TikTok privacy policy says they monitor names of other installed apps
tiktok.com
tiktok.com
Funnily only apple and its ad network now has access to the list of installed apps.
As an example, if I'm going to buy a "smart assistant", it'll be a Homepod instead of Alexa or Google Home. Not by brand loyalty, but by the nature that Siri may already be capturing all of that anyways so the additional data loss is minimal.
It works till their business is growing well. Guess what happens when it stops, but numbers still have to go up?
It becomes not a question of whether to trust some for-profit company, but which one.
Many people feel, and I tend to agree, that Apple is a safer bet than Google, because Apple (at least, at the moment) makes its money via hardware and software sales, rather than advertising revenue. They have significant incentives to protect your data and not share it, in a way that an advertising-centric company like Google does not have.
Of course, as Apple gets into the ad business they will erode this advantage, whether actual or just perceived.
They’re slowly boiling the frog.
Note - I do use Apple devices, so I’m also a frog.
Of course Apple can program in apps that look at your list, but do you have a source for this being used in their (upcoming?) ad network?
Why is that of course? I mean I get that technically they can do that, but should they be allowed to? If apps need to follow some sort of guidelines to be published on the App Store, wouldn't it be unfair if Apple don't have to follow those guidelines?
If you trust Apple to control the underlying software on your iOS device that, for example, is supposed to enforce all the other restrictions, then you are already extending them far more trust than you extend to any other app. It's not clear to me why that trust would end at a notional border between "the OS" and "an app".
I don't believe Apple ships any optional apps which have this level of privilege, let alone one which doesn't obviously need to have it. This is possible, but to the best of my knowledge it isn't the case.
Not sure if there's other mechanisms, but from 11 onwards, apps have to declare which other apps they will query through PackageManager https://developer.android.com/training/package-visibility/de...
That apps can do that this easily is a result of software deployment through a single channel in the first place.
We wouldn't need to talk about privacy abuses if phones wouldn't let apps do all the shady stuff at the first place, and if privacy controls were better.
The app is likely trying to protect itself from these clones.
I appreciate there’s politics going on, but also felt Pappas did not help her case at all with answers which were really evasive.
I don’t understand though: at what point is a decision taken that national security is more important than the business model of a few companies?
And yeah she was being super evasive. Between the two of them, there was no information transfer.
https://news.yahoo.com/josh-hawley-only-senator-voted-163304...
Apps can scan the device for installed packages that have opted to be “visible”. This is particularly common for apps that attempt to prevent rooted users from using the app. I would not be surprised if the iOS platform has similar functionality.
I’m not a fan of TikTok but this seems like it’s not a big deal.
It’s done for legitimate purposes, for example knowing which apps to launch for a given ‘Intent’ or checking for the existence of Google Chrome to attempt to launch a Chrome Custom Tab.
It’s normal functionality for mobile apps.
Now, if they are scanning visible installed packages and sending that data to their own servers for storage, that would be a story, but there’s no evidence that that is occurring.
By the way, love your username.
Isn't the whole point of 'intents' exactly that apps don't need to know what other programs are installed, delegating the decision to the OS and user?
Explicit Intents are also common and are used for a variety of purposes.
> What harm are you trying to prevent from preventing "rooted users"?
Bypassing $streaming-app DRM/accessing its downloaded files for offline viewing (to copy elsewhere and keep forever) is a fair reason I think (better if it would just disable that feature of course).
No idea why banking apps don't like it though. I assume they (or rather some manager, presumably not their Android devs) think 'rooted, uh-oh, hacker!' or something.
But it’s even more wild that the industry laps it up. Thank god the tech isn’t actually good enough to truly achieve the vision - a corporate wet dream and a consumer dystopian nightmare.
It's one of those things about privacy like Steve Jobs said: "Privacy is knowing what you sign up for". A lot of the time, the creepiness comes from poor communication. It's fair for people to assume something bad.
Somehow we made a change with our view at permissions to let or not-let apps access our files (storage permission), location and camera/microphone... but why the hell do we let them do all the other stuff (like this?).
There should be a giant popup saying "TikTok wants to see the list of all the installed applications on your phone, do you want to allow that? yes once, not now, not ever" and it's done. Then have the developers deal with the "monetizers" if it's worth it for millions of people to see that popup and question why does a video app need such a permission.
I am not saying this is a valid excuse to condone TikTok's privacy abuses in any manner. Just that we shouldn't lose focus that these types of abuses are becoming more and more common, and TikTok is just another symptom of it. The solution is not banning TikTok or some other company tomorrow, but a strong privacy preserving legislation to cover BigTech and future startups (irrespective of their origin country). This is a human rights issue - not a chinese or US BigTech one.
