On by default: your apps are sharing more than you think

A security researcher recently did something very creepy but insightful. We dug into data from the AllTrails app to track down a former White House official. Researchers have been able to track visits to the White House, locate users’ homes, and even track official activity across Washington DC via data exposed from the hiking app.

This did not occur because the particular user was a government official or was in any way prominent. This happened because the app was set to expose user data activity to the public. DefaultAfter Strava was found doing the exact same thing, the military had to reconsider using this kind of app. So many apps do that. Also Tim Horton.

I can’t read minds, but the current political climate means that public officials don’t want to share where they are with anyone, let alone visits to the Pentagon or NSA offices. I’m sure. This is just a case where another consumer didn’t know the app was doing more than they thought because Apple or Google allowed it.

Strava app on Galaxy S22 Plus and Galaxy Watch 5 Pro (both sitting on top of running shoes)

(Image credit: Michael Hicks/Android Central)

The rise of mobile technology has revolutionized the way we interact with the world. Mobile devices such as smartphones and tablets have become an integral part of our lives, enabling us to communicate, work and play on the go. However, with the proliferation of mobile apps, privacy and data protection concerns are becoming more prominent. Many mobile apps require access to personal information such as location, contacts, and online behavior, raising questions about the potential for misuse of this information.

One of the most important concerns with mobile apps is the default privacy and location settings. Apple and Google have done a lot of work to prevent access to your contacts and location without your consent, but most apps allow access to almost everything. It knows to allow and is designed to collect user data by default. This practice is so prevalent that many people have grown accustomed to the idea of ​​granting apps access to their personal data without giving it too much thought.

Strava Run Tracking

(Image credit: Michael Hicks)

This raises serious privacy and data protection concerns. By allowing apps to access and share our personal data, we effectively lose control over our information. This can lead to misuse of the data, either by the app developers themselves or by third parties who may have access to the data. However, it can get worse (as mentioned above) if the app settings are all set to on without checking.

To address these issues, settings that may share data with anyone or other services should be set to off by default, and users should be able to choose whether or not to enable it. This approach puts us in control of our data, allowing us to decide what information we want to share with app developers and the world, and what information we want to keep private.

Granular Media Permissions in Android 13

(Image credit: Google)

One of the main benefits of this approach is increased transparency regarding data collection. By making the setting opt-in rather than opt-out, app developers must provide more information about the scope of data collection and how that data is used. This helps increase trust between app developers and users. Because users can make informed decisions about whether to trust apps with their personal information.

Another advantage is that it helps reduce the potential for misuse of user data. By giving users more control over what happens after their data is collected, app developers are less likely to engage in practices that may be considered intrusive or unethical. For example, app developers are less likely to provide user data to third parties if they know users can opt out of data collection and sharing. This ensures that everything is used only for legitimate purposes and in a manner consistent with users’ expectations.

Amazon Sidewalk opt-in screen

(Image credit: Future)

Of course, the main advantage is for us. By giving you more control over your data, you’ll be able to protect your privacy more effectively. By allowing you to choose what data to share and what to keep private, you can better manage your online privacy. This is what everyone should want.

Some critics of this approach may argue that it is too complicated for users to enable privacy and location settings on their own. Most users are already familiar with the concepts of privacy and location settings and can enable them with minimal effort. As part of the app onboarding process, we already enabled some permission settings, so the process of enabling other settings is not as complicated as it is today. Developers just ask.

Walking activity showing steps and time since start on Garmin vívoactive Trend

(Image credit: Michael Hicks/Android Central)

Some developers will not see this as a problem. Because some apps are already built this way and want to easily check the settings when first starting to use it. No other developers participate, just the setting is turned on. Don’t spend your time looking to make money.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *