11 ms·
Every time I see something like this come up, it really makes me wonder how many other apps out there are doing the same thing and getting away with it. Unless
by sikhnerd 12y ago
Every time I see something like this come up, it really makes me wonder how many other apps out there are doing the same thing and getting away with it.
Unless you root your phone and use something like the mentioned android firewall, or go whole-hog and install Cyanogenmod, what chance do you have to guard against this?
I assume ios users are likely in the same boat, but with even less chance of recourse.
- stingraycharles 12y agoNever attribute to malice what could also be attributed to incompetence. All we know is that it makes the location requests, it could just as well be attributed to sloppy programming.
- sz4kerto 12y agoDunno. How can you inadvertently request location info when you're implementing a keyboard for Android?
- mahouse 12y agoRead the thread and specifically the answer from one administrator of the board.
- matthewmacleod 12y agoWe check for last known location in order to provide regional dialects via Living Language. I'm not saying it's legit or required, but that's their explanation from the link there.
- tejaswiy 12y agoWhy don't they just use the current locale info ? Why assume their keyboard is extra special when the user is happy with how the rest of the system is setup?
- bunderbunder 12y agoLooks like Living Language isn't just about figuring out the user's current locale. It's about learning local slang and dialects based on what Swype users are typing, in order to give users a dictionary that's much more specific than something generic like "en-US". For something like that you'd legitimately want to know where someone is down to the city or even neighborhood. Though checking their location 4000 times/day still sounds egregious to me. And possibly misguided - the way I speak English isn't going to change just because I've gone to Petoskey for the weekend.
- pyre 12y agoI think that the 'sloppy programming' comment was directed at the volume of requests. Maybe a poorly chosen location poll or polling interval. Whether or not a keyboard should be polling your location at all is another question.
- Groxx 12y agoI'm reasonably sure that the Google keyboard does. It's used for nearby-city autocomplete, which can be pretty handy.
- IgorPartola 12y agoThe crazy thing about all these rooting methods is that the code is seldom open and in either case they always distribute binaries anyways. Rooting your phone is no guarantee of anything. Edit: think about how this would play out if you were to go on an Apple or Ubuntu forum and someone said "here, run this executable on your laptop to get extra functionality from it. I cannot give you the source because it's secret. But trust me, my name is FunkBlade3000 and I have over 2,500 karma on this forum, so you know you can trust me." Even our grandparents now know not to do this, yet I see IT professionals happily rooting their phones this way.
- ultramancool 12y agoMost (flagship) phones are rooted using an unlocked boot loader... in which case the "rooting methods" you're refering to is just a script to run a few commands to unlock the bootloader in fastboot mode, boot the phone into a temporary recovery system (which are by the way open source) and then use that to modify the OS. You can do it from a CLI yourself if you like. It's just time consuming. Most people just want the push button solution, yeah, maybe it's hacked together by some guy on a forum, but most of the solutions I've seen like that are just shell scripts in one form or another.
- hengheng 12y agoYou'd still have to hand over root permissions to a random binary just the way grandparent described... Even in the play store, 80% of my apps have no authorship that go beyond a Gmail address.
- deleted 12y ago[deleted]
- thefreeman 12y agoActually no. To unlock android devices all you need to do is run "fastboot oem unlock". You can then optionally flash a custom recovery, custom firmware, or just sideload a Superuser apk. At least one of which is open source. https://github.com/koush/Superuser https://github.com/koush/Superuser
- Frazzydee 12y agoGoogle seems to have no interest in protecting android users from this either. There was an app called 'App Ops' that gave android users the ability to choose which permissions they wanted to grant applications. No root required. Get too many notifications from an app, or don't need location functionality? You used to be able to turn these features off one-by-one for each app. You could also see the last time an app used location services. Android developers have a bad habit of requesting every permission under the sun, so I've gotten in the habit of disabling the permissions that don't add value for me. Unfortunately, Google later removed this feature saying that its release was accidental. I thought it was a clean solution to a major problem. Source: https://www.eff.org/deeplinks/2013/12/google-removes-vital-privacy-features-android-shortly-after-adding-them https://www.eff.org/deeplinks/2013/12/google-removes-vital-p...
- Pxtl 12y agoWhat really disappoints me is the terrible placement Google uses for privacy features in the Play store. They're really hidden away instead of being prominent searchable fields. Microsoft of all companies does far better with their Windows Store.
- TheCraiggers 12y agoI would agree with you except for the part where they force you to see them before you're allowed to even install an app. It's hard to get much less hidden than that.
