9 ms·
Can't speak for Android, but on iOS it is not possible for an app to "listen" to your microphone unless it is in the foreground, and you have explicitly given t
by Herald_MJ 10y ago
Can't speak for Android, but on iOS it is not possible for an app to "listen" to your microphone unless it is in the foreground, and you have explicitly given the app permission to do this (the first time the app attempts to do so). It can also be revoked at any time without removing the app.
The only way around this restriction would be using a private API Apple could have provided. Given that Apple has even integrated some aspects of Facebook into iOS, this is not totally impossible, but it's hard to imagine Apple having an incentive in allowing Facebook to passively record and transmit all user audio. To date, Apple actually seem to be pretty good at protecting user's privacy.
- hellbanner 10y agoYou mean when they removed their warrant canary a few years ago under the guise of "new security policy"? When they were found to be tracking GPS positions even with GPS disabled? (Sorry it's impossible to find a link to this anymore) How about the Bluetooth vulnerabilities their desktop computer suffer -- I've seen keyboard connections trivially hijacked. I'm not suggesting that Apple has made a deal with Facebook (I think you're right on not being incentivized to do this), but to say Apple is "pretty good" at protecting a user's privacy, I question that.
- Herald_MJ 10y agoI know of the first two examples you gave, but disagree that they're evidence of Apple not being interested in user privacy. Let's not hijack this thread to talk about Apple's security record.
- madmax96 10y agoIt'd be interesting if there were a party with a JailBroken iPhone and the Facebook App installed who would check the network traffic.
- eric_h 10y agoWould a jailbreak really be necessary for this? Couldn't you just install a certificate on the phone and MitM the https traffic?
- madmax96 10y agoThat would be a lot simpler:)
- superuser2 10y agoNot if the app is certificate pinning (and from a security perspective, it ought to).
- eric_h 10y agoIs this a common thing for apps to do, yet? I was under the impression that there are some corporate networks which treat MitMing ssl connections as a business necessity. Would Facebook et. al. allow their apps to stop functioning on networks like that?
- superuser2 10y agoI can't imagine an enterprise which would MITM employee web browsing but not block Facebook. Come to think of it, I can't imagine an enterprise that would MITM employee web traffic but allow personal smartphones on the network.
- eric_h 10y agoHa. Yes, fair enough. But, presuming they didn't, would it not be in facebook's best interest to allow their app to still work, perhaps with a visible warning?
- joshstrange 10y agoUnless Heard has stopped working then this is not 100% true http://www.heardapp.com/ http://www.heardapp.com/ It may put a banner on the top bar but I've used this app and it worked just fine.
- koyote 10y agoVery off-topic but what is your real-world use case for such an app? The site lists a couple but most of those seem to make more sense when using a recording app in the traditional, explicit, way (e.g. "we are having a meeting, I will record this meeting").
- joshstrange 10y agoSo honestly it's best use case is "gotcha". As in you didn't know I was recording and you said something stupid and now I have a recording. Likewise if you are talking to someone and you say something along the lines of "Are you sure about that?" or "Can you confirm this is what/how you want me to do this" and then you record the audio for later incase they come back and say "I never said that". For myself I went the extra mile to just have my laptop record ALL audio but then felt this was a little too douchey/NSA-y and disabled the whole thing and wiped the audio. I wanted such a system not only for "You said this then and now you are saying that now" but to remember things I had said myself. I wanted to hook it up to STT to have a searchable archive of what I had said but again it was an invasion of privacy (to people around me) that I personally couldn't stomach.
- imbeau 10y agoBesides the creepiness, the law around recording people without them knowing (one-party consent) is state-by-state
- joshstrange 10y agoI Iive in a one-party consent state, I checked before I tested it.