9 ms·
What happened: Twitter asks users on sign up to scan their contacts (read: steal and upload them). If you say no, twitter asks again and again every day / every
by deft 7y ago
What happened:
Twitter asks users on sign up to scan their contacts (read: steal and upload them).
If you say no, twitter asks again and again every day / every login until you finally allow it to.
Twitter builds a huge and unnecessary db of users and phone numbers, as well as non-users IDs tied to phone numbers.
Someone uses an API to steal this info that in most cases twitter only collected by tricking their users / forcing it.
Anyone affected by this should be suing twitter for even collecting this information! My friend can give away my phone number because of this data collection.
- deleted 7y ago[deleted]
- fireattack 7y ago> If you say no, twitter asks again and again every day / every login until you finally allow it to. Any proof about this claim? I use Twitter on Android and web frequently and I only refuse such request once or twice. Bottom line, it doesn't "ask again and again every day".
- throwiay987 7y agoConsider yourself lucky, any account i create without a phone is immediately flagged\blocked and if i do use mine(personal), i get asked to add permissions like the parent said every single time.
- fireattack 7y agoAccount associated with a phone number is totally different from "scan your contacts".
- nacs 7y agoIf you use the web client, they have a header that asks for your phone number repeatedly until you give it.
- fireattack 7y agoOP was talking about "Twitter asks to scan your contacts", not to add a phone number.
- zippergz 7y agoI've been using Twitter daily pretty much continuously since 2008 and I don't remember ever being prompted to upload contacts. I can believe it has happened at some point, but it certainly doesn't repeatedly ask me. I use the web interface and the first-party iOS app (though over the years I have also used various third-party apps on both iOS and macOS).
- Zenst 7y ago>Anyone affected by this should be suing twitter for even collecting this information! My friend can give away my phone number because of this data collection. Given the ramifications on leaking Name with phone number of people who didn't agree directly anything with Twitter and just had there contact details trawled by any of their friends signing up. Not good as with that, hijacking phone numbers has been done many ways and times, even the CEO of Twitter had that stunt pulled upon him. What with 2FA for many being a text message sent to your phone number. The ramifications of this could be bigger than they first appear and remember. They only found this, how long has this been open to such abuse. So anybody who had their phone number hijacked in X period of time, this `might` be a possible explanation in some of those instances. Legally - no idea how this will pan out, but certainly not be the last we read about this.
- RKearney 7y agoA trick I found to stop this nonsense is, at least on iOS, answer yes to the Application's custom dialog to ask permission. This will then invoke the iOS security dialog where you can click "No" and never be asked again. Generally what I see happening is apps will ask the user if it's okay, and only when the user says yes will they execute the necessary system call to request access. In iOS at least, if a user clicks No the app can never prompt for that permission ever again. Until the app makes this formal request to the operating system, it does not show up under privacy (as the app had never asked for it in the first place).
- lonelappde 7y agoWhat does Apple allow that for App Store apls? That's obvious circumvention of iOS's privacy control regime.
- toast0 7y agoMy post below is wrong, please move along. Keeping as-is, so the replies make sense. Thanks repliers! The native prompts don't allow for app specific explanatory text to be presented. I haven't reviewed iOS guidelines, but Google provides guidance to inform users of why you're asking for permissions before you do it, and I would guess Apple would suggest the same as well. Pestering people for access once a day is probably not within the scope of the guidelines though.
- cactus2093 7y agoIncorrect, iOS does allow explanatory text on the system prompt, in fact it’s required. There is no good reason for Apple to allow apps to mask permission requests with their own dialogs, it’s just a case of not bothering to fix this loophole.
- diebeforei485 7y ago> The native prompts don't allow for app specific explanatory text to be presented Not true. iOS apps can specify explanatory text to be included in the native prompt. In fact they are required to do this, since at least two years ago. The NSContactsUsageDescription string (in the Info.plist file) is the place to specify this. https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CocoaKeys.html#//apple_ref/doc/uid/TP40009251-SW14 https://developer.apple.com/library/archive/documentation/Ge...
- amluto 7y agoApple could nip this in the bud: don’t allow apps to read a full contact list at all. Use a contact picker when needed.
- twodave 7y agoThis certainly would break plenty of valid use cases for a feature like this. More likely they ought to have policy in their developer docs to scope reasonable uses of the full contact list and start rejecting updates for applications that violate the new rule.
- rhacker 7y agoWhat's a valid use case for being able to read all contacts vs asking the user for a specific contact selection and choosing to approve sharing it?
- bcrosby95 7y agoAny application whose primary concern is something with contact lists. Maybe it offers a special view into it. Maybe special searches. Maybe a better management interface.
- np_tedious 7y agoAn alternate phone or texting app
- loh 7y agoI can't imagine it would be difficult to implement a "Select All Contacts" functionality, in addition to selecting individual contacts and/or selecting all then deselecting some. Automatically allowing access to future contacts also shouldn't be difficult. There is no need for apps to always have access to all contacts.
- twodave 7y ago
- rchaud 7y agoIt's for this reason that I use PWAs wherever possible. Right now I'm using it for Twitter and Uber. Tired of turning off permissions and then having to do it again when apps auto-update and restore the original permissions.
- drewmol 7y ago>Anyone affected by this should be suing twitter for even collecting this information! My friend can give away my phone number because of this data collection. If you made some agreement as to how your friend could use your phone number and 'sharing with Twitter' is a violation then you could sue them I suppose. Annoying as this data collection is, labeling information about you as only yours is incorrect, it's your friends and Twitters's (and Google/FB/AMZ/etc.) information too.
- app4soft 7y agoQuick & dirty fix: never use built-in/default apps for storing contacts list on your devices.
- codedokode 7y agoThat's not the only way Twitter uses to collect phone numbers. It can arbitrarily block your account and require to confirm a phone number to unblock it (under excuse of "better security"). How disclosing your phone number helps being safer I don't understand. Now those collected and leaked phone numbers will be available not only to Twitter and US government but to anyone wishing to buy them from hackers.
- mlindner 7y agoTwitter has never asked to access my contacts before. Where are you seeing this?
- numpad0 7y agoI think they’re selecting target demographic to do this, because for e.g. Japanese it means having Twitter account associated with their real names means they’ll be laughed at from everyone close to(maybe 25% literal) death. Same for follow suggestions based on IP.
- TheLastSamurai 7y agoYes, totally. Thieving from a thief logic applies here.
- rhegart 7y agoI just quit when they finally said I had to to log in.
- sohkamyung 7y ago> Twitter asks users on sign up to scan their contacts To be clear, this applies to the Twitter app for iOS and Android, correct? I exclusively use the Twitter web interface (even on my Android phone) and I have never been asked this.
- markdown 7y agoIn some countries (including mine), all sim cards/phone numbers are registered to an individual, so this is a pretty big deal.
- raxxorrax 7y agoTwitter should be seen as an asylum if you ask me. But yes, if they leaked numbers from third parties not involved in Twitter at all, there should be severe legal consequences. But I doubt there is much incentive to even create a legislative basis for such transgressions. Complicated topic to be fair, but we will only see improvements if there are severe penalties for "loosing" data. Since no system is safe, there is only the alternative left not to collect info you do not need.