15 ms·
Uber wants access to browsing history, bookmarks, and running apps
- ape4 10y agoPresumably they want to see if you are running Lyft.
- ludamad 10y agoAnd it wouldn't do anything for if you had two phones, right? This is pretty annoying as someone who still wants to use Uber. Enough that I would consider a competitor.
- gruez 10y agoMost people don't have 2 phones, and put lyft/uber on different ones. I'm presuming they're doing it so they can target lyft users with more promotions.
- deleted 10y ago[deleted]
- JeremyBanks 10y agoIn what scenario would a person be using one phone for Lyft and one for Uber? I use two phones, but I have both apps on both.
- JupiterMoon 10y agoDrivers.
- blackoil 10y agoDrivers have a different app, this is the consumer app.
- JupiterMoon 10y agoThey may well share code and or library dependencies which could be where the 'need' for the permissions comes from.
- cha5m 10y agoAh yes the multitude of people who have lyft on one phone, and uber on another. And then of course they have their twitter phone, and their facebook phone and...
- askyourmother 10y agoVery unnecessary overreach on android permissions.. Will be interesting to see how many of the fans of uber here on hn will try to spin this. Just forwarded to some friends, they are uninstalling the rogue app as I type this!
- deleted 10y ago[deleted]
- jonathankoren 10y agoIsn't permission overreach du rigueur on Android? Seriously, I thought that this was a preferred engineering pattern on Android due to platform weirdness or something.
- matt-attack 10y agoPretty sure you mean "de rigueur".
- jonathankoren 10y agoyup. fixed ;)
- justinclift 10y agoCheck again. Still needs du -> de. ;)
- jonathankoren 10y agogoddamn it. I'm firing my typist. ;)
- fahrradflucht 10y agoYes it is/was. The problem is/was that your app stops getting auto updates if you add permissions later. A lot of users never go into the update section and grant new permissions and so your app stays on the version with the old permission set for ever.
- askyourmother 10y agoEdit: interestingly, this comment had five points before the uber fans modded away. Easier to click down then explain rogue apps I suppose... They were lucky they didn't try the beta version of the new forthcoming uber app - that version wants access to the phones of all your friends, family, neighbours, your postman, the sister of the locksmith that helped you get the spare key last year, and the chap you met on the train to work last week called Brian. Still, go uber!
- MichaelGG 10y agoYour comment was downvoted because it doesn't add to the conversation and is mostly nonsense ("sister of the locksmith?").
- mortenjorck 10y agoIf you are running the app on Marshmallow, with iOS-style permission requests, in what contexts does the app ask you for these?
- nevir 10y agoWhen you update (and the permissions have changed)
- fernandotakai 10y agoi'm on marshmallow, updated the app. it popped the contacts (http://i.imgur.com/wNzktdO.png http://i.imgur.com/wNzktdO.png) one when i tried to create a family profile (so i could add people to my family account). other than that, i could not make these new permissions to trigger.
- lgessler 10y agoProps to whoever's responsible for itemized permissions requests on install/update--stories like these probably wouldn't exist without it.
- rplnt 10y agoDoes this recovery attempt of a bad feature deserve praise? It wouldn't be an issue if permissions were properly implemented from the go - i.e. user had the control over what permissions the app gets.
- sp332 10y agoMy Samsung phone came with the Uber app baked into the ROM. Fortunately I know enough to disable it, but I can't completely uninstall it. And most users will be prompted ad infinitum to update until they give in.
- technofiend 10y agoI've said it before but I'll say it again: this is why you create a second throw-away Google account and use that to create a new profile on your phone dedicated to snoopy apps. Seriously: screw anyone that thinks harvesting my personal data is the cost I must pay for a cab ride.
- electic 10y agoI don't think that will solve this particular problem. It wan't your browsing history from the device. What we desperately need is a UL for privacy. Just like UL tests electronics, we need a lab to test these apps for what data they access and how they make use of that data. Then assign a score so consumers can chose not to use services that request unnecessary permissions and misuse your data.
