. They only found this, how long has this been open to such abuse. So anybody who had their phone number hijacked in X period of time, this `might` be a possible explanation in some of those instances.
Legally - no idea how this will pan out, but certainly not be the last we read about this.
We should also sue companies who continue to use SMS as part of their 2FA system and/or for account recovery.
I don't use Facebook nor Instagram, and I only use WhatsApp for 3 Android users, the rest of the people I talk to I use iMessage.
That appears to be impossible for WhatsApp on Android. Someone wanted me to install it a bit ago, I refused to give it access to my contacts and it refused to do anything else until I did.
So I deleted it and we used Signal instead.
Meanwhile the option remains available to use a different app that doesn't behave that way.
Your local Apple device has a messaging app (iMessage) that can see all the contacts on it.
iCloud puts contacts on Apple servers.
I find it very weird to find, for example, my boss, or certain specific coworkers, on any social app. I don't want them to be able to find me either. This design decision of giving apps your entire contacts book by default has to die, and individual users need more choice instead.
If they are interested, then they'll find a way.
An app (such as whatsapp) getting access to all contacts is a valid use case, even though it doesn't apply to you.
Any proof about this claim? I use Twitter on Android and web frequently and I only refuse such request once or twice.
Bottom line, it doesn't "ask again and again every day".
Now those collected and leaked phone numbers will be available not only to Twitter and US government but to anyone wishing to buy them from hackers.
If you made some agreement as to how your friend could use your phone number and 'sharing with Twitter' is a violation then you could sue them I suppose. Annoying as this data collection is, labeling information about you as only yours is incorrect, it's your friends and Twitters's (and Google/FB/AMZ/etc.) information too.
But I doubt there is much incentive to even create a legislative basis for such transgressions. Complicated topic to be fair, but we will only see improvements if there are severe penalties for "loosing" data. Since no system is safe, there is only the alternative left not to collect info you do not need.
To be clear, this applies to the Twitter app for iOS and Android, correct?
I exclusively use the Twitter web interface (even on my Android phone) and I have never been asked this.