Slashdot Mirror


FTC Drops the Hammer On Maker of Location-Sharing Flashlight App

chicksdaddy writes "The Federal Trade Commission announced on Thursday that it settled with the maker of 'Brightest Flashlight Free,' a popular Android mobile application, over charges that the company used deceptive advertising to collect location and device information from Android owners. The FTC says the company failed to disclose wanton harvesting and sharing of customers' locations and mobile device identities with third parties. Brightest Flashlight Free, which allows Android owners to use their phone as a flashlight, is a top download from Google Play, the main Android marketplace. Statistics from the site indicate that it has been downloaded more than one million times with an overall rating of 4.8 out of 5 stars. The application, which is available for free, displays mobile advertisements on the devices it is installed on. However, the device also harvested a wide range of data from Android phones which was shared with advertisers, including what the FTC describes as 'precise geolocation along with persistent device identifiers.' As part of the settlement with the FTC, Goldenshores is ordered to change its advertisements and in-app disclosures to make explicit any collection of geolocation information, how it is or may be used, the reason for collecting location information and which third parties that data is shared with."

187 comments

  1. Location obviously needed by Imsdal · · Score: 5, Funny

    But if the app doesn't know your location, how would it possibly know where to provide the light?

    1. Re:Location obviously needed by Anonymous Coward · · Score: 0

      trash. you own how many cell fones? you think this app is the only thing against you? and that you
      wont fall prey to it? it aint alone. its the lowest common denominator attacking.

      what about the greatest? what about the corporate champions. you laugh but your owned.

    2. Re: Location obviously needed by iamhassi · · Score: 5, Insightful

      Have to wonder how many other apps are doing this that have not been caught yet

      --
      my karma will be here long after I'm gone
    3. Re:Location obviously needed by Anonymous Coward · · Score: 0

      Just because you don't have a cell phone and have disdain for those that do doesn't mean that you can't learn a bit of grammar and punctuation.

      Just sayin'...

    4. Re: Location obviously needed by Anonymous Coward · · Score: 1

      All of them...

    5. Re: Location obviously needed by Anonymous Coward · · Score: 2, Interesting

      Have to wonder how many other apps are doing this that have not been caught yet

      That's the big problem, the FTC is currently playing a losing game of whack-a-mole. The ultimate solution is to inform the developer community that there will be a three month grace period for them to come clean. After that start throwing offenders in prison until the problem goes away. Currently there are no enforced consequences, all the FTC was able to do is get Goldenshores Technologies, LLC, to agree to obey current laws on deceptive business practices and fraud. The scumbag owner is currently laughing all the way to the bank instead of sitting in a holding cell somewhere awaiting sentencing.

      Why isn't the FTC dismantling Goldenshores Technologies (and the personal assets of all the owners) for whatever they can get? I thought the whole idea of civil forfeiture was to deny criminal scumbags from profiting from their crimes.

    6. Re:Location obviously needed by Notabadguy · · Score: 2

      Droidlight has been around as long as Androids. Why is there need for competition in a free flashlight app?

    7. Re:Location obviously needed by Anonymous Coward · · Score: 0

      Because this one is BRIGHTER!

    8. Re: Location obviously needed by Mashiki · · Score: 1

      Have to wonder how many other apps are doing this that have not been caught yet

      A lot, and I mean a damned lot. Even most basic QR readers do it now.

      --
      Om, nomnomnom...
    9. Re: Location obviously needed by mattack2 · · Score: 1

      That's the big problem, the FTC is currently playing a losing game of whack-a-mole.

      You could make that argument about all crime.

    10. Re: Location obviously needed by reikae · · Score: 1

      Prison would be silly for something like this. I think a meaningful fine would be much more appropriate.

    11. Re: Location obviously needed by Anonymous Coward · · Score: 0

      Facebook, instagram, google...

    12. Re: Location obviously needed by blackraven14250 · · Score: 1

      The FTC doesn't have the authority to immediately shutter any business. They can ask that they stop and issue a fine, or bring them to court, but it's not their decision which businesses can remain open.

    13. Re:Location obviously needed by blackraven14250 · · Score: 1

      I don't know why the guys developing the UI (both Google and manufacturers) don't just add the damn button present in half the mods out there. That just kills these guys completely.

    14. Re:Location obviously needed by Anonymous Coward · · Score: 0

      We laugh at this, but out there, there are people, likely many people, who would believe this and argue it perfectly straight-faced.