- swiley 10y agoNo, what we need is the ability to modify the system software on our phones easily to stop this kind of thing. On a normal Unix system you would just run the app as a separate user (or worst case, sandbox it) but on android non of the interfaces (or really much of anything at all) can be controlled by the user.
- Nullabillity 10y agoAndroid has supported multiple users for quite a while now.
- alchemyunited 10y agoYes. But sometimes it's removed or not exposed. For example, my Samsung S5 doesn't support multi user
- technofiend 10y agoThat's ideal but runs counter to how Google sets up permissions today.
- 10y ago
- Animats 10y agoThere's an Android mod which deals with apps like that. They can try to read all the user's info, but what they get is all phony.
- maaaats 10y agoI hate that AI support-replies are a thing. He sent a serious mail, and got a bogus reply back. I've had the same issues myself with other vendors, for instance Steam.
- motti 10y agoWith Marshmallow, you can just turn off or deny certain permissions. So for most people who really want to run the Uber app, the question is really whether it runs OK without all these permissions.
- misiti3780 10y agoIt is not possible for an app to get browsing history on iOS right ? ( i have never seen any app ask for that permission personally)
- asd 10y agoYou are correct. This seems like a very dangerous permission to grant to apps.
- readams 10y agoMy copy of Uber just updated and it doesn't seem to be requesting any of these permissions. I'm on Marshmallow, and on the permissions page these permissions are not there. Version 3.98.2 of Uber. It's possible that these permissions are used in some obscure place in the app. With the new permissions system, you can progressively request permissions when you need them, so it's possible it will request these at some point in the future, but the app seems to run OK without them. I also disabled access to contacts, which the app does request for some reason.
- sghodas 10y agoNot 100% sure, but I think the access to contacts is so that you can split ride fares with other people.
- JoshTriplett 10y ago> Not 100% sure, but I think the access to contacts is so that you can split ride fares with other people. There's a standard intent to select a contact for purposes like that, and then the app only gets access to the information of that contact. Apps requesting access to contacts get all contacts.
- rajivm 10y agoIt's actually probably so you can autocomplete a contact as a destination address for your Uber. The same is true in Maps for navigation. Unfortunately UX wins over privacy so launching an intent to pick a contact probably wasn't as elegant as using a unified autocomplete field.
- 0xmohit 10y agoAha! So maybe they need a variety of permissions in order to apply machine learning so as to enhance the UX.
- jakub_g 10y agoWhen you scroll to the bottom on Uber's play store page it displays this for me: http://m.imgur.com/ndfjQWv http://m.imgur.com/ndfjQWv They request 'running apps' only from this particular subgroup. Notice the wording on the original screenshot: 'one or more of'. TLDR they don't request browsing history, the Android permissions screen on update is confusing
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- asd 10y agoSadly, 98% of folks will blindly accept this.
- jsjohnst 10y agoI'd venture to guess the number is likely closer to 99.9999%
- 0xmohit 10y agoRight. I remember hearing from somebody about Google Now recently. The guy was happy that it reminds him of bills etc., added that it even gets the amount and due date from the "emails" and "reminds". Frankly, a vast majority (99.99%+) don't care.
- URSpider94 10y agoBy "don't care," you mean, "are extremely delighted when Google reminds them to pay a bill on time and avoid a late fee."
- SG- 10y agoI don't even understand why Android would even let then happen. I can't even think of desktop apps that try to gain access to your history or bookmarks let alone a mobile app. One time bookmark import is a thing I suppose, but that's different than gaining permanent access once granted.
- blfr 10y agoDesktop apps usually have access to everything on your drive or running under the same user.
- SG- 10y agoYes, obviously it's possible for them to gain access, I'm saying I don't know of any desktop apps that need access to any of that other than one time bookmark importing.
- jsprogrammer 10y agoFor example, you may wish to use an editor or viewer on any file on your machine.
- ThisIs_MyName 10y agoRelevant username? :P
- jsprogrammer 10y agoYour name? How?
- Nullabillity 10y agoHistory sync, search personalization.
- deleted 10y ago[deleted]
- derFunk 10y agoCome on guys, where are the academics? Instead of overreacting please just reverse engineer, get the facts and check WHY the Uber app actually requests these permissions. I mean, it's still Java, so you got the source. I don't think they're using native code or do more obfuscation than the average app (disclaimer, haven't checked (yet)). Who's first?
- Daishiman 10y agoThe burden of proof on the necessity of those permissions lies in the creators, not the consumers.
- derFunk 10y agoI agree. Yet this is Hackernews, and if the creators don't do it we can.
- qihqi 10y agoif all they do is send the data home, you won't know what they use it for。。
- derFunk 10y agoIf you'd find out the Uber app is sending home your browser history, this is big news already! I'm in CEST, if I wouldn't be sleeping right now I'd start up Burp, Charles or Fiddler to check.
- brad0 10y agoAnyone who knows android dev knows this is a non issue. The permission they request doesn't even do anything in lollipop and later. Sounds more like a bad dev than anything malicious. What's the saying? Never attribute to malice with what can be explained by stupidity?
- DINKDINK 10y ago>Never attribute to malice with what can be explained by stupidity Hanlon's razor
- arca_vorago 10y agoIs a logical fallacy that is overused and hardly ever true, and should be relegated to the dustbin of intellectual discourse where it belongs.
- jonathankoren 10y agoIt's not a logical argument. It's more of a heuristic of human behavior, which tends to be right. Only rarely is there someone sitting behind a large desk making tent hands while laughing maniacally. EDIT: On second thought, if it is a logical argument, it's a specific case of Occam's Razor. Which is more likely? Someone made a mistake, or there is a grand conspiracy?
- nitrogen 10y agoHere's another fallacy: the fallacy of the excluded middle or the false dichotomy. There are many alternatives on the spectrum between "mistake" and "grand conspiracy".
- mortenjorck 10y agoExactly. These include such situations as: - a mistake where misaligned incentives are against fixing it - a questionable decision exacerbated by a mistake - malice on the part of an external actor plus internal incompetence (essentially all data breaches)
- StavrosK 10y agoFrom a reddit comment: > The permissions you see on the install screen are actually triggered by various permissions in the permission group. I've checked Ubers (there's a button on the web play store and you can see it in the manifest), and the only one from the Device and App History group they actually use is "GET_TASKS", or get a list of recently opened apps. > Furthermore, on Lollipop this permission doesn't even do anything anymore. The relevant function in the framework has been changed and only returns instances of the caller's own app now. So Uber can see when you last used Uber. Big deal. > Basically, this is a big fuss for nothing. Uber is not accessing your browser history, and if you're on Lollipop or above they can't access your app history either. They may do that on lower versions, but it's most likely to counter buggy behaviour on those older verions and not to spy on you.
- matt_wulfeck 10y agoEither that's not entirely truthful, or the app permission system is totally broken... Need to find out when you last opened the app? "Get running apps"...?
- jagger27 10y agoI don't even understand why they need local access to figure this out. Poll the web API for last_login and be done with it. Surely they're already tracking and storing this kind of data on their end.
- nxzero 10y agoIf you have any questions, you can write Uber at privacy@uber.com. -iOS App Permissions https://www.uber.com/legal/other/ios-permissions/ https://www.uber.com/legal/other/ios-permissions/ -Android App Permissions https://www.uber.com/legal/other/android-permissions/ https://www.uber.com/legal/other/android-permissions/
- tshtf 10y agoDid you read the post? He contacted privacy@uber.com. Question: http://i.imgur.com/K1mAtiH.png http://i.imgur.com/K1mAtiH.png Scripted reply that didn't answer question: http://i.imgur.com/m9sWJZR.png http://i.imgur.com/m9sWJZR.png Also, as mentioned in the post, https://www.uber.com/legal/other/android-permissions/ https://www.uber.com/legal/other/android-permissions/ doesn't mention the new permissions.
