This should be posted absolutely everywhere with this as the hook. This type of request and the admittance that companies give even more than that all the time is headline news worthy.
This should be posted absolutely everywhere with this as the hook. This type of request and the admittance that companies give even more than that all the time is headline news worthy.
I am constantly, constantly bombarded with "this looks better in the app! please just run our app!!" as I browse. Still I refuse--with the web I at least know they can't harvest information about everything I'm doing. There are still some privacy concerns of course but it's much better to have the web as a firewall of sorts.
We have 30 years of browser UX development, culminating in tabs and multitasking tools that allow you to open things to read later, wait while they load on a slow connection or form a queue of things to read.
Mobile apps for every social media site loose all of that. They are worse than useless. There is this internal fear at social media companies, they want to prevent their users leaving their little walled garden. That or the religious drive for managers to reach target metrics creates a net negative feedback loop for user satisfaction.
Social media apps have no multitasking features (at least last time I used them). It's absurd.
I've only used the twitter mobile website for the last three years. Will never install the app again.
(Aside: my (ridiculous) conspiracy theory is that React Native is an attempt to distract developers from the advantages of a WebView based app development process that would eventually lead to the success of PWAs, locking devs into the app stores as a distribution channel)
I remember the couple months or years where each Chrome tab was it's own app instance. I thought it was incredibly ambitious & interesting to make the OS try to deal with tabs, be a manager. And indeed Google backed it out. And so as usual, Android is in the background of daily life, hardly ever touched or used, and I just stay in Chrome almost all day letting it define every bit of my computing existence.
The web experience just has so many more hooks & so much more power, than these little self-defined bespoke inward experiences. Because so much part because browser gives us such basic & flexibility utility as we compute & surf.
Thanks for the good post, enjoyed reading very much, & two thumbs up!
"This looks better in the app" because they sabotage the web experience so they can do this very thing.
- use bluetooth, accelerometer data, or anything else not exposed to a browser
- spy on their user closely to generate valuable data (your app is the product, not the user)
- be discovered in the apple or google app stores. Relatively expensive, niche, high touch, business to business apps are not impulse buys for bored managing directors.
And their dev team is usually already over burdened just dealing with the web stuff.
But still they pour money into the two native apps bucket. Before they're even profitable...
I wonder how much this "IT LOOKS BETTER IN THE APP" propaganda is affecting their business sense. Twitter and Facebooks business model is a bit different from B2B SAAS SME.
Recently a coworker was struggling to change some personal details online and got stuck in a loop of no access due to multi-factor authentication. The phone helpdesk kept directing them back to the site to get stuck again. The solution? In this case the app's lack of support was a blessing. Personal details could be easily changed there because the app hadn't implemented multi-factor authentication.
Our phones are packed with sensors, and are more powerful than the computers that landed us on the moon. Apps can be so much more than dumb pipes for simple data upload and download from a server.
Not sure if this changes your calculus at all, but it can (theoretically) be used on chrome for android.
There is a lot that a website can do to profile you too.
The webbrowser limits their ability to spy on you dramatically.
In what way?
What information can a native app get from a user that a website couldn't?
They also can't collect any information in the background they couldn't in the foreground. Like apps can't tell which apps you open, can't tell what info you put into other apps, can't track you across other apps etc.
Like the app has to register as being allowed in background mode, upon which if a push notification is sent to it the OS wakes it up for ~30 seconds to make an API call or set data. But there's no UI shown, there's no ability to track which app is open, or even if the device is awake or asleep. It's not like the apps are able to run code in the background whenever they choose.
not including apps with Allow in Background location permission, like bicycle tracking apps etc. but those are done with explicit permission from the user.
Apps don't have access to device IDs other than IDFA, which can be reset at any time by the user.
> wake/sleep/network events, etc
Apps can't tell if the device has been woken up or put to sleep, apps only have access to their own application state events like didEnterForeground and didEnterBackground.
Apps can tell if the device's internet has been connected or disconnected, I didn't know that was not possible on websites.
Web apps have a lot of access to your data as well, especially your location data.
This is not the case in iOS, and I don't believe it's the case in android either, IIRC. You can also always audit app permissions via the settings app.