  2. This app never seemed necessary by SternisheFan · · Score: 0

    Whenever I need quick light I just go to an all white screen on my phone. Why would you ever need an app for this?

    1. Re:This app never seemed necessary by oodaloop · · Score: 2

      It's for the LED flash next to the camera, which is much brighter than a white screen.

      --
      Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
    2. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      Most Android devices have an extremely bright white LED on the back of the device, which is used as a camera flash. It's typically much brighter than an all-white screen. Apps like this (and ROMs like CyanogenMod) provide an interface to turn this light on and off without having to enable the camera.

    3. Re:This app never seemed necessary by locopuyo · · Score: 2

      Doesn't your phone have a camera flash that can be used as a flashlight and works just as well? I think this has been standard for the past 5 years, and most phones have a flashlight app that comes on the phone.

    4. Re:This app never seemed necessary by rubycodez · · Score: 2

      ah, so that's why the display on the back side of my phone left me seeing red

    5. Re:This app never seemed necessary by SternisheFan · · Score: 1

      Doesn't your phone have a camera flash that can be used as a flashlight and works just as well? I think this has been standard for the past 5 years, and most phones have a flashlight app that comes on the phone.

      I'm still on an older Virgin Mobile economy froyo phone (Optimus V), no flash. It's tough as hell, still works after many drops to concrete and one fall into a creek. I figure why upgrade while this one is still working fine. It gets the internet when I need to googlemap something, functions as an mp3 player, and the phone's mike/speaker still function.

      Well, that said, I guess I gotta' go shave my neck now...

    6. Re:This app never seemed necessary by safetyinnumbers · · Score: 4, Insightful

      I just hold down the lock switch for a second to turn on the LED, it's a built-in feature on my Nokia.

      But why doesn't Android sandbox apps in a way that the app is unaware of? Just present all apps with an empty contact list, a fake GPS location, an empty drive, etc and the user grants permissions to substitute the real ones as needed. That way, all apps could be installed and you'd get a popup such as "this app wants your location" in a similar way to IOS, only this way the app would keep working if you said no.

    7. Re:This app never seemed necessary by Archangel+Michael · · Score: 2

      Indeed, why do you need an APP for this. My ROM (CM 10.2) has a "torch" function built in. Why would you need an app for it?

      This is not an Android problem this is a problem with crappy carrier priorities. Must bundle crap nobody wants, and not include the obvious highly requested features.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    8. Re:This app never seemed necessary by NoNonAlphaCharsHere · · Score: 5, Insightful

      Apparently you're completely unaware of Google's business model.

    9. Re:This app never seemed necessary by mlts · · Score: 2

      There used to be a utility called LBE Privacy Guard which did exactly this in earlier versions of Android, and on jailbroken iPhones, a utility called PMP (protect my privacy.) If the app wants contacts, it gets randomly generated cards. Songs, similar. Location, it gets where you select. Photos? Fake photos or an empty drive, ad id? Randomly generated.

      Only thing is that LBE Privacy Guard has not been updated for the past few versions of Android.

      Pretty much, one's best defense against a rogue fleshlight app is to have a firewall program like Droidwall or its successors and block the app from communicating on any interface.

    10. Re:This app never seemed necessary by Solozerk · · Score: 3, Insightful

      The "built-in" torch function you're talking about in CM is an app. It's open source - see here: https://github.com/CyanogenMod/android_packages_apps_Torch .

      You make it an app because it makes no sense to integrate such a feature directly in the OS/ROM - it would take longer, and that way you can update it and have additional features (morse code flashing, for example).

      What baffles me is why people would install an app named "Brightest Flashlight Free" (name sounds like a moron-magnet), which probably require network access and include ads, when there are tens of ads-less Open-Source alternatives in the Google market as well as outside it.

    11. Re:This app never seemed necessary by Anonymous Coward · · Score: 1

      There are a couple of kids on your lawn too.

    12. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      What baffles me is why people would install an app named "Brightest Flashlight Free" (name sounds like a moron-magnet), which probably require network access and include ads, when there are tens of ads-less Open-Source alternatives in the Google market as well as outside it.

      It's always at the top of the list in the freeapps category, so people assume it's fine to download.

    13. Re:This app never seemed necessary by Politburo · · Score: 3, Funny

      Rogue fleshlight? I don't wanna know where that thing has been...

    14. Re: This app never seemed necessary by iamhassi · · Score: 2, Informative

      iPhone doesn't need it since every app has to be approved by Apple themselves before hitting the appstore and iOS doesn't allow access to contacts or locations without a large popup saying "do you want this app to access (blank)?" Which you can turn off anytime in settings. There are some advantages to a walled garden

      --
      my karma will be here long after I'm gone
    15. Re:This app never seemed necessary by Archangel+Michael · · Score: 1

      There is a way to "self censor" the app, which is to download it, mark it 1 star and give a crappy review. Enough people do that, and the app fades into obscurity. Crappy apps should be named and shamed this way.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    16. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      [...]oglemap [...]

      I've just use Facecrook for everything. Better than Ogle, Ding, or Yeahwho? for my privacy-disposal needs, or so I thought... Does Oglemap have better tracking cookies, web bugs, or NSA-tapped links or something?

    17. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      Except individual apps on i OS don't need to require GPS. APL does that for them already as of their i Ads platform (so ~2-3 years ago), and for "some reason", gets away with it.

      Maybe Obama will just handwave their issues away too.

      At least this Flashlight app, at install time, specifically stated it wanted "Your Location" in just one page. Any i User has to read through 40 pages of EULA to find their warning.

    18. Re: This app never seemed necessary by Anonymous Coward · · Score: 0

      http:// oo . apple . com

      They rape your location already, so no need for individual apps to do so.

    19. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      LBE has been updated quite a bit... here is a version that attempts English translations:

      http://forum.xda-developers.com/showthread.php?t=1422479

      Also, you can use Xposed Framework with xPrivacy... this is a more lightweight application, but I have had issues in apps knowing they are being locked down and refusing to run...

      http://forum.xda-developers.com/showthread.php?t=1574401

      http://forum.xda-developers.com/showthread.php?t=2320783

    20. Re:This app never seemed necessary by thegarbz · · Score: 1

      Not just Google's.

      The entire free app ecosystem depends on the sharing of information. If the information is fake the value of it goes down. Bye bye free app.

      Somehow I don't have too much of a problem with sharing a bit of info in exchange for something useful.

    21. Re:This app never seemed necessary by thegarbz · · Score: 1

      What baffles me is why people would install an app named "Brightest Flashlight Free" (name sounds like a moron-magnet)

      Because the open source ones aren't as bright. dur.

    22. Re:This app never seemed necessary by Sparton · · Score: 1

      There is a way to "self censor" the app, which is to download it, mark it 1 star and give a crappy review. Enough people do that, and the app fades into obscurity.

      Depending on how the store works, downloading to crappy rate it may just boost it's popularity, which gives it more visibility, not less.

      At least, that's how it works on the Apple App Store (which I believe has popularity which uses downloads/time, and grossing which uses revenue/time). Not sure if Android's equivalents use that or just have lists that are just based of ranking alone.

    23. Re:This app never seemed necessary by ultranova · · Score: 1

      But why doesn't Android sandbox apps in a way that the app is unaware of? Just present all apps with an empty contact list, a fake GPS location, an empty drive, etc and the user grants permissions to substitute the real ones as needed.

      Same reason your PC doesn't: developers and users have a natural conflict of interests, and developers have the control.

      --

      Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

    24. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      What baffles me is why people would install an app named "Brightest Flashlight Free" (name sounds like a moron-magnet)

      You've answered your own question.

    25. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      I love how you types get modded up as if anything you're saying is much more than spreading blatantly false information.

      I'm a developer who writes free "apps". The developers who think that their
      website, program, or whatever is a privilege and deserves to advert /or track the hell
      out of people for viewing it are the real ignorant ones. Add a donation link,
      if you don't like that route then remove your website or program from the
      internet while users find a better alternative not written by arrogant
      people. I prefer you didn't use stupid generalizations and say that all
      free programs earn money by tracking/ads. The programs written by
      shortsighted people are like that, perhaps.

      Your website or program is not an awesome epitome of software. It's a tool that
      people may or may not use depending on their whims. If you don't want people
      using your stuff for free, don't make it free in the first place. The internet
      was fine before idiots thinking that ads and tracking are the only thing that makes the
      internet run started piping up, and it will continue to be fine once everyone
      blocks them.

    26. Re:This app never seemed necessary by alostpacket · · Score: 1

      Google tends to keep the algorithm secret for apps showing as "top" but I'm pretty sure one of the things they look at is how quickly people uninstall. User retention is (supposedly) a heavily weighted metric.

