Apple will require apps to ask users for permission to address books
allthingsd.com
allthingsd.com
"Better late than never..."
Why do people expect that Apple respond realtime to these kinds of things?
These are complex issues and tough decisions that need lots of thought and discussion within the iOS teams at Apple. These things take time.
Remember, iOS is deployed to how many devices now? 100 million? Do you think they can come to conclusions in between two tweets?
Honestly, having an answer ready in a week is not bad at all I think.
I think people believe that Apple should have considered the privacy implications of allowing Apps unfettered access to user contact data years ago, rather than only reacting when it becomes a PR issue that user-data is being misappropriated by shady App developers who appear to believe that making money is more important than the privacy of their users.
(My personal guess is that they did think about it, after all they introduced Location access permissions with iOS 2.0, but decided that an Android-style permissions matrix would put off end-users. In other words, I suspect that Apple made exactly the same decision that their App developers did: ease-of-use was more important than user privacy.)
Or they did that because of some stupid patent.
I think most people don't expect apple to respond at all. At least that's their standard practice with bug reports sent directly to them.
I've been a registered Apple Developer for about a year.
3.3.9 You and Your Applications may not collect user or device data without prior user consent, and then only to provide a service or function that is directly relevant to the use of the Application, or to serve advertising. You may not use analytics software in Your Application to collect and send device data to a third party.
So. These apps will be removed from the app store immediately, yes?
It is my understanding that a person's address book can be a trade secret, and is protected by law.
For example it's inexplicably implemented as a bunch of low-level Core Foundation calls even though it's not remotely a performance bottleneck in any conceivable use case and 90% of the apps using it immediately wrap every query result in some kind of half-baked Objective-C container. And although 99.9% of the code using it wants to use it a simple contacts database, the APIs are designed to be as general as possible and thus are even more needlessly hard to use.
My guess is there has been a "Do something about Address Book on iOS" item on Apple's to-do list for the last couple of years and this permission business always got pigeonholed under that item, until this latest shitstorm demanded a short-term fix.
It's going to be interesting how they implement this for existing apps, since there is no "The user said 'No'" return value for any of the APIs. I guess they're just going to have to return an empty address book or a "record deleted" result code when the user declines access for an app.
So Apple didn't make enough rules. That doesn't mean that the existing rules were ineffective. I just don't understand your criticism here.
AppStore = lots of "walls/rules", supposed protection, apps have free access to contacts
Market = few "walls/rules", but accessing contacts was a declared and required permission attribute
Apple's walled garden did nothing to prevent apps from freely helping themselves to contacts without user interaction or notification. Android didn't have to curate to solve this problem, they simply implemented it "correctly" at the platform level on the first go.
Frankly, I'm not sure what I think of this criticism of Apple anyway. Where is it declared that your Address Book is absolutely secret information? Windows doesn't protect my Thunderbird contacts, hell, Thunderbird doesn't even try to. Yet I don't blame them for spyware that steals that information. Quite honestly it scares me how much people are totally okay with being dependent on Apple and running to them for protection. It's a losing game this way. There will always be some sort of information, even if acquired via the user or declared permissions, that we won't expect them to want/use/sell. We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.
(My scare quotes aren't commentary so much as they are me trying to stay neutral. I don't know what is the "right" position on these things, frankly I don't worry about this aspect of my privacy that much, and I'm currently with an Android phone.)
edit: I guess my post changes a bit if it really was against the Apple Developer agreement to do this. I guess I would be miffed that they weren't enforcing and protecting against it.
They build the OS, why shouldn't they protect me? Is there a practical alternative?
> We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.
I agree, but many people expect stuff to be free and ad-driven. As soon as an otherwise honest developer drops in a fishy Ad framework, it's basically game over. I would be surprised if none of them would send AB data over the wires. They certainly send everything else they can get.
But more importantly, we simply don't know whether Android is actually protecting customers or not.
If people are just clicking through a warning and having their address book copied against their wishes, that may technically shift responsibility onto them, but it doesn't mean they are 'protected' by a 'correct' platform. It just means that Android is protected from accusations.
It's disingenuous at best to compare user privacy protection with the massive list of rules enforced by Apple for reasons that never had anything to do with protecting users.
(Don't want to start a flame war and I am not really an Android fan)
In theory, it is good, but in practice, it's broken.
The iOS way installs the app, but denies access to the resource.
How do you expect this to work otherwise?
You are representing it as though Apple asks for user's permission for every sensitive resource.
But since you're asking: I expect the permissions to be more granular.
And I would like to be able to revoke some of them if the developer allows it.
I think the android permission system is sane and reasonably functional. It's the users responsibility to read the requested permissions at install time and make a call.