> how do I revoke it
Settings app. No idea how I'd do it in the browser, FWIW. Nor how I'd audit what permissions an app has.
> it still running in the background accessing my location at all times
Apple has a "allow location access only while running [in the foreground]" option as well. Not sure about Android.
> Furthermore, apps update silently, and are they giving themselves new permissions or not with each update?
They are absolutely not doing this. Security auditors would be screaming from the rafters if Apple or Google allowed app updates to change their permissions settings.
The ethics course itself is a very small piece of the puzzle. Even if every software engineer had to take an ethics course, there's still a huge power imbalance between the average engineer and their employer. Ethics are great and all, but without a legally backed standard of practice to protect those engineers, widespread violations are more or less inevitable. You can stand up and refuse to do work because it goes against what you learned in your ethics class, but your employer can just find someone who doesn't feel as strongly about that. That still happens in traditional engineering fields, but there's at least a legal/regulatory framework in place to discourage it.
Some jurisdictions "solve" this by lumping software engineering in with other disciplines and making the same licensing bodies deal with it. This is also a big mess. Those bodies are normally led by "traditional" engineers who barely understand software, their standards/legislation were written before software-specific issues (e.g. mass surveillance) were relevant, and their processes don't move fast enough to deal with a rapidly changing field like software engineering. It may be possible to fix all this or create similar organizations and legislation specific to software, but it's not trivial.
> The ethics course itself is a very small piece of the puzzle...
Do you have any recommended reading regarding this part of the puzzle?
Sadly, there are very few resources; textbooks and professors qualified in software engineering and ethics, and the adjacent political, social and economic realms to fill this.
I'm really, honestly doing my best with this problem.
The subject area is massive. The issues are horrendously complex. The targets keep moving (each day we seem to set a new bar for what shitfuckery is acceptable).
Also writing a book on Ethics For Hackers that is not prescriptive or too personal value-laden is extraordinarily hard (and it makes it worse that I am an opinionated bastard)
HN remains one of my best resources for "pragmatic" ethics, and so I thank you all.
to, what, make sure it is forgotten by the time you graduate?
is there even any evidence that making somebody take a class on ethics will make them more ethical? most college courses are grading you on your ability to write about a subject, not on how much you care about it, or decide to alter your future behavior.
That seems a little dismissive. Did you forget everything you were ever taught? I doubt it. Maybe let's be charitable toward others.
> is there even any evidence that making somebody take a class on ethics will make them more ethical?
Yes of course. Same as there's evidence that teaching cookery makes better chefs and people who take a driving lesson crash their cars less. Education is a real, actual thing, as you well know.
> most college courses are grading you on your ability to write about a subject, not on how much you care about it, or decide to alter your future behaviour.
Most college courses are rubbish. They're training camps there to take your money and give you a piece of paper to boost your fragile ego. I know that because I'm a university professor. You can read what I think about the current state of education the Times HE.
Maybe one in five students actually take anything meaningful from school. They're the ones who care about stuff and focus on their future behaviour as successful individuals and members of society rather than on ephemeral "knowledge" or getting grades. Don't fall for the certificate scam and don't let schooling get in the way of your education.
> making somebody take a class
Now, that's a telling word you use. Not wishing to psychologise, but are you maybe afraid of someone making you take a class in this useless subject?
If so I agree with you. "Ethics" is widely abused as a stand-in for whimsical "policy" that can't be backed up rationally, or to conceal hidden political agendas. Many classes are tedious finger-wagging checklists and plenty of "ethics boards" are sham kangaroo-courts run by cardigan wearing Kevins and Karens [1] who sit down with tea and biscuits to decide the future of a department of PhD's based on how they "feel" about some keywords in a checklist (I've sat in those meetings).
You should be afraid of "ethics" when someone else co-opts it as way to tell you how to think.
That's not what my project is about. If you're sceptical about ethics in tech you'd probably like it. It's about ethics empowering you as a decision maker - to back that up with 8000 years of human wisdom - to be wholeheartedly motivated by projects that can make the world a better place, and confidently, courageously say no to tedious dehumanising schemes of extraction and surveillance that passes for computing these days.