      --
      PocketPermissions Android Permission Guide
    27. Re: This app never seemed necessary by Anonymous Coward · · Score: 0

      What app do u make?(desperately seeking non-evil android apps)

    28. Re:This app never seemed necessary by phantomfive · · Score: 1

      "Brightest Flashlight Free" (name sounds like a moron-magnet)

      That's why. My brother was building a website for a (legitimate) investment company, and the owner said to him, "it looks to good. Make it look more scammy." The owner said that because a scammy-looking website gets more customers.

      The world is such a depressing place.

      --
      "First they came for the slanderers and i said nothing."
    29. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      What you describe is essentially a hidden feature in the last two versions of android called App Ops. It seems likely that the reason the feature is hidden is because Google feels it is incomplete; It is likely this option will be exposed to the user in the next version.

    30. Re:This app never seemed necessary by JThundley · · Score: 1

      Cyanogenmod has this feature, it's called Privacy Guard. It states: "When Privacy Guard is enabled, the app will not be able to access personal data such as contacts, messages or call logs."

    31. Re:This app never seemed necessary by Anonymous Coward · · Score: 0

      If it wasn't then scammers wouldn't exist. Cause is effect.

  3. Re:As a user by Anonymous Coward · · Score: 0

    slip thier meant to say Users

  4. Well now... by Anonymous Coward · · Score: 0, Offtopic

    The government has a lot of balls pointing fingers like that...

    1. Re:Well now... by Krojack · · Score: 1

      DO AS WE SAY NOT AS WE DO!

    2. Re:Well now... by Anonymous Coward · · Score: 0

      The government has a lot of balls pointing fingers like that...

      Governments can't stand competition...

      capcha: vassal :-/

    3. Re:Well now... by minstrelmike · · Score: 1

      The government has a lot of balls pointing fingers like that...

      I don't believe it is fingers that they are pointing.

    4. Re:Well now... by Anonymous Coward · · Score: 0, Offtopic

      It seems that you have a problem understanding aristocracy. The government is the new aristocracy. We The People have let it happen by becoming big party shills. The last two administration have done everything short of opening concentration camps for undesirables and still we fuss more of Miley Cyrus and Paul Walker than we do over what our overlords have become.
       
      Give it about two more administrations... the powers that be will have us paying at least 50% more in tribute, health insurance will be government run which will make it more costly and less effective and the citizens will have access to nothing more powerful than a child slingshot while the police and military will become one and the same... and they'll have all kinds of nifty toys to beat you down with if you don't comply with their demands, lawful or not.
       
      Orwell couldn't have imagined something as totalitarian was what we'll be the victims of in the next two decades.

  5. Re: As a user by Anonymous Coward · · Score: 1

    Four keywords: cyanogenmod with p-droid patch

  6. Security model by Anonymous Coward · · Score: 3, Interesting

    If someone still says that Android's (or IOS I suppose) security model isn't completely broken...

    Why can't the user choose to disable networking on a per-app level?

    1. Re:Security model by MachineShedFred · · Score: 4, Informative

      On iOS, you do have granular permissions - if an app requests your location, you can say no, and the app can go fuck itself - the API doesn't give it shit. It's not all-or-nothing.

      Disabling data access per app is a different story though, so your point still stands.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    2. Re:Security model by Anonymous Coward · · Score: 1

      If someone still says that Android's (or IOS I suppose) security model isn't completely broken...

      Why can't the user choose to disable networking on a per-app level?

      Because this is Android, from Google. A company designed from the ground up to monetize your private and personal data.

      Don't settle for being merely evil.

    3. Re:Security model by Anonymous Coward · · Score: 1

      The security model is such that the app needed to request permissions from the user to read the location data and to access the network.

      If the user installs a freaking flashlight app, and then is prompted, "hey, do you want this app to access the network and read your location data?" and the user responds "sounds good to me!", well, what the hell are you supposed to do about that? Can't save them from themselves, unless you go full-on down the Apple "padded room" approach. (Or was that "walled garden"? Same diff.)

    4. Re:Security model by Concerned+Onlooker · · Score: 2

      "Disabling data access per app is a different story though, so your point still stands."

      On iOS 7 you can do this, but only if you're not using wifi. In the prefs you can turn off cellular data access on a per app basis. You can also see how much of your cellular data plan each app is eating.

      --
      http://www.rootstrikers.org/
    5. Re:Security model by Anonymous Coward · · Score: 0

      Android 4.3 and 4.4 have granular permissions. App Ops, which is just a tiny download from the play store.

      Furthermore, there are perfectly good non-permissions-needing flashlights on Play, like TeslaLED.

    6. Re:Security model by Anonymous Coward · · Score: 0

      Sure. I know how it works. But if the user could decide at run-time, the user would actually be able to use the flashlight app AND not send anything to the idiots who wrote that app. Get it? That's why I said the security model of the OS is broken. It enables developers to tricking users into installing apps that steal information from the users. Which is completely shitty. I'm using a firewall which lets me do this anyway, but it doesn't make the security model less shitty.

    7. Re:Security model by Anonymous Coward · · Score: 0

      I heard iOS also has clearable cookies instead of "persistent device identifiers", but I suspect that's at least partly BS. The greed for an evercookie is too strong to resist, and the users are not detail-oriented enough human beings. Hell, I don't even know wtf is going on myself.

    8. Re:Security model by Anonymous Coward · · Score: 0

      App Ops (hidden unfinished feature in Android 4.x, you can see the parts that work with a free Play Store app that opens it up) lets you selectively deny permissions for each app you have this way too. To make this not crash the application the OS has to fake it so that the app won't know there's a problem.

      As of 4.4 you can disable:

      Location: Fakes not knowing where you are
      Contacts, Clipboard, Calendar: Pretends you have no contacts, nothing in calendar, nothing on clipboard
      Vibrate: Pretends to vibrate but doesn't
      Notification: The notification isn't displayed to the user, doesn't make a "new notification" sound, doesn't light the LED etc.
      Keep Awake: Falls asleep as usual anyway, as if user pressed the button
      Send SMS, Make Call: Pretends there is no cell service
      Receive SMS; Pretends you never receive an SMS
      Record Audio: Pretends there is no microphone? Or maybe just sends silence?
      Camera: Pretends there is no camera? Or maybe black rectangles
      Modfying Settings: Ignores new settings

      If you care about this sort of thing and can handle knowing that if you switch stuff off it might make certain apps not do what you expected, then go get App Ops.

    9. Re:Security model by Anonymous Coward · · Score: 0

      WRONG!!!!!!
       
      There's an app that makes it look like permissions are working that aren't really giving real data/permissions. It's not part of Android at all.
       
      Keep kissing Google butt. We know the difference.

    10. Re:Security model by Anonymous Coward · · Score: 0

      Disabling data access per app is a different story though, so your point still stands.

      Oddly enough, RIM figured out how to do this on blackberry about a decade ago.

      Detailed, granular permissions, so that an app can connect to ip address 1.2.3.4 on port 443, but can't connect to ip address 5.6.7.8 on port 80.

      I love my old blackberry, but sadly no one seems to care about privacy.

      Especially as people put their entire life on their phone, and both apple & google hand over all their data to the US government. Doesn't seem to slow sales at all.

    11. Re:Security model by DMUTPeregrine · · Score: 1

      For Android, AFWall+ is a good frontend for iptables, and makes it easy to create per-app rules. It includes its own iptables and busybox binaries if your rom doesn't have them.

      --
      Not a sentence!
    12. Re:Security model by alostpacket · · Score: 1
      --
      PocketPermissions Android Permission Guide
  7. Permissions? by Anonymous Coward · · Score: 2, Insightful

    Who gives a flashlight app permissions to access location, internet, flash drive, etc?

    1. Re:Permissions? by Anonymous Coward · · Score: 1

      Most do. Most people I know, that are running Android, grant access to everything that pops up. They don't read and don't understand it if they do.

    2. Re:Permissions? by ausekilis · · Score: 1

      Who gives a flashlight app permissions to access location, internet, flash drive, etc?

      Only some rooted android phones (or custom ROMs) allow fine-grained access to allow/deny explicit permissions for applications. Every 'droid I've had with T-Mobile and AT&T has not allowed such control by default. Only a select few actually look at the requested permissions before agreeing to install an app, even worse, the android permissions are incredibly vague. "Phone State" means idle/sleep/calling/etc..., but the wording sounds like any app can make calls on your behalf.

    3. Re:Permissions? by the_skywise · · Score: 1

      And one of these days, Apple is going to make use of the HumancentiPad clause in the iTunes agreement pop up!

    4. Re:Permissions? by minstrelmike · · Score: 1

      Who gives a flashlight app permissions to access location, internet, flash drive, etc?

      users who have finally seen the light, that's who.