There could be improvements here of course. I'd like to see a two tiered approach where developers could mark which permissions are optional and users could decide which to grant the on the first or each time these permissions are used in addition to the current method. I'd also like to see a requirement for devs to provide an explination of what each requested permission is needed for that could display on the market.
Hopefully these types of controls will continue to evolve on all platforms.
This would be SO useful!
I have an app that I want to be able to collect crash reports for. This means I need the "READ_LOG" permission. Thing is, the log CAN have other potentially private information in it, so there's a scary warning for that permission.
If I could ask for READ_LOG permission at run-time, and Android would pop up a box saying "This app is requesting access to the log to: 'create a complete crash report and send it to the developer'" or some such, then only the very few people who are actually sending me a crash report would ever have to "reveal" their log data to my app.
Another situation I've got is I'd like to use the the permission to act as your Google account to optionally grab some user detail from <some Google service>, but I don't want to scare off users with this permission.
The other feature on my permission wish list is some permission specific options like internet access to [urlmask1,urlmask2,...] or log read access to logs from my app only, errors and warnings.
Oddly; even when you (the dev) ask for this; Google prompts you (the user) at access-time to approve/deny account access permissions (similar to Google's OAuth prompts on the web). Seems that would remove the need to ask for the permission at install time as well.
The SMS permission in Android seems the most egregious to me. For example, an Android app you install requires SMS permission. However, in Android as it stands right now, the app does not need to notify a user when it sends an SMS - there's no requirement (nay, not even a widget to pop open and require the user to "Send" the way you see on other platforms like iOS--you've got to build this into your client yourself) to do this. So, you install a third party SMS client thinking you'll use it to send SMSes, but the app can send SMSes on its own, without you even seeing them. See also: http://www.cs.ncsu.edu/faculty/jiang/RogueSPPush/
Personally, while not perfect, I like Blackberry's model here (Cyanogenmod has implemented something similar) - the user can block out certain functions, knowing full well that the app will break - but can then decide to re-enable them if needed or once their trust level is raised.
I guess what I'm advocating here is a combined approach
- up front permission notification of android, but more fine grained
- activity alert approve/deny from ios
- selective permission blocks from bb except the developer can specify which permissions are optional so the apps don't crash when you disable random permissions, they just refuse to start with a clear message.
- parameters for some permissions to further narrow the scope like URL masks that you'll access over the internet instead of asking for full net access, etc.
It’s granular from the developer point of view, but it’s not for the user: when you install an app you either grant it all the permissions it requires (before you have a chance to actually run the app and see what it does) or you don’t install it at all.
With the iOS model (asking permissions when the app uses them) I can install an app, deny it permission to use my location and it will still work for everything else.
Also, how would that solve the problem if the Android developers forgot to add the ”read contacts” permission in the SDK? They would still have to update the software to add it.
It would be nice to allow or deny an app "optional" permissions (selected as optional BY the app) at run-time. It would NOT be nice for users to be able to do this willy-nilly. With the dozens of possible permissions, you'd have millions of potential combinations a particular user could enable or disable, and you'd need to be sure your app worked with any combination.
But worse than that is the fact that a lot of apps are monetized by ads, and disabling "INTERNET" permission would prevent ads from downloading. If I'm trying to make a living off of my app, I don't want to make it easy for people to get it for free. Some people will anyway, of course, but no need to make it easy.
I meant the Android OS developers (which is what happened with iOS here), not the 3rd party developers.
String READ_CONTACTS Allows an application to read the user's contacts data.
String WRITE_CONTACTS Allows an application to write (but not read) the user's contacts data.
So yes, if they HAD forgotten, then Android would have the same security hole. But it doesn't, because they took security seriously.[1] http://developer.android.com/reference/android/Manifest.perm...
iOS seems to only care about your location when it comes to permissions which worries me a little.
More granularity might be nice also. They could have a separate "names only" entitlement, or allow users to identify address book contacts / fields that should never be shared; that are redacted in content returned by the underlying APIs.
Important to note that this still does not address the wholesale detailed export and persistence of contact data by developers. Could be opp for a new provider there.
I doubt Apple will go this route.
This is one of these fundamental bugs where you can only wonder what they are smoking at google.
Instead of automatically scanning the code for actual API calls ("Ah, trying to send SMS here") they require the developer to manually declare their desired permissions in a separate manifest-file.
Unsurprisingly this has led to the current situation where every little "wallpaper clock" app demands every permission under the sun, and then some, without ever actually using them. Developers are just dumb and lazy like that, go figure...
So, my point is, android-style permission granularity is not a problem at all. Just make sure "can read phonebook" translates to will actually read your phonebook (hopefully soon in iOS) instead of developer is probably incompetent (Android).
It's not perfect by any means, but the system does seem to be working reasonably well for what it is. It's certainly a step up from, say, desktop Windows' UAC implementation.
EDIT:
Come to think of it, the problem with UAC is more or less the opposite of your complaint about Android's permission system -- apps don't ask for permission unless they need them with UAC, but UAC doesn't do a very good job of communicating what the app needs permission to do.
That may be true, but it's not showing a big effect. Pick two apps randomly from the store and you'll probably be asked to grant all sorts of unrelated permissions both times...
developers explain in app descriptions why they're requesting certain permissions
Yes, that's another aspect worth fixing. The developer should be able to annotate each critical call with an explanation. Although I like the idea in the sibling comment even better; just raise a popup when the permission is actually used (for the first time). There will be some corner-cases but in 9/10 cases that should make it pretty obvious for the user.
Then you'll only bug the user if they use a feature that requires the call, instead of giving a list of permissions when the app is installed.
http://www.appbrain.com/app/lbe-privacy-guard/com.lbe.securi...
Should be baked in IMO.
Maybe you SHOULD know something about smartphones before you use them. It would certainly make users safer.
Most people aren't stupid, but they simply don't have the cultural background to understand how software works.
Address books are out of bounds. End discussion.
Permission fail.
I think a good compromise would be allowing an app access to phone numbers or emails without the rest of the information, eg whose number that is, their street address, etc. Then, giving your own number when you sign up could be an option. That way a new user's app could connect them to those friends of theirs who have opted to attach their name to their number.
With so many people syncing with their corporate groupware with their iPhones, how is this not a howling, category 10, shitstorm yet?
I really dislike the line of reasoning that the government should step in any time a company makes a mistake. If something egregious is happening, then let's get the government involved, but what we don't need, is Washington getting their panties in a wad and trying to craft some new legislation. We all know how that turns out.
Laws do not go away in the United States - they can get overridden or re-interpreted by judges, but they never leave the books once they're on them. Part of the reason why our legal system has so many pitfalls is that laws written in bygone eras intended for use-cases that no longer exist can be interpreted and applied to modern scenarios.
Consumers should vote with their feet and wallets by using different apps that don't misuse their contact information or perhaps a different mobile platform altogether.
I would rather see them stepping in and kicking AT&T (and friends) for 20c cost per SMS, non-free incoming SMS and abolishment of bulk SMS plans. Just recently I wanted to sign up for 100 for $5 plan, it's not there anymore, the only bulk plan left if $20 unlimited. This is ridiculous oligopoly and consumer exploitation.
But how soon is actually soon? 5.0.2 soon? Or 5.1 soon?
I can only wonder how many app developers need to update their apps to remove unnecessary and shady looking address book access. Even worse, I wonder if any popular libraries are slurping address book data that developers don't even know about. Analytics and advertising companies in particular surely couldn't have resisted taking a peek could they? How can you even tell if someone zips up and encrypts your address book? Maybe if you have a jail broken phone modified to detect that, but that's pretty unlikely. Look how many people use Path and we're just now getting wind of it.
http://isource.com/2008/07/23/aurora-feint-removed-from-app-...
The game was removed, but the (obvious) policy change wasn't made.
Almost all of the apps I use have no reason to need my addressbook data so it would be nice to know that none of those are secretly stealing it.
Android has had it since day one, isn't it common sense to assume that users might want to approve such access?
<shakes head>
iOS gives every app the same rights, Android presents a list of permissions without the ability to disable any of them. What's the difference? I suspect that the vast majority of users don't read that list anyway and just click through. Those that do read it and understand it have only two options - ok to everything, or don't use the app.
I'm afraid because it seems like these days everyone wants their apps for free with absolutely no strings attached. There's an entitlement on the web that you don't see anywhere else. On the web we expect to get the best, coolest, most entertaining, problem-solving, pain-point-eliminating products and services free and we expect the providers of those products and services to bend to our will in the way they operate too. So let's give the critics this one and say that yeah, it's absolutely necessary to ask permission first before accessing the iOS address book. Okay but what's next? We're used to going nuts about slippery slopes when it comes to the user but what about some companies? They're not all evil like some would make them out to be. Are we going to demand that Google stop showing ads because they're confusing or annoying when mixed with organic results? Will we demand the ability to post to Facebook and Twitter.. anonymously? Will we band together and force companies to add features that muddy already good products because a noisy few were, well, really noisy?
