> Many major companies, like Air Canada, Hollister and Expedia, are recording every tap and swipe you make on their iPhone apps. In most cases you won’t even realize it. And they don’t need to ask for permission.
The key phrases here are "recording every tap and swipe" and "on their iPhone apps". I'm not saying it is okay, but the sensationalist headline takes away from the real issue.
I've been seeing the same sensationalist language even in "respected" publications like the NYT lately. For example, they recently published a story where it was implied that because Spotify's Messenger plugin has standard read/write permissions (necessary to ensure basic functionality like sharing songs) that it could also actively monitor, store, and modify your private messages.
In smaller publications, some shoddy reporting can often be attributed to a lack of experience or resources. It's hard to find an excuse for larger publications with well-established editorial resources, however. These stories are presented under the guise of public interest, but in reality they seem increasingly driven by politics and sinister ulterior motives. The end result is the spread of misinformation and further public distrust of the media and technology as a whole.
I doubt the sinister / political motives - these headlines and articles are nothing more than to drive traffic / revenue.
Pick a popular company / product / service, find something that they could be doing, throw up an article suggesting that's what they could be doing but have the title inferring that it is what they are actually doing. Rinse / repeat.
I'm not going to get into the subjectivity of what is or is not "sinister", but there's a more fundamental issue with the pattern you've described. Increasingly often today headlines are defacto articles. They get shared on various social media outlets and then people start discussing the title, filling in the body themselves. When the title is 'fake', it leads to mass disinformation. This gets even worse when the title and lead paragraph say one thing and it's only later in the article that the more nuanced reality is revealed. In that case you not only mislead the 'titlers' but also the skimmers.
I imagine readers on HN actually read articles at a vastly higher rate than e.g. Reddit or Facebook, yet on reading the comments it often becomes quickly apparent that many users, even here, do not bother reading articles before commenting on them. In an ideal world I wouldn't mind seeing misleading headlines put in the same bucket as false or misleading advertising. Of course in practice that'd be a terrible idea since this rule would simply be used for the powers that be to litigate against anything they don't like being published.
This is what happens under capitalism when private news organizations are disrupted by the Internet.
The solution is a collaborative news site, we don’t need intrepid reporters going into war zones when everyone can record video on their phone. We don’t need biased clickbait news providing fodder for soial network algorithms to herd us into echo chambers. We need a place where people of all viewpoints meet and duke it out like Wikipedia but for news.
There's a difference between the photos people take on a phone and the journalism that people like Tyler Hicks do. It's just not the same. Please show me a crowd sourced article that has this impact. https://www.nytimes.com/interactive/2018/10/20/world/middlee...
Wait, how is read/write permissions to messages (assuming that’s what you allude to) in any way necessary? On iOS at least, apps can’t even get access to your messages, and sharing works very well. I must misunderstand something.
No, they mean Facebook Messenger. The extension can be used for things like collaboratively creating a playlist with contacts in Messenger, sounds like that would require being able to read messages from Messenger and write messages to it.
I don't want this to devolve into an argument of semantics, but given NYT's editorial resources there's no doubt they carefully scrutinized how the "read" and "write" would be interpreted by their readership in the context of a negative report about Facebook.
"Many popular iPhone apps record what you do with them" would be perfectly accurate and less sensationalist.
I saw the title and thought "so the app is recording what's on the screen... which on a phone, is going to be itself... that's not such a big deal." As much as I don't like this sort of telemetry, it is in no way the sort of security issue the title appears to be insinuating.
How is that not a major privacy and security issue? A screen recording of your session would expose passwords in many cases as the characters show up one at a time before being masked.
When an app records itself it only has access to passwords that it already has access to. The issues are (1) these recordings go to a separate company, not the app developer and (2) developers (should) know to treat passwords as sensitive data but they didn't think to treat these recordings the same way.
If its doing actual screen recording (is this even possible) then it presumably can record the password you type into the Google Oauth screen that the app pops open.
“This gives Air Canada employees — and anyone else capable of accessing the screenshot database — to see unencrypted credit card and password information,” he told TechCrunch.
The takeaway is that some companies are capturing things that they shouldn't be storing, and the article has exposed atleast one instance where this information has been sent to a third party without masking.
--
As a side note, I've always been afraid to use payment options within apps that redirect to bank logins or payment gateways and this only feeds my fears.
Even if you're making the payment through a trusted bank or a payment provider, these apps still probably intercept and store the information you gave your bank.
I worked in this space and its definitly possible https://uxcam.com/ and https://appsee.com/ are other players in the space. They record the full screen by default. Much like fullstory for desktop.
A lot of companies and insurance in particular screen capture desktop applications as well.
This is so that should there be a dispute they have a screen shot of the forms presented and what details the customer provided. Payment screens would not be captured this way.
This. The only real issue is that the teams implementing this decided not to do a data security assessment and are violating PCI-DSS and similar by recording things that are supposed to be stored securely or not at all (ex. CCV).
Also, as I recall, banks legitimately "track" user interactions as a means of fraud detection.
The key phrases here are "recording every tap and swipe" and "on their iPhone apps". I'm not saying it is okay, but the sensationalist headline takes away from the real issue.