    5. Re:Permissions? by Anonymous Coward · · Score: 1

      Yes, and everything is getting worse. I've stopped updating the google apps (gapps) because they keep trying to expand their permissions too, and I feel that I need to make a stand on principles. And if I cannot get an alternate firmware soon that really allows me to control permissions, I may have to abandon the gapps entirely. There is no reason that google maps should have access to my contacts, SMS history, phone calling, etc.

      We have a fundamental problem that the company defining the platform thinks that ads and customer tracking are sacrosanct. We have a worse problem that they are trying to water down the open part of their platform to force everyone to use their own apps and components on top, to further this agenda now that they have had wide adoption.

      I want an open-sourced platform and apps that serves my needs, not those of any rent-seeking company. I want my mobile browser to have the same security and privacy options as my desktop: privoxy, noscript, and requestpolicy to allow me to control what my computer does, not some sociopath who thinks he has a right to put ads in my face or track my every moment. Privacy controls should be stronger on a platform we carry around everywhere, not weaker!

    6. Re:Permissions? by Ralph+Wiggam · · Score: 1

      Only some rooted android phones (or custom ROMs) allow fine-grained access to allow/deny explicit permissions for applications

      Not true. Stock Android 4.3 has that functionality. It's just buried under a lot of menu choices.

    7. Re:Permissions? by ColdWetDog · · Score: 1

      Who gives a flashlight app permissions to access location, internet, flash drive, etc?

      users who have finally seen the light, that's who.

      No, it would appear to be users who are left in the dark.

      --
      Faster! Faster! Faster would be better!
    8. Re:Permissions? by Anonymous Coward · · Score: 0

      You may not be able to allow/deny permissions for apps you've already installed but when you install them you always get a warning about what they are. Or at least I do, and I'm running Android 2.2 on my phone.

    9. Re:Permissions? by Anonymous Coward · · Score: 0

      Which is why we clearly need some new government regulations requiring that the lists of required permissions be written in English, not some made up language that no one could possibly understand.

  8. Re:As a user by Krojack · · Score: 1

    When you installed it, didn't you look at the list of what it has access to? If I saw it wanting to get my location I would have stopped right there and not installed it. No flashlight app needs to know my location to work.

  9. Re:As a user by MachineShedFred · · Score: 3, Insightful

    I think at this point, the default mode for most Android users is to just allow, as most apps have a laundry list of things they want access to. It's probably the second-least read message from an app install of all time (first being the EULA).

    No, that is not wise. But people aren't always wise.

    --
    Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
  10. Some Hammer by TubeSteak · · Score: 5, Insightful

    No civil fines.
    No criminal penalties.
    No admission of guilt.

    --
    [Fuck Beta]
    o0t!
    1. Re:Some Hammer by denis-The-menace · · Score: 1, Informative

      That's because they are a corporation.

      A corporation under US law is a "Person" that is superior to humans and thus cannot be faulted for anything.

      --
      Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
    2. Re:Some Hammer by Anonymous Coward · · Score: 0

      almost the same results of blackstone's laundering/insurance fraud. They should face crippling fines...

    3. Re:Some Hammer by NoNonAlphaCharsHere · · Score: 1

      Who do they think they are? CitiBank? Goldman Sachs?

    4. Re:Some Hammer by Remus+Shepherd · · Score: 1

      Nerf hammers *are* technically hammers.

      --
      Genocide Man -- Life is funny. Death is funnier. Mass murder can be hilarious.
    5. Re:Some Hammer by tippe · · Score: 1

      Yes, I've seen this type of hammer before. My son has one. It's a big blue inflatable thing that goes "Squeek!" when you hit stuff with it. The FTC must obviously have one much like it. Maybe they got theirs from a country fair as well...

    6. Re:Some Hammer by ohnocitizen · · Score: 1

      What can we do? Pressure the FCC to take stronger action. Pressure our representatives to give the FCC more power to take stronger action in situations like this. Create a public database of companies and apps that are known to spy on users, and attack their bottom line.

    7. Re:Some Hammer by Holi · · Score: 1

      That's because judges are only human, and who are they to question the motives of a Corporation.

      --
      Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
    8. Re:Some Hammer by Anonymous Coward · · Score: 0

      Just remember: as far as freedoms for the corporation go, the corporation is a "person." As far as punishments or morality goes, it's "a corporation, not a human being."

