9 ms·
Google to ban financial lending apps from accessing user photos, contacts
- two_handfuls 3y agoWhat we really need is finer-grained permissions like “let the OS pick a photo and hand it to the app” and “let the OS pick a contact and hand it to the app” and then require that most apps use that instead of overly-broad permissions that will be abused.
- eimrine 3y agoI am so sad that I live in the society which is needed in such regulations. This change sounds like something good, but ability of vendor to do all kinds of things with a device makes me a smartphoneless person.
- ikiris 3y agoAlmost all regulations are written as a result of some entities' abuse. That's why it's always so baffling to me how libertarians exist. Like the entire world view requires the holder to not understand history.
- ranting-moth 3y agoI reality, very few apps should have access to that data in the first place.
- version_five 3y agoIt's "good" in the same way that "google stops punching man in the face" might be good. In a sea of predatory applications, why is lending the only one that gets blocked here? A whitelist would be better (say approved photo and contact apps could access photos and contacts), and better still would be the app can only access what you transfer to it and doesn't get blanket permissions. I also agree with the other comment that this shouldn't be within Google's power to decide, it should be regulated - if you force a closed OS on users, you should be limited in what it can access
- simfree 3y agoThere is such a thing as going too far though. An app I'm familiar with had Apple rejecting the app for accessing contacts, even though the contacts stay on device at all times and the only way they are exported is if you send a debug log which has a warning modal about their contacts being logged and gives the user the chance to edit those out. There was nothing to be done that would satiate Apple besides disabling the contacts permission, so the user experience is now worsened. It's still death by a thousand cuts when working with these app stores.
- version_five 3y agoWhat did the app need the contacts for? I'd say I side with apple on that (I can see how it could be abused to shut down competition though). There really would need to be a good reason to have the contacts. (I don't want to debate the threshold, just interested in a "benign" example of needing contacts)
- simfree 3y agoCalling, texting or emailing said contacts from inside the app. Having this data was for the exclusive benefit of the end user, and the permission was optional and did not block use of the app.
- nerdjon 3y agoAs the other person said, what did it actually need the contacts for? Was it being rejected for asking or for being broken if it didnt get the permissions? Or was it simply not able to give a justifiable reason to Apple for needing the permission? You say it was staying on device but once you have access to those contacts it would be trivial to add the ability to send them to a server or have them leak via third party tools like the facebook sdk. That would be completely invisible to the user after giving past permissions. The fact that you say that the user experience is now worsened makes me believe that contact access was not an absolute requirement for the app to exist (like say... a contacts organizer or something) and is extra functionality. Personally with very very few exceptions I will not grant an app access to my contacts since anyone in my contacts don't have the luxury to also consent to some company having their data.
- expertentipp 3y ago> predatory loan apps Loan sharks?! We reached a point when I don't even allow chat app (WhatsApp) to access my contacts. Banks' apps love contacts as well ("send money to phone number"). With "convenience" bait they get birth dates, physical addresses, emails, profile photos, and whatnot. I see from behind my keyboard how banks salivate to calculate some credit worthiness from the contacts uploaded (and confirmed by the entry in the other person's address book).
- babyshake 3y agoI just immediately uninstall any app that requests access to contacts without me first indicating I'd like to use that app to share something with my contacts.
- toastal 3y agoThis is the correct kneejerk, but I assume it's not for the majority of users. It makes me hesitant to give out contact info knowing it'll end up building shadow profiles despite how useful having a easily-shareable vCard should be.
- deleted 3y ago[deleted]
- josephcsible 3y agoThis feels like treating one particularly visible symptom of the problem instead of fixing the actual problem. What Google should do instead is prevent apps from refusing to work or disabling unrelated functionality just because some permissions are denied (e.g., if you deny your banking app permission to access your camera, everything but mobile check deposit should still have to work). They should use a two-pronged approach to do so: 1. Make that a rule in the Play Store and ban apps that violate it 2. Make Android present convincing fake data to apps when permissions are denied
- amelius 3y agoI wrote almost exactly this comment more than five years ago. It is a shame that it is taking them so long to get security right. Do they even use their own software?
- supriyo-biswas 3y agoThat approach would leave users confused as they see fake contacts or photos being surfaced through the app that was denied said permissions.
- waboremo 3y agoOnly if you use fake contacts and photos that look real. Instead whenever this is done elsewhere, there is text on the image and the names are obvious. Google can even add a page within privacy where you see the fake options before you can enable it system-wide/per-app.
- supriyo-biswas 3y agoThe app could also detect the fake text based on general testing (after all, there's gonna be only so many variations of "Biggus Dickus") and refuse to dispense the functionality in question.
- joshuaissac 3y ago
- jbritton 3y agoI think the OS should provide the ability to select items and then give opaque handles to applications. The app could send a message to the OS to display photo selector. The OS could send a message back with a handle to selected photo. One could then asks the OS to send a handle, which would forward selected item somewhere else.
