It's really hard to believe this point given that... getting mad seems to have worked.
It's really hard to believe this point given that... getting mad seems to have worked.
Webex, Teams, Slack are the only ones that matter.
Yeah some companies are behind the curve (not blaming you).
Zoom is getting very popular
"Top of page 21- In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."
Check any news outlet to know why, and you’re likely to also read about zoom in some article.
No.
That's all that really needs to be said about it but I'll add a couple of more lines here so no one thinks I'm lazy or posting a shallow dismissal:
- First, just because someone trusts you it doesn't mean you are free to abuse them. This should go without saying!
- Second: In Europe and I think California as well this is also illegal.
We’re all stuck inside for a while, this is the perfect time to act. One app and SDK at a time.
During covid nobody is paying attention and we have the additional problem that they're trying to use cellphone location data to enforce social distancing! Once this is in effect it will be difficult to undo because the next epidemic will be "just around the corner" ...
write a blog post?
take it twitter/HN/reddit?
hold a rally/demonstration outside Apple/Google?
call our MP?
bombard their employees with phone calls or knock on their front door where they live?
write malware?
... really I got nothing that sounds like it would work. In retrospect all of Tim Cook's privacy / security grandstanding and attitude of superiority was just that. There are no good guys in this game.
We're outgunned by the lobbying from these companies I think.
In this very thread we started from “I can tell you from experience that everyone does this.”.
Now when a PO will be asked to add facebook in its app (or wants to remove it) there is at least one prominent instance to point to showing that having the SDK is not the right move. And hopefully that “everyone does it” will become “some still do it”.
If of course in the meantime we find a working systematic solution, it’s all for the better.
Compare to a system where you fix the incentives to automatically align everyone’s interests: e.g. bottle deposits, or a small fee for plastic bags. Now people will want to do the right thing, because it is aligned with their own interests.
The same holds here: fix this one instance with enough outrage, there will be a thousand more. Instead, let’s fix the misaligned incentives between app builders and users, so their invasion of my privacy costs them as much as it does me (e.g. GDPR).
This is how you make efficient markets: align incentives. Fixing everything on a case by case basis only provides temporary relief.
[edit: note that OP never said "don't do it", they just said "it's missing the point". which I think is a fair call. this one fix is good, but it's unsustainable.]
You know how these programs started? They started small. A few stores requiring them. Eventually, they become a law.
It isn’t. This is recycling one bottle. It doesn’t have any sustainable long lasting effect.
To stretch the metaphor, the equivalent of one store asking for deposits would be e.g. Apple requiring full disclosure of all such tracking SDKs on the App Store page, as suggested by someone else in this thread. That’s sustainable, scalable, and that’s what might eventually even lead to legislation, as you pointed out.
If California and the EU get wind of this, they may also give Facebook a gentle nudge.
That'll get Facebook to remove it fairly quickly, or at least stop triggering it in the background without user initiation.