  11. Don't be Naive by A10Mechanic · · Score: 5, Insightful

    This is just the tip of the dirty iceberg here. Thousands of apps do this and far worse for your privacy. Caveat Emptor

    1. Re:Don't be Naive by Anonymous Coward · · Score: 1

      I actually was looking for a flashlight app a few months ago. I went down the list on the flashlight apps, and I had to get to about the fifth one before I found one that didn't need some really questionable permissions (like reading contacts, GPS data, etc.). IMO this is a widespread issue.

      I was actually going to install Pandora the other day, but I read the TOS to try to understand the permissions it required, and I just couldn't agree to it.

      It's a pain, but the average user needs to start actually paying attention to app permissions.

    2. Re:Don't be Naive by Anonymous Coward · · Score: 0

      Because it's brilliant! The app does nothing but print money. Mobile ad frameworks for everybody!

    3. Re:Don't be Naive by Anonymous Coward · · Score: 0

      What do you expect? I mean really? Break your POTS and cell phone as you cut HD cable and the Internet, live under a bridge so mail lists lose you, cut up your debit card, never show ID, never scan anything out of your pocket (in fact, burn everything in your pocket!), ditch driver's license and vehicle, wear a ball cap and sunglasses with a muffler around your neck and elevator shoes when outdoors (even in a remote forest) or in any public places. And always wear those CSI gloves to keep your fingerints off and germs away.

      Do not interact or associate with anyone who does, or does not, any of these things. And more! OK, you're safe.

      It's a brave new world. But, really, you expected something else? Stay out of popular movements for the overthrow of your local government and you will probably just be a little miffed at what your data shadow does, but feel convenienced when the new, small, local Azerbaijanian restaurant sends you, the only Azerbaijanian on your block, its location digitally instead of using mass mailing because the new restaurateur's wife hates killing trees.

      You paid a pittance for your digital leashes and 'Net and roadster and all the other baubles of the octopus; so the manufacturers and service providers monetize that, and you wonder at what it can do. And what Google will give you or iPhone sell to you?

      20% of us are schizophrenics finding insidious plots where, just maybe, there are none. Watch what you read and how that makes you react; see if you are one of them.

  12. Marketing by Anonymous Coward · · Score: 0

    Hi, I'm an Silicone Valley entrepreneur. We use that data for this innovative app we have.

    See, by getting your location, browsing and every other piece of personal information we can possibly get from you device, we can then push to your device information that you would be interested in. Of course, (1)some of this information would be products that you may be interested in buying from our partnered (2)certified suppliers.

    And we absolutely will NOT share your information without your permission(3).

    ...

    1 . By "some" we mean all.

    2. certification - they pay us and we pimp your data.

    3. By using our app, you opt-in and there's no way to turn it off and we sell it to anyone who forks over the cash.

    -Yours, your typical Silicone valley Lamoe company.

  13. firefox by Anonymous Coward · · Score: 1

    I switched to a FireFox phone.

  14. Why can't they copy this from iOS? by dingleberrie · · Score: 5, Insightful

    I have an iPhone 5 and a Nexus 7.
    When I download an app on the Nexus, I always feel an uneasiness as I look at all the access it wants to my contacts and other invasively unnecessary permissions. So each time I must make a decision to accept or reject using the app. I've rejected some that just seem overreaching, but I've become less strict over time... like I'm accepting to lose a battle. I assure myself, that my phone has all my real contacts, not my Nexus 7 and then begrudgingly accept the conditions. This is one reason I will not use an android phone and why I rarely download apps on android.
    http://yro.slashdot.org/story/13/12/06/1452241/ftc-drops-the-hammer-on-maker-of-location-sharing-flashlight-app#
    iOS, for those that don't know, will let me decline permissions to track my location or share my contacts on a per-app basis. Even if I enabled it before, I can go into the control center and disable it. I don't benefit from that aspect of the iOS app, but I'm fine with that. For all the control that Android is supposed to give the user, iOS shines here and I wish that is one thing that Android would copy.

    1. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 1

      But iphones don't have flash, so they cant even run a flashlight app. But seriously, go to your menu drop-down and push the button that says "Torch Off" and it will change to "Torch" and then you wont need this app.

    2. Re:Why can't they copy this from iOS? by wbo · · Score: 2

      Newer iPhones (and i think a few other iOS devices) do have a flash and in fact a flashlight toggle is built into the lock screen on devices running iOS 7 or later.

