5 ms·
The worst I've had is a clock/weather widget that seemed to give you a choice of ads/no-ads, but if no-ads were chosen, it would make your phone part of a netwo
by msravi 3y ago
The worst I've had is a clock/weather widget that seemed to give you a choice of ads/no-ads, but if no-ads were chosen, it would make your phone part of a network of proxies (oxylabs) without telling you, in addition to transmitting location info (which it told you about). No payment option to get rid of ads/data selling. Only way I found out was by looking at requests it made using netguard.
- MaxBarraclough 3y agoWould you be willing to name the app?
- msravi 3y agoSimple weather and clock widget by Difer. I think they've now removed the proxy and added a payment option, but I'd never trust them again.
- teakie 3y agomastodon inctances are prone to this. user data stored in plaintext, even PM are unencrypted and readable by design for moderation
- dncornholio 3y agoMastodon has no secrets. Never post secrets on Mastodon. It will get broadcasted and can be abused. Treat system as such and you're golden.
- teakie 3y agoIt's also bad for publishing (they now use the term too, anyways) all (I mean really like ALL of thoose tech savy people store their data in plaintext on someone computer, they not know what this thing does. there are many thousand on one instance. which disappears. maybe they where ethical people had no dirtmoney, couldn't exchange information to currency to pay the hoster.. I don't know. But you can get banned pretty quickly. Even when talking in private, a mod can decide it's creepy and ban you. they still have the data. you no access to your audience.
- thejohnconway 3y agoThey aren’t PMs, they’re DMs.
- edgyquant 3y agoThese are two words for the same concept.
- runjake 3y agoNot at all. One is private, one is direct and not private.
- teakie 3y agothey are actually toots. it's an feature that other people can read what you say in private to someone and ban you if it's creepy (the conversation) besaid feature is active on all instances it's not opt out. no instance has an inhouse fix (think they would post about it, since people like to talk in private. I mean almost every human on earth does use e2ee but mastodon is such an (honestly? the devs are drunk or something really fishy going on there. they got funding and build an client (that is exactly what was NOT need or useable or their thing)) clusterfuck. it's to complecated they say. I know, ping me if you have same thought, it's easy to fix!
- eitland 3y agoThe worst I had was an alarm clock app that cost somewhere $3 - $6 a month (it has been a while) but still wanted to collect data on me. Worst part was while I decided against using it, it still took a while before I found a replacement. Seriously: Monthly payments, and not only $1 for an alarm app, and then they have the gall to try to get away with tracking me on top of it..!
- mdp2021 3y agoIt's actually a bit trickier than I am about to present it, but: is it possible that you did not suspect that an "alarm clock" should need no Internet permissions?
- dspillett 3y agoIt was described as an “alarm/weather widget” - the weather portion would need network access to get uptodate forcast data so that wouldn't seem odd.
- late25 3y agoI have to suspect they thought whoever was gullible enough to pay $3-6 a month for an alarm app would surely not care about their data going along with it.
- plagiarist 3y agoThe entire demographic in the data is willing to pay $3-6 a month for an alarm app. I'd sell the data too, they're probably hitting printer ink levels of valuation for it.
- Workaccount2 3y agoI never thought about how valuable the list of idiots willing to sub for basic functionality apps would be.
- skinkestek 3y ago
- dspillett 3y agoSimilarly, the default clock that came with my Xiaomi phone wanted permission to access my contacts before it would let me set an alarm. It did not get any such permission, I run an alternate clock/alarm app instead, and this will be the last Xiaomi phone I buy.
- NavinF 3y agoTBH that just sounds like bad design. The manufacturer could easily have granted that permission out of the box and you'd be none the wiser. A lot of built-in apps have permissions that can't be viewed by the user
- alwayslikethis 3y agoGoogle Apps generally have all permissions. GrapheneOS actually offers a sandboxed version of them that works like normal apps, and you can see how many permissions it is requesting.
- IndySun 3y ago"TBH that just sounds like bad design"... It's not bad design, it's deliberate design. https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pdf https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd...
- NavinF 3y agoLink doesn't explain why a built-in app would ask for permission to do anything. Eg as the sibling comment mentioned, Google apps often have full permissions by default and don't need to ask
- IndySun 3y agoI couldn't possibly link to the copious evidence online, anecdotal on this forum, high stakes data breaches, that personal data is being harvested by default en masse. It is true about the link, it was meant as nod to some at least scientific endeavour to investigate sharing.
- hnburnsy 3y agoI noticed that my Samsung phone the Clock app has "QUERY_ALL_PACKAGES". According to Google this is not a permitted use of QUERY_ALL_PACKAGES. F Google for not allowing user consent for this permission. >Permitted uses involve apps that must discover any and all installed apps on the device, for awareness or interoperability purposes may have eligibility for the permission. Permitted uses include device search, antivirus apps, file managers, and browsers.