11 ms·
The actual statement from La Liga is in spanish, I translated it with DeepL [1] here: >Privacy policy of the LaLiga app. >Regarding the new privacy policy of
by lightbyte 8y ago
The actual statement from La Liga is in spanish, I translated it with DeepL [1] here:
>Privacy policy of the LaLiga app.
>Regarding the new privacy policy of the LaLiga app, we would like to make some clarifications.
>Origin
>LaLiga has the responsibility to protect clubs and their fans from fraud in the broadcasting of football matches by public institutions (HORECA). These fraudulent activities represent an estimated annual loss of 150 million euros for Spanish football, which translates into direct damage to clubs, operators and fans, among others.
>For this reason, LaLiga has implemented a new functionality in its official app with the sole purpose of detecting these fraudulent exploitations, transparently informing about them and asking users for their express and specific consent, with or without their being able to lend it freely.
>This new functionality for fraud detection is enabled in the app since last Friday, June 8, 2018, only for Android system users and nationally*.
>Functioning
>When a user downloads or updates the APP, the operating system of your mobile device will prompt them through a pop-up window to provide their consent for LaLiga to activate the microphone and geopositioning of their mobile device. Only if you decide to accept it, the microphone will pick up the binary code from audio clips, for the sole purpose of knowing if you are watching football matches played by LaLiga teams, but the content of the recording will never be accessible.
>We protect user privacy
>LaLiga has implemented appropriate technical measures to protect your privacy if you authorize us to use this feature. These measures are detailed below:
>LaLiga will only activate the microphone and geopositioning of the mobile device during the time slots of matches in which LaLiga teams compete.
>LaLiga does not access the audio fragments picked up by the device's microphone, as they are automatically converted into binary code on the device itself. LaLiga only accesses this binary code, which is irreversible and does not allow you to obtain the audio recording again.
>If this code matches a previous control code, LaLiga may know that you are watching a particular match. If it does not match, the code is removed.
>The codes will not refer to your name, but to your IP address and the specific ID assigned by the PPP when you register.
>We will periodically remind you that LaLiga may activate your microphone and geo-positioning and ask you to confirm your consent.
>You can revoke your consent at any time in the mobile device settings.
[1] https://www.deepl.com/translator https://www.deepl.com/translator
- deleted 8y ago[deleted]
- severine 8y agoThis would be the corresponding translation of the analysis linked upthread, from https://reversecodes.wordpress.com/2018/06/12/analizando-la-app-de-la-liga-para-android/ https://reversecodes.wordpress.com/2018/06/12/analizando-la-...: Leaving aside the first part where they try to justify themselves by talking about economic losses and other stories, in the third paragraph they already begin to say things that do not agree with reality. This new functionality for fraud detection is enabled in the app since last Friday, June 8, 2018, only for Android system users and nationally*. They say that the functionality of collecting microphone and location information was enabled on June 8, 2010, so version 6.4.0 released on February 21, 2018 with SHA1 efd50120f73c0d674492126ce9e9198da57c8287 has the ability to collect microphone and location information in exactly the same way as the latest version available. It may have been implemented in an earlier version, it's a matter of looking at it, but with this example it's enough to dismantle that part of the release. Unless the'functionality' they refer to is that of asking permission and not that of'spying on users'. (....) the microphone will pick up the binary code of audio fragments, with the sole purpose of knowing if you are watching football matches of competitions played by LaLiga teams, but the content of the recording will never be accessed. There's little to say here, it's obviously outrageous to say that the microphone doesn't record audio clips. It is also contradictory to say that the recording is analyzed (in any way, it will be seen later) and in the following line that the content will never be accessed. What we mean by that is that they record and then immediately delete, because the moment they do anything else about the generated file other than delete it they are already accessing the content. Now they tell us how they protect the privacy of the user.... LaLiga will only activate the microphone and geopositioning of the mobile device during the time slots of matches in which LaLiga teams compete. This time slot thing is very relative, if a Spanish team plays in China when it's 5 a.m. here, they can activate the 10 million terminals and record them. LaLiga does not access the audio fragments picked up by the device's microphone, as they are automatically converted into binary code on the device itself. LaLiga only accesses this binary code, which is irreversible and does not allow you to obtain the audio recording again. Tjis is wjere the statement loses all credibility it could have. On the one hand, they tell us that La Liga does not access the audios, that they transform them into binary code automatically in the device (obviously, in computing everything is binary data, which does not mean that they are not recording an audio that can be played later) but if we give them the benefit of the doubt, what they are trying to tell us is that they are generating a progressive hash with their application after recording the audio and in the terminal itself? or in other words, do they mean that their application does what Shazam (valued at EUR 400 million) does? But in this case it is much more complex, because Shazam can build a database of songs that are a finite and concrete ensemble; but to recognize that the ambient sound corresponds to a football match in a bar are already big words. It is quite clear at this point that what they do is that, but obviously they do not do it locally, but they send the recording to another service to identify it and maybe I have searched wrong, but at no point in the general conditions of use and privacy policies of the application I have seen that it is mentioned that the data collected are sent to another company for analysis, really do not know how these issues go at the legal level, but in the legal notice on privacy and cookies makes a mention to Your personal data will not be transferred to other persons or companies to be used for their own purposes. However, some entities subcontracted by LaLiga may access Personal Data and information as Processors or Sub-processors to provide LaLiga with a necessary service. In particular, LaLiga receives assistance from: (a) Service Providers. Sometimes, we share your information with our third party service providers, who help us provide our services. Examples of service providers: hosting, metrics and analytics. That's generic again and in my view leaves the door open for unlimited data traffic, so any company can become a service provider overnight, right? From this point on, the following points already seem to me to be pure rejoicing of those who have written it and those who have approved it as a serious statement. (...) Translated with www.DeepL.com/Translator -- There's more, and then a technical analysis, thanks JorgeGT!