[1] sorry actual Kevin and Karen
But I think by the time of starting third level education, something like this is too late to change someone's moral decision making, so I don't really think it had any effect on anyone in that course.
That's an interesting reflection. It depends on whether you see ethics as rational and actively learned, or formative conditioning.
It's why such a project is harder than I imagined, and also why I tried (only somewhat successfully) to avoid prescriptive narratives. The overlap between psychology (behaviour, which can be changed) and moral feelings is complex.
I think the best we can do is lay bare some uncomfortable truths; how people have seen things historically, what the likely outcomes of our behaviours will be, and how we delude ourselves otherwise.
What I see in tech is that there's a lot of "moral armour" - comfortable things we tell ourselves, distorted rationalisations, fallacies, short-term economic justifications - that kind of thing can be improved, unlearned and replaced by a better framework by appeal to the rational adult mind.
My best guess as to why people are so willing to act as if ethical criticisms are not valid is that the commenters self interest sees themselves as a potential future benefactor of similar actions and so they see the rational behaviour as being to defend it in case they could benefit from doing the same.
I'm not saying that people cannot ever be convinced to change their outlook here, but that doing so for an adult is a way more involved, individual process that requires input from people the person in question respects, which is way more than a university ethics course can hope to achieve.
Ethics and personal values are the same thing. It would be impossible to write a book on Ethics for [any audience] that didn't consist entirely of personal values. Similarly, since ethics are necessarily subjective, it is impossible to write about ethics in a non-prescriptive way.
That one's especially easy. They are exactly the same thing; mos is the Latin word, and ethos is the Greek one.
It troubles me when someone proclaims such glib ease. I read maybe 10 different sources, philosophy books, old and modern, and numerous debates on the subject precisely because some people think "oh that's easy" - a symptom of our deflationary society which itself is an interesting predicament.
What do those Greek and Latin words mean? Mos comes from "mores and customs" whereas ethics (from Ethikos) means character in the mind of an individual. That sets a distinction between normative and subjective standpoints. However "Western" sense this is reversed. We are comfortable talking about "your morals"my morality" as subjective, relative positions, but reserve the word ethics for something supposedly more objective, scientific, and therefore presumably more widely agreed.
And that's just the surface of it. Resolving the actual documented uses of "morality" versus "ethics" in case studies reveals a whole lot more. Some distinctions assign the qualities of rightness and wrongness to morality, but the terms goodness and badness to ethics. And then the are are the entirely subtle but profound distinctions Plato and Emmanuel Kant make about the mental/spiritual realm of ethics versus Aristotle's primary focus on how actual people might behave. Or a modern moral philosopher like Jonathan Haight's distinctions between morals and ethics.
The bottom line is it's not that important so long as you're consistent. However it is useful to have different concepts and to set them out as philosophical tools. So "especially easy" - I don't think so :)
I gave you the correct source. The -ic- in ethikos forms an adjective from the noun, just like the Latin form -alis that you see in "morals". There is of course zero semantic distinction between a noun and its own adjectival form.
If you look up "moralis" in Lewis and Short, you'll see a citation noting that the word was coined by Cicero as part of a protest against the idea that Latin was unsuited to the purpose of discussing philosophy (popular opinion at the time being that you had to use Greek for that purpose). It begins by noting that "mores [are what] the Greeks call ethe".
The Greek and Latin words are translations of each other, and both refer to habits and norms. It is true that in modern English norms are a distinct concept from ethics. (Not true in Greek!) But it is not true that in modern English morals and ethics are distinct from each other.
Make the end push to graduate require ethics classes to book end all the technical detail they spent the prior years absorbing.
I'm still waiting for ACM to audit the practices of Facebook, Google, Twitter, etc. and then apply penalties (conference and publication bans, membership revocations, digital library bans, etc.) as appropriate.
At the very least they should call out examples of unethical behavior - which currently includes many common practices in tech companies.
Sexual harassment is bad. Victims have an ethical obligation to report the harassment. The result will be HR protecting themselves, likely via moving the harassed person to a new team or making their life suck in other ways. The only path forward after is to fight, likely in/with the threat of courts. Social fall out (because a manager or their skip level's life got harder) is almost guaranteed. A product deadline may be missed. The blame is often directed at the victim and not directed at the person who was harassing. I have watched this play out multiple times.
