3 ms·
> No Consent. Under the ePrivacy Directive, the mere access or storage of data on the user’s terminal device is only allowed if users give their free, informed,
by TheMode 3y ago
> No Consent. Under the ePrivacy Directive, the mere access or storage of data on the user’s terminal device is only allowed if users give their free, informed, specific and unambiguous consent. Two out of the three mobile apps did not display a consent banner when launching the app. The third app presented a banner that theoretically gave the complainant the choice of giving or withholding their consent. In reality, the transmission of their personal data began without any interaction on their part – and before they even had a chance to think about consent.
Why do nobody question the fact that it is possible for an application to access data without user consent to begin with? Why are we transforming it into a human problem? The tech is to blame.
- MichaelZuo 3y agoIt does seem a bit surprising, I thought it was totally blocked on iOS without user consent?
- TheMode 3y agoI assume that it is dependent on the platform, and what you are accessing. The problem is that we first design platforms/APIs to automate everything, and secondly try to make it secure/explicit. We need the opposite.
- pixl97 3y agoWon't happen till laws demand it. Very few companies/programmers I know write 'secure first'. Most of the time it's "this shit isn't working, turn off the security stuff and see if it works then we'll re-enable it later"
- TheMode 3y agoWhat app developers want/do is irrelevant. I am saying that it should be impossible for any individual app to access or connect to anything without explicit user consent. We need to stop automating everything and then complain that companies aren't putting optional banners everywhere. This is beyond stupid.
- ianlevesque 3y agoFor what it's worth, the opinion isn't universal. As a user I like the Haiku approach of not even having "user accounts" and on Linux I have 'sudo nopasswd ALL' on. Coddling everyone and sandboxing everything without any options to get that stuff out of the way isn't acceptable to me. Security or even privacy aren't always my top priority, and I should have that freedom available to me, even if you want the option not to have it.
- TheMode 3y agoIt is easier to build automation on top of a simpler/manual/secure process, than it is to make a fully automated system secure. I am not saying that automation shouldn't be possible at all, but that platforms shouldn't be designed this way. If users had to consent to contact access, socket connection, and every single packet sent (obviously they would need to become readable to layman) there would be way less demand for data privacy laws.
- pixl97 3y agoHonestly with most users the opposite seems to happen. They get warning fatigue and start clicking YES on everything
- TheMode 3y agoThat's understandable, and so perhaps that we need to re-think our computing model to replace yes/no popups with something a bit more involving. By "involving" I do not necessarily mean harder, the goal isn't to make computers less accessible, but if we give users the ability to control whatever go in and out their devices maybe that making them a bit more interactive so instead of clicking "yes" to allow keyboard access you could drag a keyboard icon to the app or any other device you want to use as input instead. Consent doesn't need to be presented as yes/no, there are multiple ways to make users understand what is being accessed.
- 3y ago
- jshier 3y agoLocal storage, whether straight to disk or through UserDefaults, has no permissions on iOS.
- lowbloodsugar 3y ago>The complainant installed the popular apps MyFitnessPal, Fnac and SeLoger on their Android smartphone.
- sanitycheck 3y agoOf course the personal data needs to be transmitted prior to interaction! How else could we send the "consent-banner-displayed" event to Google Analytics to know if it's working?!
- dale_glass 3y agoGoogle is an advertising company and it's not in their interest. It's absolutely technically viable to build an app store that incentivizes using the minimum amount of permissions possible, or to even feed fake data to overly nosy apps. In fact it's been done, but it'll be a cold day in hell before Google makes it easy. Eg: https://playsearch.kaki87.net/ https://playsearch.kaki87.net/