- nxzero 10y agoIf I made that clear, it would be less likely others would contact Uber; appears that I should have just let it be.
- deleted 10y ago[deleted]
- awinter-py 10y agokeep the big picture in mind here. If Ü can't tell what it looks like you're trying to do, they can't perfect clippy.
- liquidise 10y agoMultiple comments here parroting the "this is a non-issue on Lollipop or later" defense. Per Android's own statistics [1], that leaves 60% of users vulnerable to excessive permissions. 1: http://developer.android.com/about/dashboards/index.html http://developer.android.com/about/dashboards/index.html
- 0xmohit 10y agoRegardless of whether it's a non-issue on Lollipop (or later) or not, it exhibits the intent of Uber. And google is no less: https://www.privateinternetaccess.com/blog/2015/06/google-chrome-listening-in-to-your-room-shows-the-importance-of-privacy-defense-in-depth/ https://www.privateinternetaccess.com/blog/2015/06/google-ch...
- morgante 10y agoNo, it really doesn't. It's a fundamental flaw in the earlier Android permissions model that it requests so much. Uber doesn't try to pull anything like this on iOS.
- codedokode 10y agoiOS applications are moderated and Apple might not want Uber to collect too much information on their users.
- ryanwaggoner 10y agoTo be fair, there is zero ability (outside of undocumented and forbidden private APIs) for an iOS app to even request access to browsing history, bookmarks, or app history.
- habosa 10y agoActually that's backwards. Android moved to the new permission system (fewer perm groups, runtime user permission) to be more like iOS. It used to be that all permissions were granted at install time, which made apps much more likely to ask for onerous permissions because the user is unlikely to read the list or turn back. It's likely they don't try this on iOS because iOS simply doesn't have the APIs to do this under any permission. It's a philosophical platform difference about what the user should be able to allow apps to do.
- jarnix 10y agoThis permission should just simply not exist. I had two games and an another app. The browsing history was, in this case, used for targetting ads. I did not need the apps and uninstalled the apps (it was around 2 years ago, on previous version of Android I think). The apps on Android should be sandboxed and not be given this kind of permissions, that's all.
- riprowan 10y agoExactly. If an app requests a permission it should not need, then it should simply be considered malware and rejected with a big 1-star review.
- on_and_off 10y agoWell, browsing history sounds very helpful in order to create another browser and that's pretty much it. The unfortunate thing is that it is bundled in the same group as 'running apps'. I guess it is because Android's PMs wanted to limit the number of permissions groups but it means that many apps have to request it simply because they need GET_TASKS for old devices.
- _nedR 10y agoFirefox doesn't expose its browser history to other apps whereas both Chrome and the vanilla 'Internet' browser on Android does. This is one reason why i use Firefox on Android (another being the read-it-later feature, and option to add other search engines easily).
- codedokode 10y agoSo this is information about Uber app that I found in some blog: ------- Android Uber app code has many suspicious places. For example, it contains a namespace "com.baidu.frontia" and classes there include such code as: localObject = ((TelephonyManager)localObject).getSubscriberId(); // gets IMSI ((TelephonyManager)localObject2).getDeviceId(); // gets IMEI localObject1 = ((WifiInfo)localObject1).getMacAddress(); public static void makeCall(String paramString) public static void sendSMS Also there is the code that collects information about cell towers, mcc and mnc codes, scans wifi networks. I looked quickly through the code and it seems that those methods are never called. They are probably just a part of a library not used in this app. Uber mostly uses baidu maps, authorization and payment API.
- onewaystreet 10y agoThat code is from the Baidu SDK which Uber integrates into its app for Chinese users.
- wosos 10y agoStill suspicious nontheless
- levemi 10y agoI think you're on to something, for example the Uber app probably also uses the `true` constant in places, which could be used by `if` comparisons, and Uber could actually be using `if` comparisons all over the place. Who knows what sort of suspicious `if` comparisons Uber's app might be making? We don't know, and until we do we should probably not use this app.