That's what I fear. I fear that the balance of power between users and developers will swing too far I'm the user direction. Make no mistake, I'm not saying a service provider should be able to do whatever it pleases with no say from users. I do believe, however, that there needs to be a balance of power (or influence, whatever you want to call it) and that balance should never swing too far in either direction. Its not often that I hear "I don't like that company/developer/service provider X is doing Y so I quit using them". Instead I often hear "they're doing X and I hate it do come complain with me and let's make them change that". That's fine a lot of times but I'm afraid that at some point people's sense of entitlement will grow too large and there will be outrage where none is needed and where the best course of action for a small minority would be to quit using X while the majority who are alright with it continue. In some cases like Google and Facebook the service has become so ingrained in our lives that it's hard to just quit using it and in those cases I'm willing to forgive a lot of seemingly frivolous outrage but in other cases it wouldnt be that awful to find an alternative.
I just wonder if one day the frivolous outrage of a noisy minority will ruin a product or service for the very content majority.
2. The "very content majority" are just people who, reasonably enough, never even thought about the possibility that apps were doing underhanded things like this.
Think of it this way:
A salesman is visiting a customer's home or office. The customer goes to the bathroom. When the customer comes back, he finds the salesman has picked up the customer's phone, called another salesman back at headquarters, and is going through the contact list and reading all the info out to the other salesman.
Will the customer be happy? No, he will not.
Will he be satisfied if the salesman then issues a non-apology apology ("we're sorry if you were offended"), claims that he was only doing it to "help the customer connect better", or tries to blame it on the customer and/or the phone manufacturer because the information wasn't locked? No, he will not.
In general, right and wrong don't change just because the action is carried out by software rather than direct human intervention.
I want a car for free, too, with no taxes and no insurance. Who cares what people want? Give them what you give them and they will decide the price they're willing to pay. No one is surprised when Facebook has all your contact information because you decided to give it to them. And if you want to give them access to your personal address book, you make that choice. They don't do it automatically behind your back.
The problem isn't that they're doing it, that's perfectly fine. The problem is they don't tell you. The very content majority will be just as content knowing it's going on. Asking for forgiveness instead of permission is much harder when the risk is your customer's trust in you.
I also wonder how much of this outrage is genuine and how much is just people thinking they should be outraged. Personally, I'd have no problem with apps getting the contents of my address book. Of course thats conditional but what I'm getting at is that this sort of thing isn't okay or not okay by itself, it's how it's framed that often makes it looked at this way. In this case it was framed as a terrible invasion of privacy with lots of room for security issues. What if it was framed as being awesome because it totally enhances the experience of the app? Maybe around here we're qualified to say "this is okay, that isn't" because of our knowledge and backgrounds but think of regular folks playing Angry Birds on their phones having no clue what a iOS is. I'm not sure they really have an opinion until you give them one and thats exactly what we're doing. So when you say they'd be just as content knowing its going on you're correct but I'm not so sure they'd come to the conclusion that it was bad while they didn't know totally on their own. I can totally picture a lot of regular folks finding out and saying "oh, they upload the address book? I didn't notice. Whatever." and continue on with their day. Of course that won't happen now because of how this is reported.
Anyway, I'm sorry to see so many people having such strong negative reactions to my original comment. Maybe I didn't make the point clear enough or maybe my thinking really is just way off on this one. Either way, I still maintain that these what-if questions will really get you thinking differently about this stuff.
The big thing is, I don't know Path as a company. They haven't been around a long time, they don't have a huge, trusting userbase. You assume that they have the information you've given them. You assume they use it for ads or other pseudo-anonymous stuff. What you don't expect is that they will be grabbing things off your phone that you didn't explicitly allow them access to. Programs on your desktop don't hijack the information from other installed programs.
Maybe the line of thinking is faulty for mobile OSes. Maybe it's a chance to start fresh and allow full access across all apps. But the main cry in this controversy is that the users want to at least feel they are in control, even if it's just "install and accept the terms, or don't install period".
Heath Ledger said it best, I think, in The Dark Knight. "Nobody panics when things go 'according to plan.' Even if the plan is horrifying!" Request from the users all the information on their phone and permissions to everything, then present them with an intriguing product. I'll bet a great majority of those who would have installed it would still install it because, like you said, it really does enhance the awesomeness of the app. A little truth goes a long way.
At any rate, this will likely be forgotten in short notice when the next outrage begins.
Maybe under EU privacy laws?
Good decision Apple.
Yes, I can see that an App Store makes it easier for people to install all kinds of apps. (I can also see that more people are going to have more extensive address books on their mobile phones compared to their PCs.) There isn’t really a handful of developers anymore (like there were on the Mac for the longest time) who you know you can trust.
And yes, spyware was also a problem on the desktop – but usually not one for high profile apps. If the developer was big and had something to lose you could be somewhat certain that they were not going to sell you out.
But no. More dialogs everyone will ignore anyway. Not a real solution by any stretch of the imagination.