In this way, reporting someone for sexual harassment is a sacrifice. So while there may be a moral impetus to report, there is a cost to do so, and the end result is not an ethical question, but a cost benefit analysis.
The cost benefit analysis is then hampered by short term vs long term thinking. If nobody reports it, the abuse continues. If everyone reports it, then some of the abusers would likely be punished. The individual cost of reporting is high, and so a person would rather move on than fight. The abuser then continues to abuse.
The end result is that the ethics themselves are obvious and uninteresting, but it is the economic factors and game theory factors that bring all the meaning to any type of pragmatic discussion of ethics.
It was not a "why do good people end up performing unethical actions, and how you can prevent yourself from equivocating and rationalizing unethical actions as well" course.
Can probably be related to email addresses too, and hence shared with every other mall with same ownership as well as the company that provides the free wifi.
e.g. Aruba, Meraki, ...
Sure, if they were giving your IP to a telCo who can map your IP to a name if you're a customer - that's identifying you.
It's HIGHLY unlikely this happened at the usual suspects (FAANG).
There are a bunch who basically pay apps to use their api and then take the data.
Apple was right to kill that imho. IIRC that was foursquare's pivot
There is also lot/lon in programmatic bid requests, but I don't think they're super accurate or granular and lots of fraud. (could be wrong, just from my small experience buy side using DSPs seeing lots of lat/lons being smack in the middle of a city)
[1] https://www.safegraph.com/guides/mobile-location-data-provid...
[2] https://developers.google.com/authorized-buyers/rtb/geotarge...
[3] https://fixad.tech/wp-content/uploads/2019/02/3-bid-request-...
They explicitly and unambiguously deny doing it; if that was incorrect, there would be a huge regulatory and public backlash. (Think of what happened with the Cambridge Analytica case, despite Facebook's hands being pretty clean on that). No disgruntled ex-employees blew the whistle on this but did on other issue), which suggests it probably didn't happen.
Selling ads is very profitable. Selling data directly risks that business for little gain. In addition to the backlash when that data selling were revealed, it risks somebody else using the data sold by Meta to outcompete them on ad targeting.
Companies typically don't admit to the public when they're engaged in unethical practices. Purdue Pharma is a good example.
Bingo. They're unlikely to be selling the data because those data are their secret sauce. They are as economically incentivized to build sociopathic models on you as they are to keep your data out of anyone else's hands.
If they know that, they can target those areas and then heavily advertise that they have better service than their competitors in those areas lol.
Historically they could do that by old fashioned research and surveying. But that's expensive. I imagine getting this data from everyones' phones is a lot cheaper and easier.
If that's the case, I don't think their desire is necessarily _evil_, but very misguided lol.
Also telcos only have data for their customers - this gets them access to competitors' customers.
Was not very precise. One of the "advantages" of 5G is a lot higher resolution for telcos. And I think even 4G was superior to "a few city blocks"
> telcos only have data for their customers - this gets them access to competitors' customers.
And this is the true reason for the request.
A mind-bending digital info screen, developed in partnership with Misapplied Sciences and dubbed Parallel Reality, will debut in beta form on June 29 near the Delta Sky Club in Concourse A of the McNamara Terminal.
According to a news release, numerous passengers can look at the same screen at once, and each passenger will see personalized flight information that the other people looking at the screen will not see, because they'll be looking at their own personalized flight info.
The Parallel Reality display conveys the same sort of stuff you find on traditional airport screens—about departure times, gate numbers, baggage carousel locations, and so on—but you don't have to scan lists of data because the screen semi-magically shows you only what you're looking for, while up to 100 other people are simultaneously looking at the same screen semi-magically showing them what they're looking for.
https://www.frommers.com/blogs/passportable/blog_posts/delta...
Perhaps I am missing something, but I don't understand the intersection of why telco's are involved in serving subpoenas and the need to know the physical location of users. Are you referring to a log of networks / DHCP leases their customers were using at any given time?
Telcos keep it because it helps them with network capacity planning and is incredibility financially lucrative when they want to sell the data. It's probably more to fill in their data product for malls and fine grained location than to do it for subpoenas, which if they had a choice would probably rather not have to do.