- teamfrizz 10y agoNot sure if this is sarcasm or just strange.
- 10y ago
- manu29d 10y agoHmmm. Nobody talking about other apps that do this? Talking about Tinder[1] for example. They require "Device ID and cell information" too. [1]: https://twitter.com/manu29d/status/710883865955422208 https://twitter.com/manu29d/status/710883865955422208
- dredmorbius 10y ago"Et tu" comments without even bothering to search for earlier submissions aren't particularly enlightening. https://news.ycombinator.com/item?id=11465215 https://news.ycombinator.com/item?id=11465215 From myself in the past week. I've lobbied several app devs to remove/reduce permissions. I've uninstalled others. Android's privacy model sucks. It needs retroactive fixes. Highlighting the problems is how that gets fixed.
- Bud 10y agoInteresting that the headline leaves out the fact that this only applies to poor, security-less Android. Less sensational that way, I guess. (And less accurate.)
- acheron 10y agoThis has little to do with Uber and is all to do with Android. Care about privacy. Use Google products. Pick one.
- colordrops 10y agoThere is definitely an Uber presence on HN doing damage control.
- dang 10y agoWe detached this subthread from https://news.ycombinator.com/item?id=11512701 https://news.ycombinator.com/item?id=11512701 and marked it off-topic.
- SquareWheel 10y agoPeople sure love to throw out the shill card without providing any proof.
- chris_wot 10y agoPerhaps, but the comments are a bit silly given what the parent poster says: 60% of Android users are affected by this. Why do Uber need that permission in the first place? What exactly are they doing with the permissions that are granted?
- mirimir 10y agoThey want to black-box your mind, of course ;)
- Johnny555 10y agoIt would make a pretty poor shill if it were easy to prove it.
- vehementi 10y agoThe fact is there are shills everywhere. It's hard to prove them in all cases. But it is a "big" and important industry for companies to anonymously and without accountability do damage control. There have been articles and AMA's etc. from people who had worked for these firms and it's really disgusting. So it's not people with tin foil hats speculating that shills might exist - we know shills exist and are pervasive. Given that, we should have a certain non zero belief that any given poster is a shill. Not sure what is the best way to proceed when you know for sure that there are spies around you all the time. That's a bigger discussion. But jumping on people as if we should have to prove beyond a reasonable doubt that there's a shill is really counter productive and helping "them" win.
- fblp 10y agoAfter a long break from Uber I opened it up to price compare against Lyft. I switched between the two apps and then uber offered me two free rides. It seemed like it was detecting that I was hesitating to "come back" to Uber. I use Android Lollipop and even if the permission didn't allow them to see I was using Lyft, I wouldn't be suprised if they're trying to re-engage "hesitating" users and are snooping for whatever data they can.
- firebones 10y agoCould simply be based on a campaign that kicks in after a long period of non-usage. Then again, you have the outline of a repeatable experiment here for someone with two phones and a period of Uber exile.
- jasonjs 10y agoInterestingly, I had the exact same experience; opened Uber, got a ride estimate. Opened Lyft, got a ride estimate. Opened Uber again, and was presented with a promotion.
- dredmorbius 10y agoGoogle released, then withdrew, an interface for revoking and limiting application permissions. On existing Android devices. Three years ago. We know they can do this. We also know they don't care. The challenge is to make them care. https://www.eff.org/deeplinks/2013/12/google-removes-vital-privacy-features-android-shortly-after-adding-them https://www.eff.org/deeplinks/2013/12/google-removes-vital-p...
- magicalist 10y agoYeah, it would be awesome if they would release an android update that allowed you to revoke and limit application permissions. http://android-developers.blogspot.com/2015/08/building-better-apps-with-runtime.html http://android-developers.blogspot.com/2015/08/building-bett...
- dredmorbius 10y agoAs I understand it, that puts the onus fully on application developers, whom users have to trust. That's precisely the current problem.
