Popular Flashlight App has been secretly sharing your location
fastcompany.com
fastcompany.com
> "I wanted to install a led flashlight app a couple days ago. The one with 10 million downloads wants access to my phone book, internet, browser, etc. WTF! This is a LED flashlight app and it has an install base of 10 million, why on earth does it need access to the internet and phone book?! Arg, there is a total disconnect between useful apps and privacy! I do not know what the answer is, but the current system really grinds my gears!"
> "Imagine if you wanted to use the ls, cd, grep, tar, pwd, top, etc commands on unix and an "ad" would pop up, or maybe you would see it connecting to the internet. These are utilities too. Is this acceptable behavior?"
However, it should be that an app asks for permissions and as a user I can tick or untick each individual permission. I.e. does this or that weather app really need access to my contacts? Nope. So why can't just untick that permission?
Permissions on apps seem to be pretty much broken.
I Know it makes dev's life difficult but the capability does exist since Android 4.3.
This ticking/unticking just recently got much easier with XPrivacy app. It still needs root to install the Xposed framework.
[0] https://github.com/M66B/XPrivacy#xprivacy
[1] https://play.google.com/store/apps/details?id=biz.bokhorst.x...
[2] http://forum.xda-developers.com/showthread.php?t=2320783
Edit: I see Groxx already posted about XPrivacy two hours ago.
Consider potentially lots of:
if session.gps: show_ads(location) else: show_ads(general)
--
but for every feature of the application that could be using extended permissions.
--
This flashlight app is a bad example, and I'm not saying this is an excuse, but I think this is the rationale that is generally used.
Instead, it thinks it has a GPS, but you've decided to tell it that, for example, its "GPS" will always be e.g. times square or perhaps something a bit more realistic, but not real.
If developers try to coerce you into giving extra permissions, hopefully the average user will be smart about it and just delete the app. At any rate, your solution definitely sounds like throwing the baby out with the bathwater.
I actually just a got a new phone (Nexus 5), and the app is crashing on open right now, I imagine because I'm using KitKat or something like that. But that's besides the point.
Showing where you are in some city or other location is the best feature of it, what use does it even have without your location?
A flashlight app needing to read your contacts is obviously ridiculous, but a map needing your location is rather handy.
I appreciate that Android lets developers and users do what they want and lets Users know what the applications have permission to do, but if you have to snoop at every application's specific details to find this out, it's not really good for those of us who care about such things.
A big problem is some of the permissions have terrible names - stuff like "read phone state and identity" - what freaking user is going to know what that means?
I recently switched from iOS to Android, and the two readily available app stores on my device(Google Play and Amazon)are little more than a cross between a digital flea market and the wild west.
Google would do well to copy Apple's approach to app store curation and locking down their OS so that shenanigans like this can't be pulled off.
Apple's curated approach wasn't allowing me to find and install an app for a very simple need - completely blocking calls and SMS from certain phone numbers, without those numbers even showing up in the logs. My iPhone couldn't do tethering either, because it's an on/off switch accessible to your mobile career and my mobile career was charging an extra 4 EUR/month for it.
Also, people don't freaking read and we can pretend that it's somehow our problem, but what's so hard at looking at the list of required dependency and reading:
- wants access to your location
- wants to read your contacts list
What's so hard about asking yourself - why the hell would a flashlight app or screensaver want to know my location or my contacts list or whatever? Are people so dumb that we need to disallow them from hurting themselves?Android is not perfect and the permissions system could sure use some work. It would have been awesome if you could disallow certain permissions, but still install the app, in which case the app would simply not receive your location, or it would receive a blank contacts list and so on.
Also, people don't freaking read and we can pretend that it's somehow our
problem, but what's so hard at looking at the list of required dependency
and reading:
- wants access to your location
- wants to read your contacts list
The problem with this is these apps poison the whole marketplace. If I'm going to buy a car, I'm not going to buy it from somewhere where half the cars, perhaps the popular, good-looking ones, phone home to advertisers and track my location for profit and where it is my job to read all the paperwork to check which ones do and which ones don't.The reason why the App Store has been so attractive to developers is that it has engaged users who know the downside of installing random app Foo is not high. If we train users to be wary of apps, it will not be good for hones developers of good quality apps either.
> If we train users to be wary of apps, it will not be good for honest developers
So what you're saying is that users would learn to not trust implicitly random strangers making promises in exchange for cash and that would somehow harm honest developers? Like how in the world did you reach that conclusion?
Dude, selling an app on the web or in an app store is no different than selling something in the real world. You find some initial customers, if your product is good those customers will give you reviews, they'll tell other people and so on. Trust is something you earn. I don't see where the problem is for "honest developers", I really don't.
I agree. My point is that a large part of why this is true is that users have learned that installing random software from the App Store is mostly harmless. This is in stark contrast to the situation on Windows (desktop) and Android (mobile).
>> Dude, ...
Thanks.
>> selling an app on the web is no different than selling something in the real world. You find some initial customers, if your product is good those customers will give you reviews, they'll tell other people and so on. Trust is something you earn. I don't see where the problem is for "honest developers", I really don't.
Selling an app on the web is different because the user doesn't know who you are. In real life, they can make assessments about your scaminess based on a whole host of (possible irrelevant) factors: is your shop clean and tidy? Is it in a dodgy part of town or on the main high street? This makes them feel more comfortable trying your thing out.
On the Internet, no one knows you're a dog. Or worse, a contact-list sucking, location-tracking, SMS-scanning scammer.
The problem is you are trained to completely ignore permissions. After installing your first 5 apps which all come with a billion permissions and you have no idea what they mean or why they are used, you really stop caring.
You said "after installing your first 5 apps". Well, I never got past 1, because I never installed an app that asks for unjustified permissions. I also have a non-technical wife that is usually not interested in technical stuff, but if I want to teach her something and I choose the proper words, such that she can understand, then she listens - that's how I taught her to use BCC when emailing multiple people, or to be wary of browser SSL security errors, or to tighten her privacy settings on Facebook, or indeed, to read the permissions required by apps on her Android.
Education is the answer, in combination with smarter controls (e.g. optional permissions), instead of making the world a worse place for those of us that can read just fine.
Indeed curation works for Apple insofar as it's in their interest. It's in their interest because people, overwhelmed with other things to deal with in a mere 16 hours a day, choose (among other reasons) to function in the "walled garden" where such crap behavior is screened out and they don't have to worry about it. The Android ecosystem isn't, for most people, appreciably different from the iOS ecosystem; a major differentiator is curation, which while having some downsides, on the whole leads to a better experience of getting to useful apps rather than having to wade well-educated thru a swamp of gratuitous permissions abuse.
Sure, one could learn the risks of pre-loaded crapware so prevalent on new Windows computers and learn (it's easy!) how to wipe everything & do a clean OS install to get rid of it ... or get a Mac, which doesn't include any crapware. It's a persuasive option for many people. Likewise Android vs iOS app stores: learn the details of dealing with problems, or just go where you don't have to deal with those problems.
There's an activity to manage apps permissions, although it's not exposed and a little bit funky [1]. There's an app on the play store whose sole purpose is to launch the activity [2].
[1] http://googlesystem.blogspot.ca/2013/08/app-ops-androids-hid... [2] https://play.google.com/store/apps/details?id=com.schurich.a...
Or a proper Open Source app store like F-Droid.
The main difference is that Android has this all-or-nothing approach (accept giving the app all these permissions, or don't use the app at all), while iOS asks you for each permission individually, and you can use an app without granting it specific permissions. (eg. the weather app -- disallow access to location, and you can still type in place names manually)
OTOH, maybe they did it this way so you can't prevent ad-driven apps from accessing all the fine data about you.
With the technology we have, saying that one of the biggest software companies in the world just 'had no choice' but to implement something in a particular way is crazy.
This is why I switched back to IOS, I had really hard time finding apps with permissions that are not ridiculous. Whats worse, most of the people I know just didn't care and used these apps, making em popular and high rated.
IOS as awesome in this regard, after all, my phone is the most privately used device. I think am not a paranoid type but I am not O.K. with somebody out there accessing my location and contacts.
I am actually surprised we don't have big scandals with rough apps spreading all kind of private data all over the internet.
[1]: http://forum.xda-developers.com/showthread.php?t=2320783
iOS may be better about notifying users when it comes to accessing location and contact information, but Android has a much more robust system of permissions. Users can see nearly every component of the system the device wants to interact with, determine whether that is satisfactory and choose to install the software or not. Unfortunately most users are more concerned about finding their keys in the dark or hanging a picture straight to care.
- It shows up the alert when the app actually tries to use a resource.
- It lets me use the app without specific permissions. This is something great. I don't grant location permissions to social apps to avoid sharing my location unintentionally. They work just fine.
- The long list of permissions on Google Play store does not really help when the app just wants to be able to pause something when phone rings and that requires absolute access to phone services. That causes a scary list for legitimate apps almost always.
To be fair, Android's way of having them listed makes it possible to assess an app's intention before installing it. That's great and all for me and you, but did not help 50+ million users in this case.
Also, I've been saying it for a long time, but icons colored according to their security risk would be better than just names with descriptions. We have to make security more convenient.
This is too much "developers, developers, developers"
If the person can't be bothered to manually edit the permission list (and I think this changed, because I remember having to add a permission when I did an Android test project), then they shouldn't use the resource!
But yeah, let's add all permissions to any crappy app.
Somewhat OT, but I could've sworn Google does this on new Android installs. I updated my Nexus 4 via CM a few days back to 4.3, and as I went into the account settings to turn off Google sync (contacts, Gmail, calendar etc.) I saw the sync icons spinning for all of them. I don't recollect allowing Google to sync any of my data.
Of course I subsequently turned off sync for all Google services.
For those looking for an alternative, I've been using the Telsa light, and loving it. Highly recommend. The author even outlines the exact permissions that he's using, and why he's using them.
https://play.google.com/store/apps/details?id=com.teslacoils...
android.permission.WRITE_EXTERNAL_STORAGE ==> needed to write images to external storage android.permission.ACCESS_NETWORK_STATE ==> pretty much anything that needs to have a working internet connection android.permission.READ_PHONE_STATE ==> link tracking android.permission.GET_TASKS ==> crash reporting android.permission.READ_LOGS ==> also crash reporting but probably doesn't work in 4.3 android.permission.GET_ACCOUNTS ==> Google Cloud Messaging...seriously android.permission.WAKE_LOCK ==> also GCM
etc.
And when you add ad networks it gets worse. And, they also pay more for gender, location, and age so thats why everyone wants you to sign in with Facebook, etc, because otherwise you can't pay the bills.
I don't know why this is a big deal. Isn't Google already vacuuming up this information from their Android users anyways via "Google Play Services".
On the other hand,
(2) Why aren't these people put in jail?
(2) Every single user was asked for permission to access the information, and they all gave their approval. Give your consent to (1b) because of (1a), and (2) isn't an option.
As long as there's nothing equivalent for Android (after Whispercore was shelved), I'm stuck on IOS.
https://play.google.com/store/apps/details?id=com.jtschohl.a...
http://www.usatoday.com/story/tech/2013/12/06/ftc-flashlight...
For example, it's much easier for a company to spam your entire address book using a native app than using a web interface.
Is the joke intentional?!