4 ms·
"Record the screen" could be more precise. I assumed the article was saying apps were literally recording a video of the screen, complete with alert popups etc
by fitzroy 8y ago
"Record the screen" could be more precise. I assumed the article was saying apps were literally recording a video of the screen, complete with alert popups etc (like the Screen Recorder app).
I realize there isn't functionally much difference within an app. But unless I'm reading it incorrectly, it's not recording the screen it's just the UI of the app. That's not nothing, but I always assumed (sadly?) that a lot of apps have been doing that for years to hone their UX dark arts.
- jrockway 8y agoYeah. An equally hysterical article could be written about web servers recording your IP address and what page you visited. Maybe this is a bit much, but developers do need some data as to how their app is performing in the real world. You might have some metrics that says 0% of visitors to your order checkout page on FooPhone 1.0 are completing orders successfully. With a screenshot, you can immediately see that that screen doesn't even work on that device. It doesn't sound like a tragic loss of privacy to me, but rather an important tool for developers to help smooth over the reality of massive device incompatibility.
- kovrik 8y agoIt is all good until you start sending credit card details and all other personal and sensitive information without even asking user about it. As a user, I don't care at all if it makes dev's life easier. I bought the app and don't want my personal info to be leaked.
- kbenson 8y agoSo, we're supposed to trust the application's main process to accept a credit card securely, but not trust their system which tracks UX? It might be one more place to screw up, but so is just having more actions your app can do. I'm not sure I see any difference between an app recording all I traction within it (for single purpose apps, but not browsers) and a store video recording everything in it.
- kalleboo 8y ago> So, we're supposed to trust the application's main process to accept a credit card securely, but not trust their system which tracks UX? Correct. The payment code is usually gone over with a comb for PCI compliance (or completely outsourced to someone like Stripe), whereas the UX tracking is much less so. It's also a common enough issue that stuff like credit cards or API codes end up leaking into logs.
- kbenson 8y agoPCI compliance covers all aspects of credit card numbers and how they are collected, transmitted and stored. There's no reason to believe a company you can't trust to either not grab it or transmit it or store it for UX metrics non-compliantly will take care to do so in a compliant manner otherwise for normal operations. Either they take care with important data or they don't, and for this measurement "assume it's taken care of because they offload it to some other company" doesn't really count as taking care and absolve them of the responsibility, as I'm sure a lot of developers convince themselves it does. That said, my point isn't necessarily that you should trust apps gathering UX metrics more, but that you should probably trust all apps quite a bit less, whether they track user actions or not.
- germinalphrase 8y agoIt’s a trust issue. Until we have a proper reckoning about privacy in the US, much of the trust in software is predicated on ignorance. There’s minimal outrage because people don’t know that the app is recording their every swipe and typed word (even if deleted before sending a la Facebook).
- vokep 8y agoNope, this kinda thing should be limited to opt-in beta testing.
- notable_user 8y agoThe real take away is that they’re sending all text typed in, including credit card and social security numbers, unencrypted to a third party.
- rnotaro 8y agoSource? This would probably fail some compliances audit. Most of these kind of tools (ie:HotJar) have a flag that will prevent theses data from being sent.
- ryanwhitney 8y ago> In the case of Air Canada’s app, although the fields are masked, the masking didn’t always stick