- strcat 10y agoNo, it does not. Dangerous permission can be toggled off for all apps now. For apps on the new API level, they can no longer obtain dangerous permissions at install time. They have to trigger an OS-level prompt for the permission. They're supposed to explain why they need it before triggering the OS prompt and many apps did it poorly by adding an extra, meaningless prompt before the real one. This was't done for the old API level because it would cause crashes for permissions where data can't feasibly be faked and the user would have no indication that fake/empty data was being used if it was the default.
- dredmorbius 10y agoFor Marshmallow. Which 60% of current Android users don't have and will never have until they retire their current devices. Which is why Google needs to fucking fix this retrospectively.
- spoiledtechie 10y agoDidn't Uber just admit to giving Feds their data on all their users? What's the thought on Uber having access to such data as browsing and passing that along to the feds too?
- nbb 10y agoNo they didn't.
- spoiledtechie 10y agoYes they did. Don't tell me know until you can learn how to Google.
- nbb 10y agoDon't tell you what?
- thirdreplicator 10y ago+1 Uninstalled
- thirdreplicator 10y ago+1 Uninstalled
- known 10y agoAre they doing it at the behest of NSA?
- rcheu 10y agoI believe the browser history lookup doesn't work anymore (I tried recently on 5.0 I believe). Also, many of the Android permissions are unecessarily broad, I think that really would be a good thing to fix. Oftentimes you only need some specific function, but have to request a much broader range.
- paulddraper 10y agoExamples? (Especially any for browsing history, bookmarks, or running apps.)
- rcheu 10y agoGetting a list of accounts (needed if you want to integrate with Google login), asks the user if the app can read their contacts: https://code.google.com/p/android/issues/detail?id=189766#c8 https://code.google.com/p/android/issues/detail?id=189766#c8. Another example is phone state https://arnowelzel.de/wp/en/android-and-read_phone_state https://arnowelzel.de/wp/en/android-and-read_phone_state (games use this to adjust volume to not drown out calls). There is a replacement, but it's not well known.
- jjuhyun007 10y agoUber could provide much more than a point to point ride service in its current traditional sense if users are willing to give up more data. For example, it could provide user a tour/travel experience to match with the proper driver if it knows you are traveling. Or send you off to a nice dining experience if it knows you are a foody, etc.
- siculars 10y agoCrazy town app permissions are what keep me from using Android. I really wouldn't be able to install half the apps out there that ask for all sorts of permissions that are frankly obnoxious.
- lsc 10y agothis is why I don't use an android device as my primary phone, even though my perception is that you get rather more bang for your buck, hardware wise, on android phones, and even though the samsung gear VR looks like someone implemented one of my less-realistic fantasies. On IOS, yes, uber asks for access to my contacts list, I click 'no' and uber works just fine (modulo the 'spam my friends' feature, which I didn't want anyhow.) On an android, my understanding is that I've gotta chose between giving uber permission to spam my contacts list and simply not using uber, which is sad, because uber is way more convenient than a yellow cab. This contributes to the perception that because IOS is paid for up-front, apple is willing to do things that might make apps less profitable, if it makes those apps better for the users, but that Android, because it is paid for by advertising, is less willing to side with the user against the app providers/advertisers.
- 5ersi 10y agoThis is how it works in Android 6 - permissions are requested as needed and user can deny them individually. Unfortunately apps have to be build against the new API, so it does not happen automatically for old apps.
- izacus 10y agoYou can deny permissions individually for older apps as well.
- anowlcalledjosh 10y agoThey aren't capable of handling the case where they aren't given access to a permission though, so that makes them potentially more prone to crashing.
- unlinker 10y agoMy idea is that if they try to access your contacts, instead of receiving a potentially unhandled "access denied" exception, they should just receive an empty contact list. Et cetera.
- ryan-allen 10y agoI'm really starting to worry about this as an Android user. If I want to keep control of my privacy there are so many apps that I can't trust to install. Even little dinky games are asking for access to contacts and messages and all sorts of other things. An application on a desktop computer that steals data from your email application and sends it back to base is called "Malware". On Android, this is called "business as usual" from what I can tell. I don't know the app developers' reputation, I don't know anything... Except that someone in some other country has unbridled access to my phone. As a result there are many applications I want to use and I just don't install. It's not very cool.