Source? This seems like it would be a pretty extreme breach of privacy.
Click on "What information do we collect?"
Scroll down to the section "Information we collect automatically " and the sub-section "Device Information".
This is what it says:
Device Information
We collect certain information about the device you use to access the Platform, such as your IP address, user agent, mobile carrier, time zone settings, identifiers for advertising purposes, model of your device, the device system, network type, device IDs, your screen resolution and operating system, app and file names and types, keystroke patterns or rhythms, battery state, audio settings and connected audio devices. Where you log-in from multiple devices, we will be able to use your profile information to identify your activity across devices. We may also associate you with information collected from devices other than those you use to log-in to the Platform.
One of the listed items is "app and file names".Personally I'd be more worried about these: "keystroke patterns or rhythms" and "Where you log-in from multiple devices, we will be able to use your profile information to identify your activity across devices. We may also associate you with information collected from devices other than those you use to log-in to the Platform."
Well this is something new to me. I understand how this can provide entropy, just I had not realized we are there yet.
Edit: Quick search gave this - "Understanding users' keystroke patterns for computer access security".
So it can be a security measure too. https://www.sciencedirect.com/science/article/pii/S016740480...
Otherwise, how could you be so sure about this?
I don't think keystroke patterns will be similar enough across devices to properly detect and track users, though they can certainly make an attempt. They'll be able to detect users on shared devices but I don't that adding much value to their tracking.
If Google kicks Tiktok out of the app store then that's going to cost them sales. They need to maintain an attractive platform more than they need to uphold the terms of service.
Apple risked banning Fortnite because the company started going into a direction that could cost them billions. The choice to ban is really no more than a calculation based on the cost of a lawsuit plus the probability of losing multiplied by the loss of revenue of said loss.
It's so tiresome to just see senators personally attacking executives in Congressional testimony.
Imo we're afraid of: (1) the algorithm's influence on our kids' minds (a health risk), and (2) transfer and mining of personal data for dystopian uses we can imagine.
For 1, are we ready to regulate what individuals can do to their minds (which we used to say books and tv could also hurt?) Maybe there's a case for it now. Let's debate it.
For 2, let's talk honestly about what we're okay with and what we aren't. Industry has decided these things are ok, but the law isn't super clear on it. It's mostly based on GDPR: -it's okay to use personal data to fix bugs and provide the service the user expects -it's okay to use it to secure and avoid fraud etc -with consent, it's okay to use it to do product development studies to inform how you build future features -with more specific consent, it's okay to use it for targeted marketing in the app or other places online -regardless of consent, any government whose country you care about can force you to hand the data over to law enforcement authorities.
Another complexity comes in with the vendors you share the data with for all of these purposes.
As a business, tell me what I can and can't do.
Most of the world's social media used to come from the USA and that wasn't a problem for the American government because they could control those companies. The EU was all up in arms against this but the USA did not care as there was little need to give any concessions.
The result was the failing of Privacy Shield and more and more American companies and services now becoming illegal in the EU. I bet the GDPR wouldn't have even existed if it weren't for Facebook and Google.
The fact your Congress is so afraid of what American tech companies have effectively been doing happening to them is quite telling. It confirms that every other country's actions against American tech giants is warranted.
As for your points: the shortening of one's attention span is quite noticeable if you use these apps for a while and then take a break. The constant dopamine hits of videos you like are addicting and are definitely having an impact on children. This is incredibly hard to regulate and I expect this behaviour to continue for quite a while.
As for your second point, the less data you collect, sell, or transfer, the less likely it'll be that you run into trouble. If you want to be sure about what you can or can't do without a legal advisor, assume that wherever the law is vague about something, it's probably preventing you from doing something.
For most American states the privacy laws are incredibly forgiving as long as you make sure to not have any children under 13 on your platform (COPPA) or collect health INFORMATION (HIPAA). California was the first state to set up privacy barriers but they're not as strict as other countries' laws.
If you (plan to) cross borders, though, you'll have to stick to the lowest common denominator or do some very creative corporate structuring. In many cases this also means setting up subsidiaries that cannot share any data with your American company and physically store the data in the legislative area as many countries ban storing customers' private data in a foreign country (i.e. in the EU, in Russia, and I believe in India as well). If you're afraid of giving user data to a foreign government, don't operate under those governments.
If you want to mine data like you're describing, get yourself someone who can give you legal advice. Tiktok is breaking the law in many places but unlike you it's got enough millions to burn on an eventual lawsuit and settlement.
I'm no lawyer but the simplest answer I can give you is "stop mining so much data unless your legal team signs off on it".