Privacy respecting weather app for Android
f-droid.org
f-droid.org
Probably still will for learning but thanks.
"Per the terms of the .edu Cooperative Agreement, institutions applying to register a .edu domain name or seeking to renew a .edu domain name registration that was approved on or after October 29, 2001, must meet the following eligibility criteria:
They must be U.S.-based postsecondary institutions. This means that they must be postsecondary institutions located within the United States (including U.S. territories and possessions); be licensed, chartered, or incorporated within the United States (including U.S. territories and possessions); or otherwise be officially recognized as a U.S. postsecondary institution by a U.S. state or federal government agency (including U.S. territories and possessions). If an institution is not based in the United States per this definition, it is not eligible for .edu domain name registration."
One thing I see missing though is a mood tracker.
[1] https://play.google.com/store/apps/dev?id=479730765079191737...
I guess the absence of a "like" or review function in the f-droid app is a deliberate choice, but I'd love to see user feedback at a central, or at least easily discoverable, place.
This has been discussed [1],[2], and looks like it won't happen "officially", but a third-party site utilising the API and possibly organised like nexusmods, with posts and endorsements, say, would be nice to see!
1: https://forum.f-droid.org/t/reviews-feature-for-f-droid/1197...
2: https://forum.f-droid.org/t/discussion-thread-for-each-app-i...
Though it could use more users and reviewers.
* are Open Source (GPLv3) and their source code can be viewed an GitHub by anybody
* used minimal permissions
* do not neither tracking mechanisms nor advertisement
The app are made by students of the Karlsruhe Institute of Technology.
The ideal privacy respecting weather app would download and update a local copy of every location's weather, and any requests you made would never leave your own device. I'm not sure how realistic that is, but as long you trust the Karlsruhe Institute of Technology, the government they operate under, and that the data being sent to OpenWeather is non-identifying or that they too can be trusted with your data, then this is probably the closest we're going to get.
I have no problem manually enter my location once in a few months (or more likely once and for good for home address and 1-2x per year for vacation location).
Even if the traffic is encrypted if a remote server has to understand what location you're requesting data for, find that data for you, and then deliver it back to you, that same server will be able to log that and you're back to having to trust that they won't save and abuse that data.
An example which allows you to read Wikipedia articles from the server, without the server knowing which article you are requesting, exists here: https://spiralwiki.com/
I don't think something like this is in regular use yet, but it could become an interesting solution to reduce leaking user information.
This doesn't even make sense. How do you want a weather app to not send "locations you want the weather for"?
Also, updating a local copy of every weather place on the planet doesn't scale at all. There's so many places that it won't fit on a single device.
But I really think that you can trust an app made by a German university not to sell your data. Not so sure about US universities though.
You can also do it with multiple, independently operated servers, as long as they don't collude with each other beyond a given threshold. Then the queries and responses can be kept small. The private info in the queries is split between the servers, and the responses are recombined, using methods inspired by Shamir secret sharing in cryptography. That prevents the servers from learning the actual queries being made or responses being sent.
See:
https://en.wikipedia.org/wiki/Private_information_retrieval#...
At some point I had to use a china-based app (that i would normally not touch with a 10 foot pole) despite privacy considerations
Why? Because they had a widget that did the trick.
I could see forecast by the hour on the widget, including % rain by the hour and wind.
A user needs to be able to plan his day (or week) out with a mere glance. If I have to tap more than once foe this information, thats a problem.
Is it going to rain at the time im scheduling this lunch meeting? Will it pour during my daughter's little League game? Will the mild cold going to be frigid because of severe wind gusts?
Those are answers i need on my home screen, viewable at.all.times.
I commend weather app for their privacy considerations but its too basic to be useable in most use cases except for generic 'just give me temp and precip '
Scary stuff. The fact that a well-informed user would compromise privacy consideration to save a tap or two when checking the weather is why we're all probably doomed. Even the slightest inconvenience seems to outweigh any long term privacy implications.
Yet at some point I had a china weather app on my phone and i was quite happy w it. Since replies mentioned a widget is now available, will try it out.
:(
I have it bookmarked, so its faster than the phone itself (right now its set at the White House ZIP code)
https://forecast.weather.gov/MapClick.php?lat=38.895&lon=-77...
I use Weawow and Today Weather, none of them have access to Location, actually both of them have no permissions granted at all and works fine. I don't use apps which don't allow manually selecting Location.
Also, kinda surprisingly, Android has the capability to allow for different sources of data through different apps providing it. So they could have allowed for choice of weather service through other "apps" (even if those other apps provided no user interface). It's kinda sad how under-used Android can be tbh,
Web apps are nicely sandboxed, work on every device and give the user tons of interface features they are used to. Like zoom, copy&paste, bookmark urls (each city could be a url, parameters could be query string parameters) etc.
But maybe it's possible to use the other PWA support without the periodic sync API to cook up similar functionality?
A way more fundamental API they refuse to implement is the file access api. Which lets you build web apps that can open and save local files. With this API, Chrome is now a great application platform for which you can write software that can be used just like desktop software.
Also, I didn't even realize until now, but the app's functionality is available via the web (https://rain-alarm.com/).
The web functionality is not available if you refuse tracking so nothing there too ..
Your broader point is right though. It doesn't benefit the app devs since 99.99% of users just use the first-party search.
I generally release all of my code as public domain, but never publish the source code to an app.
The first day I got an Android phone, the first app I wanted was a flashlight app. After clicking through the permissions on some for a couple of minutes, I realized it was just going to be faster just to learn to write my own. It's just appalling that Google, the so called "master of search" won't let you filter results by permissions required.
None of my apps require more permissions than what's required, and some require none. And people give them 1 star reviews stating the "permissions screen is blank", or back when there used to be a popup with the permissions: "Warning! This app doesn't display a permissions popup!". They've literally never seen an app that doesn't require permissions.
https://play.google.com/store/apps/dev?id=479730765079191737...
Why the need to install an app for a simple query?
People are obsessed with them though, they're massively popular so I'm missing something.
I'm Czech and always looking for better weather apps. Mostly using our local Windy[0], which shows a comparison of the GFS, ECMWF, Meteoblue, and ICON models.
[0]: https://windy.com/
I don't consider Windy weather forecast app at all, I wanna see simple hourly forecast or simple day forecast without watching some animations and wasting my time plus it's horrible touch UI in general trying to see what will be temperature 24 hours from now through animation on phone.
It takes three clicks (yes, a lot) to get from the widget to the comparison of forecasts, which is my favourite feature.
Shame it seems you can't hide that animated screen completely since I don't really care about it, just wanna simple forecast + have radar in other app.
Btw. Weawow has also forecast comparison with easy access, after setting up the app/city you just need to open the app and tap on data source in bottom of screen which opens comparison screen with various data sources and their forecasts. Easier to read than Windy comparison.
Flashlight is literally 1 bit of information (on/off) and after that you can only add more sophisticated triggers (gestures, timers, etc.), which is why native OS functionality typically makes apps completely obsolete.
Weather data is a lot bigger: not only are there are a handful of different providers, but you could spend a lifetime optimizing the presentation of the data on a 6" screen (let alone a widget or notification). You can't possibly fit in all the relevant numbers so you have a lot of room for UX design work.
The app is simply called Yr and they have a website where you can find the apps (bottom)[0]
[0]: https://github.com/orgs/nrkno/
[1]: https://github.com/orgs/nrkno/repositories?q=yr&type=all&lan...
>NWS NOW is a FREE weather application with no advertising, no user tracking using the National Weather Service™ and National Oceanic and Atmospheric Administration™ public API.
https://play.google.com/store/apps/details?id=bbc.mobile.wea...
The “telling state of tech” may be that our hardware has outpaced our ability to socially reason about how useful weather data should be collected and shared, or not shared.
Transparency on the use of data is important to make decisions on this type of stuff. If a weather app requests access to my barometer to improve predictions, independent of my personal data, I would fully comply with that.
Individual and aggregated environmental sensor data could be used for so many good things. We can track storms, fires and floods, earthquakes, air and noise pollution, and save lives.
But it is abused by a greedy, unethical few, and so the systems can no longer be trusted.
Medical data, individual and aggregated, can be used to stop transmissible disease by detecting outbreaks, and improve our personal health through exercise monitoring and early issue diagnosis.
But it is abused by a greedy, unethical few, and so the systems can no longer be trusted.
Domestic data has the potential to manage energy, water use and air quality, keep homes safe from intruders, protect the elderly and babies.
But it is abused by a greedy, unethical few, and so the systems can no longer be trusted.
The pattern here looks like a tragedy of the commons. As engineers we can build systems with ostensible social utility which are then hijacked (sold, acquired, infiltrated) by "digital pirates" who turn them into systems of abuse (surveillance, manipulation and control). Each time the empty "assurances" are the same and the corruption predictable, inevitable and painful.
Perhaps it is time to stop thinking about "privacy" at the level of technical measures and permissions etc, and deal with corruption and abuse, which seems intrinsic to tech, at a different level. We have the mathematical/cryptological knowledge to build better systems. but it's the unethical few who benefit from stealing our data who don't want computer systems to be secure.
Corruption always happens for a greedy, unethical few, but with the right technologies, we can make such abuse very costly. That hopefully, would restore trust from most users.
and then you go on to say "but I would just like to not give folks privacy because it's much more convenient for me not to".
That's not tricky, that's called being a shark. You are making the world a worse place by reasoning in this way and an even worse place by trying to spread it to other people.
It's the same with fitness tracking apps, so many of them send health data to their servers, but there are a few (often paid ones, of course) that seem to store important data only locally.
Donkeyd, I find the privacy cards in the iOS app store to be an unreliable source. I will read the relevant privacy policy stating 'data not collected' to mean anything but. Do you know if the card self-reporting?
I am very reluctant to fitness apps and devices for that exact reason and I'd really like to see a privacy friendly app.
Bonus points if you know devices that can be used with local data only.
The major apps all have the ability to market weight loss products when you gain weight, for example, which is the thing I personally resent the most.