- 20after4 3y agoiOS already has this feature precisely. I can either grant access to all photos or only a selected subset, or even just one.
- abyesilyurt 3y agoOr none, then the all would think you have no photos, instead of getting permission denied error.
- nerdjon 3y agoI feel like this was introduced within the last couple years and did not get a ton of attention when it did. But like many things with iOS Apple did this and apps had no choice but to work with it since (seemingly) as far as the app is concerned it is the same situation as before. I do wish though it was easier to grant more images without needing to go to settings. I have had one app that somehow gave me the ability to add more images, but I am not entirely sure how it did it.
- HeavyFeather 3y agoAnd I love it, but it has two issues: - Apps can refuse to work with that, like Google Photos (it used to work during the beta and it was perfect for me) - Apps still offer their awful photo picker on top of your already-picked photos, so selecting new ones requires a lot of taps. I wish Apple would reign in some of these apps. In-app browsers and custom photo pickers should be banned unless they have demonstrated advantages.
- the_snooze 3y ago
- nerdjon 3y agoOff topic of the lending apps but something I have long wanted to see is actual information about the data accessed by these apps. Maybe Android has this, but on iOS I can go into privacy and easily see what apps have access to what data (and easily revoke that permission). But I don't see any kinds of metrics that would indicate that an app is possibly abusing that permission. For example, it would be awesome if I could go look at photos or contacts and see a percent for how much that app has accessed that data and maybe even a graph overtime so I can see if it was a one time thing or its mining for data. There is the app privacy report on iOS that gives me some of this data, but it doesn't give me how much data it is accessing. Which I think is the critical part. If I give an app access to my photos I expect its going to access it, but without knowing what its doing its not quite as useful. Still useful, but not as useful.
- mattzito 3y agoAndroid has it: https://techcrunch.com/2022/04/26/google-play-launches-its-own-privacy-nutrition-labels-following-similar-effort-by-apple/ https://techcrunch.com/2022/04/26/google-play-launches-its-o...
- nerdjon 3y agoUnless I am missing something, that is all on the play store side before you download an app? I am talking after you have the app installed to actually see what it is doing. Specifically what it is doing. On iOS I can see that an app is accessing photos and I can see when, but I can't see what or how much. The feature you mentioned is similar to the labels that iOS has. It even says that in the header.
- hadrien01 3y agoI have that feature on my tablet (Android 12L or 13), but like you I can only see when ("last 24h"), nothing else. Edit: I just checked because the screen design felt weird compared to the rest of the settings, it's controlled by Google: com.google.android.permissioncontroller (and it hides Google permission usage by default...)
- swframe2 3y agoI am curious. Why not give each app a private copy of common user resources? Every app has access to contacts but by default only the ones they create. Then android should allow sharing across apps based what the user wants to share. It would be a little bit tedious to share but an OS provided sharing tool can reduce that friction.
- Ekaros 3y agoSo I take they also prevented Google Wallet from accessing that data?
- iamleppert 3y agoThey need to ban that Dave app. I signed up because it offered a loan for $500, but when I got in the app they forced me to "connect" my checking account, sucked up all the data, then offered me only $20. With a daily notification to setup one of their "checking accounts". The app was advertised as a short-term loan with borrower-friendly terms ("give us a tip!") -- yeah right. Come to find out it's just a new accounts funnel. Yet this app is allowed to blatantly exist on the app stores, despite not doing anything like what it was advertised to do and tricking you into handing over all your transactions data from your checking account (probably to look at your cash flow and decide how valuable you are from a new accounts perspective).
- FormerBandmate 3y agoThese apps are literally just friendlier payday lenders. They will also go under soon because the unfriendliness of payday lenders is essential to the business model and it doesn't scale well. Dave's delinquencies are probably atrocious
- HWR_14 3y agoWhy would the unfriendlessness of payday lenders be essential to the business model?
- johngladtj 3y agoBecause the type of people who have no choice but to resort to payday lenders are the same type of people who need men with guns to visit their in their house at 2 am in order to pay back their debts.
- HWR_14 3y agoYou are confusing payday lenders (who use the courts and high interest rates to make up for defaults) and loan sharks (who use violence).
- 3y ago
- xrd 3y agoWow, those are an entirely new category of dark patterns. Sending manipulated photos of relatives to get someone to pay a debt. Incredible. All those Meta employees that were lamenting the damage caused by their work at a social media company can rest easy when they tell themselves that at least they aren't working for a Kenyan scammy loan app.
- Tycho 3y agoDo we really need apps? Usually when I want to use one, I've got to update it first. Better to just use websites.
- charcircuit 3y agoApps do not require updating to launch and they autoupdate in the background. If an app is forcing you to manually upgrade either they have poor backwards support oh your computer for some reason isn't downloading the updates.