Well I know that in the UK it is a legal requirement, but not sure about the US.
Not sure what country you are in, though that is untrue in USA. Businesses keep whatever business records they desire, and some required regulatory/personnel data. Even if they have the data a USA attorney can try to argue that the request is unduly burdensome or too broad and ask court to quash subpoena.
Subpoenas are used to compel production of existing information. Speculatively creating info to comply with future theoretical request is not necessary. It's easier to not have the info and truthfully respond to subpoena with "no such data".
It's called a bluff.
(As an aside, it seems cute that the guy thinks the change in ownership somehow makes it "safer" for him to share inside details, but I'm glad he did)
If the change in ownership means "I am never going back, time to set that bridge on fire" he's absolutely right it's "safer". Or simply if he thinks "It is now acceptable to future employers to do this", it is also safer.
Or maybe it was something that he now sees as a greater threat, and therefore is worth mentioning even if is not safer or even riskier.
But I focused on reputational risk.
- the location logs would be collected by a simple application, witch imply the phone/phone OS itself can do that;
- they do refuse, Legal teams do not, but nothing state they can't satisfy the request TECHNICALLY.
In other words when people tend to disagree with my consideration of smartphone as macro-spy devices bought and kept up by those who get spied as opposite of classic spying gears should think about not only that, but what they do with their (well, not really their, since they are just formal but powerless owners) phones, things like pay taxes, act on their banks accounts, pre-heat/cool their cars etc.
Because such activities have a FAR bigger impact than mere position logs.
> This should be posted absolutely everywhere with this as the hook. This type of request and the admittance that companies give even more than that all the time is headline news worthy.
It's pretty well know, but it should be even more well known. IIRC, what's left of foursquare basically does that, lots of "free" apps do it (like weather, calculators, flashlights, etc.). It's the whole reason the "only allow location access when using the app," was invented.
Spamming this submission with that hook (rather than the parts that the OP had actual direct knowledge of) is basically just spreading misinformation.
Have any journalists and/or leakers exposed exactly what these tech companies are sharing? As much as I've heard about data collection and sharing by big tech, I feel like I don't see much in the way of samples or example data. Even the forced GDPR data releases I've seen haven't been extraordinarily in-depth. Surely there must be some articles out there that I'm missing?
* https://www.advanresearch.com/
It comes from the telcos directly (think Sprint phones with custom OS installs), it comes from popular mobile SDKs (e.g. why Yahoo bought Flurry), and it comes from apps who simply sell the data directly.
There is one journalist who actively covers this sort of PII/data-selling world: Joseph Cox at Vice [1]. The only US-based legislator who actively fights against this is Senator Wyden.
It's simple - an app asks for background location permissions, then uploads all the datapoints and timestamps the OS gives them to their servers, which is then resold with "anonymization" that just replaces any personal information with an impersonal unique identifier.
That's the reason Apple/Google have clamped down so hard on location permissions since then. But even a degraded dataset is still valuable - https://www.eff.org/deeplinks/2022/08/fog-revealed-guided-to...
I think that the answer to this is "yes, multiple times, often multiple times on the same companies up and down every level of the stack".
And some of the companies brag about their abilities. There was some surveillance company which was showing how Covid spread after spring break in Florida by gleefully posting screenshots from their tool that tracks individual phone locations.
Do you have a link? It's always sort of discussed as if everyone knows exactly what's happening, but I'm specifically looking for links that break it down.
https://www.cnet.com/tech/tech-industry/apple-unblocks-googl...
But Twitter had been tracking apps installed on a users iPhone until Apple restricted access to the API that they used.
https://www.cnet.com/tech/mobile/twitter-is-now-tracking-the...
The purpose of the API was for one app to send messages to another app. But it could be used to tell if an app was installed.
A data science company I used to work for got hired in 2017 by a large American telco to handle this exact same sort of data coming from antenna location to do better ad targeting.
The reason why Verizon or AT&T do not have the ad capabilities of Google or Meta is because they are giant incompetent corporations that are incapable of developing anything in any area that didn't exist in the 1980s.
There is some obsession amongst a subset of techies with knowing everything, and that extends to the daily minutiae of the lives of others.