- Freak_NL 10y agoNot sure why you are getting downvoted for voicing a valid concern.
- ryan-allen 10y agoProbably due to the lack of scientific rigor that I failed to produce in all of 3 seconds, or, just general BS of an online community. Or shills, who knows! Nobody said this was a community of rational beings.
- h8er4fun 10y agoI wish Android had permission control like WP10 do...
- rvalue 10y agoI have observed on my device when i use Transit Stop to check for bus schedule, Uber app pops up.
- esafwan 10y agoI have often wondered why Android don't categorise or have some mechanism to allow users revoke permission later. I have been a long time Android user but recently started using iPhone. I don't like iPhone for many reasons but then the control you have on turning on and turning off location, data connectivity, access to photos etc from one screen is really something you should have on all device. I felt the need of this, when Facebook asked for permission to read my messages.
- jogzden 10y agoThis feature has been available on Android M for a while now. Sadly, the fragmentation of versions running on the Android platform is the biggest threat to its security.
- m52go 10y agoJust switch to the mobile web. Same capability, same interface, no intrusive permissions requirements. Add it to your homescreen and you even get the glorious U logo back! https://m.uber.com/ https://m.uber.com/
- joulesbeef 10y agoHow about make apps show us the data they collect and if they dont they dont get access to the store. Google has an pretty awesome page that lists all that crap they collect on you and you can delete it from there. On the google store site.. when browsing apps, there should be a tab on every app page, where i can see a sample of what it collects and a declaration of what it does with that data. after installing the app, in the app manager, i should get a tab where i can see what its grabbing from me. right now we got strangers going into our bedrooms borrowing something they wont tell us what it is. and really permissions dont help a lot when it comes to this. Yeah my bookmark dup cleaner has to access my bookmarks to clean.. so i give it the permission, but does it keep them? does it sell them? i dont know permissions arent that detailed. if there was a privacy tab that i could check...then i would know. People hide nanny cams to watch the nanny. Its because they gave her permission to have access to the house and kid and such.. the cam is like my privacy tab. it makes sure she doesnt abuse the permissions. We KNOW she needs access to the house and kid to do her job.. we just dont want the kid molested. well I dont want my data molested.. So google please give me an app nanny cam.
- makeramen 10y agoUber engineer here. These permissions were mistakenly introduced by an engineer on the team who thought a 3rd party library needed them when in fact it does not. We definitely do not need or want those permissions and we’ve promptly released new versions to the Play Store that do not request them. Please upgrade to Uber app version 3.98.3 (3.99.2 in the beta channel) which no longer requests the extra permissions.
- decisiveness 10y ago> These permissions were mistakenly introduced by an engineer on the team who thought a 3rd party library needed them when in fact it does not. What caused the engineer to be mistaken about this? What library? Considering Uber's history, expecting people to believe a claim like: "one guy acted alone in an oopsy", without providing a more detailed report, is a bit optimistic.
- jfrisby 10y agoIf they did indeed immediately release an update that ceases asking for these permissions, then I'd say this is an entirely reasonable explanation regardless of their history.
- decisiveness 10y agoI could be wrong, but without a real explanation, it seems more likely Uber is still convinced analyzing customer behavior in the most personally invasive ways is worth the risk, and were testing the waters, hoping a response like the OP's wouldn't gain traction the way it did. In a company with thousands of employees, already scrutinized for privacy violations, it's hard to believe that a single engineer could ask for the most sensitive of permissions without anyone else reviewing or bumping up the chain first.
- makeramen 10y agoYou're right that we have a very strict review process for added permissions, but unfortunately due to the way libraries and Android's manifest merger work, this change managed to slip through our standard review process. We're definitely going to add stricter enforcement to make sure something like this doesn't happen again.