Mozilla says “most top apps” on Android have misleading privacy labels

A man laughs at his smartphone while a cartoon character peeks over his shoulder.
Expanding / A tiny Android robot watches your every move.

Relying solely on developers to tell the truth about their data collection on Google Play doesn’t seem to work. Much like iOS, Android launched a “nutrition label” for app privacy on the Play Store last year. The idea is to allow users to immediately see how much data each app collects. An obvious problem with this system is that developers fill out data collection forms, and nothing stops developers from lying or omitting certain data collection policies. It’s no surprise that a recent audit of Google Play’s top apps found that “most of the top apps” had a “false or misleading” app privacy label.

Mozilla surveyed the 40 most popular apps on the Play Store by global downloads and found that “nearly 80% of the apps reviewed had a conflict between the app’s privacy policy and the information reported on Google’s data safety form. Each app was rated “bad”, “needs improvement”, or “ok”, with 16 of the 40 apps receiving the lowest ratings. .

Mozilla didn’t have to dig too deep to find the flaws, stating that many apps’ privacy labels openly contradicted their public privacy policies.. Snapchat, TikTok, and Twitter all claim to “do not share data with third parties” on the Play Store, but detail their sharing with third parties in their privacy policies. When Facebook, Facebook Messenger, Facebook Lite, Snapchat, Twitter, and surprisingly Samsung Push Services are free apps, the list of recipients with “bad” ratings isn’t all that surprising.There are many paid games such as Mine Craft Also make a “bad” list.

TikTok's Google Play privacy label and its privacy policy.
Expanding / TikTok’s Google Play privacy label and its privacy policy.

Mozilla

Mozilla says: “There is little evidence that Google works diligently to ensure the accuracy of their posts, and this lack of enforcement very often results in very poor quality information.” We have provided some recommendations to Google in case you want to remedy the situation. For example, by actually punishing them for lying on the form, or by making it clear to users that Google does not vette these responses. Mozilla also hopes that Google and Apple will work together to standardize the design of privacy labels for apps across the ecosystem. Just like one food nutrition label has a standard design across products, Mozilla says he should have one design for privacy labels too.

Mozilla has rated some Google apps like Gmail as “needs improvement,” but trees lack forest. This report doesn’t delve into this in depth, but for Android, Google likes privacy tricks and “OS privacy” (privacy from Google) is probably more important than “app privacy”. focus the discussion around the idea of of concern. Both Google and device makers have system-level access to the OS that lives outside of the app security model, so basically they can do whatever they want with the phone, including collecting all the data. can do.

Even if the apps’ privacy labels were accurate, Android is a class of companies that doesn’t need it. app Vacuum the data. Instead, one million different system-level services are available. One such service, Google Play Services, includes empty field App privacy screen! If that’s accurate, it would be a mile long, but Google apparently prefers not to look behind the curtain. The same “privileged permissions” model also applies to pre-installed apps. This is one of the reasons why Facebook is difficult to pre-install on most Android phones. More permissions allow for better spying. It would be nice if the Play Store labels were accurate too, but no one wants to talk about the OS as a whole.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *