8 ms·
>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, includin
by lamlam 9y ago
>When researchers installed Ai.Type they were shocked to discover that users must allow “Full Access” to all of their data stored on the testng iPhone, including all keyboard data past and present. It raises the question of why would a keyboard and emoji application need to gather the entire data of the user’s phone or tablet?
I have a suspicion that due to how cheap bulk storage is these days, that companies collect as much information as they can get away with in hopes that _maybe_ it will be useful one day. That mixed with poor security practices is just going to keep leading to these sorts of events happening.
- danso 9y agoI thought most keyboards at least ask for Full Access, though may not necessarily mandate it: https://techcrunch.com/2014/10/04/everything-you-need-to-know-about-ios-8-keyboard-permissions-but-were-afraid-to-ask/ https://techcrunch.com/2014/10/04/everything-you-need-to-kno... I was never sure what "Full Access" meant, other than keyboard data (including keystroke recording if the dev wanted it) going forward. But surely it doesn't mean everything, as in access to keyboard-non-related data (user photos, etc).?
- oakesm9 9y agoThe documentation for that is here: https://developer.apple.com/library/content/documentation/General/Conceptual/ExtensibilityPG/CustomKeyboard.html#//apple_ref/doc/uid/TP40014214-CH16-SW3 https://developer.apple.com/library/content/documentation/Ge... The gist of it is that requesting "full access" allows them to access the internet and some other bits automatically, but they need to ask for further permissions for photos, location, contacts, etc.
- wlesieutre 9y agoYep, it's not everything, but "full access" gets a scary name because when you give your keyboard a network connection it can easily log and send off all of your passwords. Very few things on iOS have that level of access.
- 0x62 9y agoiOS doesn't allow custom keyboard to be used for password inputs. Any input element which masks the users input will only open with the iOS stock keyboard.
- wlesieutre 9y agoOh, that's a good policy. Wasn't aware since I use the stock keyboard everywhere. I tried some alternate ones for swype style typing, but frankly they were all worse than the stock Google keyboard from my days on Android so I gave up on it and learned to type with my thumbs again.
- berberous 9y agoIf you haven't tried it, Google's GBoard is now on iOS and is quite good.
- wlesieutre 9y agoThanks for the recommendation! It does seem good. Bummer that it has a giant search bar at the top of the keyboard, which is an enormous waste of space on an iPhone SE. If you don't give it full access, the same space is used to constantly beg for full access to turn on the search bar, and accidentally touching that will pull you out of your app over to the Gboard app, which gives you a button to open the Settings app. I can see why they do it. No way to serve ads to the keyboard, so searches are the only way to make money off of it. Shame they had to crap it up though, I'd have happily paid money for this keyboard, but I think I'll have to pass. In keeping with this thread, I'm not that into the idea of giving Google access to my keystrokes even if they pinky-swear to not use them. We're talking about the same company currently being sued for deliberately working around iOS's privacy protections: https://9to5mac.com/2017/11/30/google-safari-work-around-class-action-suit/ https://9to5mac.com/2017/11/30/google-safari-work-around-cla...
- vbernat 9y ago
- mtgx 9y agoThis is why I'm a believer in this type of regulation - you have two options: 1) Collect only the data strictly necessary for the functioning of the service. If you suffer a data breach, you used security best practices, and notified the corresponding authorities and your users in due time, then you shouldn't be punished at all, with very few exceptions. If you didn't use best security practices, you may see some small to moderate fines, depending on each case. 2) Collect whatever you want (while still mentioning it in your Privacy Policy, and the whole thing). But if you suffer a data breach, and that data is exposed, you should need a big fat banking account to survive the fine that will be imposed on you. The fines should be big enough that they should deter even the big players from collecting too much of the data they don't need.
- fredley 9y agoAbsolutely. Good regulation is that which effectively disincentivises anti-consumer behavior. Businesses are playing risk/reward games all the time, and regulation should just pile on some huge extra risk in places where it's needed to protect consumers, and the health of the market as a whole.
- codedokode 9y agoThis risk/reward mechanism works only for large, established companies. There is no real responsibility for a startup. If they make a mistake and are caught, they can shut down the company and start a new one with the same staff.
- coldcode 9y agoThat only works if you and the developer are in the same legal environment.
- codedokode 9y agoI think it should be other way: in many countries surveillance is prohibited. The developers who collect those data should be treated the same way. And their software should be treated as a spyware. UPD: For example, we often hear news about hackers from some Eastern European country that were obtaining personal information in large quantities. Their actions are very similar to what the developers of this keyboard did.
- gcb0 9y ago"all keyboard data". for a keyboard app? seems right on point. why wouldn't it want it?
- wlesieutre 9y agoWith the basic permissions the keyboard can only type, it has no capability to send the keystrokes out to the internet or store them where they could be sent. If you don't trust the keyboard developer to not be an idiot with your keystrokes, better to not give that access.
- gcb0 9y agowhy would you ever install a keyboard from someone you don't trust?
- JustSomeNobody 9y agoSecurity is one reason. You need to be able to put absolute trust in the developer of the keyboard.
- JustSomeNobody 9y agoWhat past data is being stored? Is this simply frequently typed emoji/words?
- yellow_postit 9y agoPast data is useful for building a personalized typing and autocorrect model from the get go. That's the key conviency vs. security/privacy concerns tradeoff for many if these keyboards.
- prawn 9y agoCould it be made illegal to store personal information of users? Or even just restricted to particular industries? How many services do you use that even need it?
- deleted 9y ago[deleted]
- yeahsure 9y agoSure could. If I'm not mistaken, Europe does that to some extend.
- bryanrasmussen 9y agoI have a hard time believing this company is GDPR ready.