- Tycho 3y agoWhat if i don’t want it automatically downloading updates?
- charcircuit 3y agoThen you are opting into a worse UX. You shouldn't be surprised that opting into a worse UX results into experiencing a worse UX like having to be nagged about updating instead of letting your system handle everything for you.
- jmholla 3y agoI'd argue the worse UX is letting apps change their UX on a whim without my input, i.e. auto-updates.
- Johnny555 3y agoVery few apps should have full contacts access. There should be a way to share a contact at a time with an app, like if I want to send an email payment through my banking app, it should call an android function to open a contact selector so I can share just that one contact. Or really, just the email address of that contact, not the rest of the data I may have associated with it.
- expertentipp 3y agoCould be also manually allowing only selected CardDAV fields (e.g. only FN and mobile phone) across the address book.
- jpalomaki 3y agoThere’s currently a lot of pressure for Apple to allow alternative app stores or sideloading. That means more choice, but can also weaken the protections for users. Alternative stores will likely have more loose policies for what apps/behavior they accept.
- morkalork 3y agoDidn't google flat out ban pay-day loan businesses from buying ads on Google search? Why would they even let them in the app store.
- hedora 3y agoThe top google three hits for: pay day loan mountain view are labeled “sponsored” and look sketchy to me.
- morkalork 3y agoStrange considering: https://www.npr.org/sections/thetwo-way/2016/05/11/477633475/google-announces-it-will-stop-allowing-ads-for-payday-lenders https://www.npr.org/sections/thetwo-way/2016/05/11/477633475...
- 55555 3y ago>> pay day loan mountain view This might be the first time anyone has ever Googled that.
- Volker_W 3y agoI never understood why Program permissions is such a big deal on Android and IOS, but not on Desktop Windows/Linux, where any application can to everything.
- cj 3y agoThat’s sort of like saying seatbelts shouldn’t be required in cars because you don’t need one on a motorcycle.
- thomasahle 3y agoIt's just that innovation on the desktop side died years ago.
- omoikane 3y agoDepending on the scope of "everything", Windows may pop up a dialog box asking for permission, and Linux will return error to the application. I believe most modern operating systems will not just grant blanket permissions to every application, except maybe single user systems like BeOS.
- autoexec 3y agoI'd love permissions for desktop apps too, but it's not as big a deal because on a desktop I have root access and can monitor what applications are doing myself. I can see which files or hardware is being accessed and when. I can see what network traffic is being sent and to where. I have full control over what applications are installed and what they are allowed to do. I can even fully sandbox apps or run them in VMs. The phone in my pocket isn't mine, I paid for it, but it belongs to Google, and they make changes to it all the time without my permission and without giving any indication to me that something was changed on my device. Google prevents me from being able to see what the apps on it are doing, and prevents me from changing how they run, or from monitoring all in/outbound communication. Google's shitty permissions system is such a big deal for mobile because it's literally all we have "protecting" us, and that isn't much. Naturally that leaves us with zero protection from Google itself. but that's the price we pay for having a mobile device that gives us more freedom than Apple ever would.
- nr2x 3y agoExcept for Google Pay.
- cornholio 3y agoHow about we leave access to Contacts only to apps that, you know, allow you to contact other people and legitimately need either the email or number? Make it a global XOR: you can ask for Contacts OR credit card/financial data, but not both. In any case, there is never a legitimate need to know the entire address book to "send money to your contacts": mobile OSes could just offer an interface to manually pick a single contact and return it to the app, which could then validate it as a financial partner
- quitit 3y agoEurope has the KYC (know your customer) and AML (anti-money laundering) regulations. To satisfy KYC/AML, providers of financial services on apps thus ask to see photo id and pair this with a photo taken by the app itself. I'm not fully across the KYC loopholes, but it seems like this would make fulfilling the regulations very difficult or potentially impossible as the required identification options needed to satisfy KYC each include a headshot. https://www.ecb.europa.eu/paym/groups/pdf/dimcg/ecb.dimcg210127_item3.1b.en.pdf https://www.ecb.europa.eu/paym/groups/pdf/dimcg/ecb.dimcg210...
- MagicMoonlight 3y ago“Apple is evil bro, we need to remove any sort of restrictions on what apps can do”
- ThorsBane 3y agoThis is a cool feature, good job Google.
- caskstrength 3y agoWas was that ever allowed in the first place?!
- nubinetwork 3y agoMaybe I'm just being a smooth brain, but wouldn't that mean I can't deposit a cheque by taking a picture of it anymore?
- aembleton 3y agoNot sure. You might still be able to access the camera, just not all of the photos on the device.
- pleb_nz 3y agoRecently wanted to know what day a particular date was, so on Samsung, I opened the first calendar app I could find. On opening it asked for location, I denied its request and the application shut down. WTF. I understand why a calendar might want location, but it did not need it to be used as a calendar. Such crap....