- nitrogen 12y agoIt's not particularly useful if the permissions aren't displayed on lists and aren't searchable. The only option now is a brute force search by hand, clicking Install on each app in a category until you find a version of 2048 that doesn't demand SD card, camera, and full net access...
- scep12 12y agoIt was never released -- they removed access to a feature that was not intended for the public. That seems well within their right. For you to declare "Google seems to have no interest in protecting android users from this either." seems quite misguided, given that they are clearly working on a solution for this exact problem.
- davexunit 12y agoProprietary applications spy on their users constantly. It's no surprise that Swype is making these location requests. Rooting your phone isn't an answer in itself. Rooting allows you to install a more free Android distro like Replicant or CyanogenMod. However, if you're still using proprietary applications then you haven't accomplished too much. iOS users have no chance at all. There is no freedom in the iThings. Apple is in strict control over their users.
- nb4hnp 12y agoiOS allows users to choose whether or not each individual app can make use of the location services. Cute attempt at FUD though.
- pille 12y agoFor this specific problem though, "settings" -> "privacy" -> "location services" allows you to turn off location tracking per app in iOS, or turn it off altogether.
- JTon 12y agoAgreed. But I'd like to point out it's not not clear whether the insane amount of location requests is a "feature" or bug. In the thread OP linked to, other users reported Swype acting as expected (i.e. few to no location requests)
- threeseed 12y ago> iOS users have no chance at all Except that you know they have more protection than Android. The user is prompted when the app requests the users' current location and there is per-app preferences to disable location service.
- e40 12y ago"However, if you're still using proprietary applications then you haven't accomplished too much." Wrong. You can revoke the permission to request the location with apps like App Ops X (needs root).
- 12y ago
- threeseed 12y ago>I assume ios users are likely in the same boat, but with even less chance of recourse. You assumed wrong. On iOS when an application requests access to your current location the OS shows the user a prompt. If a keyboard replacement app was requesting my location I would be asking serious questions about its intent. iOS has a very well implemented permissions systems that I have no idea why Google hasn't copied yet. They really should.
- bunderbunder 12y agoOne nice side effect of this is that on iOS, most apps don't even try to ask for information they don't actually need. OTOH, there are also no (approved) keyboard replacement apps for iOS. :/
- bbradley406 12y agoI recall reading here that on Android, an app won't automatically update if the newer version needs additional permissions, so most devs ask for all they could possibly need up front. Ideally, Google will bring back App Ops (with dummy data so that apps don't crash), and allow explanations in permission requests. Currently, iOs has per-app permission settings, and apps don't crash when you deny them access. This doesn't solve the problem of users just clicking "allow" blindly, but it does provide more fine-grained control.
- e40 12y agoIf you're on Android and rooted, use App Ops X. It allows the revocation of individual permissions, like location, wake lock (a battery waster), and others. Every time I install a new app, I look at Ap Ops X and see what perms it's using and revoke the ones I don't want it to have.
- drdaeman 12y agoI'd recommend XPrivacy. It's much more granular (function level ACLs with some argument-level filtering), so one could allow connecting only to specific hosts or opening only allowed file paths on external storage.
- Groxx 12y agoSeconded. I've been using XPrivacy for quite a while now, very stable, very useful. It also shows you the last time a call was made, so you can see e.g. that a variety of apps try to access your contacts after asking you if you want to allow it, even when you say "no" (which is not necessarily shady behavior, but still frowny-face inducing).
- jchung 12y agoI feel the same way. After the whole flashlight app data harvesting debacle on Android, I haven't been able to find a flashlight app for my phone that doesn't give me privacy goosebumps.
- dublinben 12y agoOpen Flashlight in F-Droid is open source and GPL. You can verify that it respects your privacy.
- jchung 12y agoAwesome. Just checked. https://github.com/sanbeg/flashlight https://github.com/sanbeg/flashlight That's better...
- icebraining 12y agoBut the flashlight in the data harvesting debacle requested your location. It didn't somehow fetch data that your didn't authorize it to get. You can just install a flashlight app that only asks for the permission it needs.
- afro88 12y agoiOS has per app location privacy settings. Just switch location services off for any apps you're suspicious of. It also prompts for GPS permission on first use in an app, so it will never send your location without you having allowed it to do so in the first place.
- micampe 12y agoYour assumption is incorrect. On iOS you can turn on or off location (and several other permissions) for any application at any time, since day one.
- jmomo 12y agoIf you don't 0wn your phone, you don't own your phone.