4 ms·
'Perhaps "This app would like to use HTTP for its API" should be a permission that the user has to explicitly give.' Good idea.
by nodata 12y ago
'Perhaps "This app would like to use HTTP for its API" should be a permission that the user has to explicitly give.'
Good idea.
- Tepix 12y agoChances are the app is doing a NSURLRequest and the OS can't tell if it's an calling API some other HTTP(S) request.
- richardwhiuk 12y agoUnless internet access is segregated into the following it's fairly meaningless: This app would like to use HTTPS This app would like to use HTTP This app would like full internet access From a security point of the view the app realistically should also pin it's certificate as well - the app developer knows the certificates that the app should expect to prevent Charles proxy working.
- balabaster 12y agoIt needs to be more obvious than this... the average non-technical user isn't going to understand the ramifications of this verbage without training - even as minimal as that training may be. - This app would like to transmit secured data over the internet. - This app would like to transmit unsecured data over the internet. Transmitting unsecured data could result in it being intercepted by unauthorized third parties for unintended purposes such as monitoring or tracking of your communications or identity theft. This information could also be used to gain unauthorized access to your devices or accounts. Of course, even if it is secured... it could still be used for such by anyone who can acquire the private key of the server, then you're pretty much hooped. I guess ultimately, it just needs to warn the user that data is being communicated with the internet. It's probably being tracked and monitored by someone and probably not for the purpose the user intended. Use with caution.
- grabeh 12y agoI suspect it is unlikely that the average user would understand the ramifications of agreeing to that request though. How about "This app would like to send your location to its API insecurely"?
- skywhopper 12y agoThe OS does not know what data the app is sending to its API, so it couldn't provide this specific of a warning.
- nodata 12y agoAn average user doesn't know what an API is.
- buro9 12y agoOr better still: "This app would like to send data over the internet insecurely." There would be a nice stampede to get SSL coverage for API endpoints if we called it what it really is.
- jacquesm 12y agoWait until people find out how many of their emails travel in plain text.
- declan 12y agoYup. I wrote about this for CNET in 2013: http://www.cnet.com/news/how-web-mail-providers-leave-door-open-for-nsa-surveillance/ http://www.cnet.com/news/how-web-mail-providers-leave-door-o... "A survey of top mail providers shows that Google is alone in using strong encryption, known as SMTP-TLS... Facebook, Hotmail, Yahoo Mail, and AOL Mail do not accept incoming e-mail in SMTP-TLS encrypted form..." I hope things have improved since. (Some enterprising journalist might want to do a followup.)