    3. Re:Why can't they copy this from iOS? by SirGarlon · · Score: 0

      I think Samsung showed us that copying features from Apple products is bad for business. Fine-grained app privileges seem obvious (and hence unpatentable), but when the courts are upholding and enforcing patents on something as stupid as rounded corners, it's better to be safe than sorry.

      --
      [Sir Garlon] is the marvellest knight that is now living, for he destroyeth many good knights, for he goeth invisible.
    4. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 4, Informative

      Oh you have a Nexus 7? Perfect, you can download App Ops to select permissions on a per-app basis.

      Any Android 4.3 or higher device supports it. And root is not required.

    5. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 1

      All new iPhones have had flashes for over 3 years. troll harder.

    6. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 0

      "I wish that is one thing that Android would copy."

      I hear lawyers sharpening their knives from afar...

    7. Re:Why can't they copy this from iOS? by immaterial · · Score: 1

      Whoosh. I guess his joke flashed by too quickly...

    8. Re:Why can't they copy this from iOS? by ADRA · · Score: 1

      1. Don't download apps that use permissions you wouldn't give them
      2. If you're using Android 4.3/4.4, look for 'App Ops' (The one that requires zero permissions) from the play store. It allows you to turn specific (though not all alas) permissions off per app: Notably SMS, reading contacts, keeping the phone on, polling your location, call log/making calls/clipboard/audio focus/camera/record audio/modifying system settings...

      The benefit of Android's App Ops is that it also tells you when the app last used a given permission, which really tells you when some program has been exploiting your good will... Just remember though:

      Whenever you have ads in an app, always expect
      INTERNET_FULL
      LOCATION_COURSE
      and maybe LOCATION_FINE
      Pretty much all ad platform tools require them to function

      --
      Bye!
    9. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 0

      You ignorant little faggot. Did you see the word "a" before the word "flash"? Fag. He was making a joke. Referencing Adobe Flash. What a nerdfag.

    10. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 0

      I think Samsung showed us that copying features from Apple products is bad for business.

      It's not Samsung, it's Google. Remember Android is DESIGNED from the ground up to leak personal information, that's how Google gets their money from Android.

    11. Re:Why can't they copy this from iOS? by mattack2 · · Score: 1

      You apparently don't understand what a *design* patent is.

    12. Re:Why can't they copy this from iOS? by Anonymous Coward · · Score: 0

      Double whoosh

    13. Re:Why can't they copy this from iOS? by Obfuscant · · Score: 1

      2. If you're using Android 4.3/4.4, look for 'App Ops'

      Citation required. I did a google for "App Ops" and there are at least four different apps on the Play store called "App Ops", and two also-rans called "Permission Manager".

    14. Re:Why can't they copy this from iOS? by blackraven14250 · · Score: 1

      I found 3 of the ones called App Ops, and they're all the same as far as I can tell - they open a hidden panel baked in to Android, except one allows you to search apps by name. I can't see the permissions, though, as I'm on the website, so that may be a substantial difference.

    15. Re:Why can't they copy this from iOS? by ADRA · · Score: 1

      I used this one btw: https://play.google.com/store/apps/details?id=fr.slvn.appops

      And I have verified that disabling a permission changes the behaviour of the apps (PvZ2 normally diables outside sound, but this change overrides that, so you can still listen to music while playing for example).

      --
      Bye!
  15. Re:As a user by Anonymous Coward · · Score: 0

    1) Uninstall this app
    2) Install F-Droid. Use that as your go-to source for apps.
    3) Use a spyware-free flashlight app from there.

  16. So No One Thought It Odd by Greyfox · · Score: 5, Interesting
    Their flashlight app was requesting network and GPS privs? There's obviously a fundamental problem with the Android security model, and I'm just going to go ahead and point my finger at people. First off, people assume that just because it's on the Play store, it's safe to install. Obviously not the case. Second, people obviously don't review the privs their apps request and say something like "Why the fuck does a flashlight app need access to my GPS and network?" And third, lazy developers have no incentive not to request every priv in the model.

    I'd heard Cyanogenmod was experimenting with a means to deny specific privs to an application rather than take the all-or-nothing approach of "You have to give me all this shit or you can't install it." That's a feature I'd really like to have for my Android phone.

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

    1. Re:So No One Thought It Odd by Mr_Silver · · Score: 4, Insightful

      Their flashlight app was requesting network and GPS privs? There's obviously a fundamental problem with the Android security model, and I'm just going to go ahead and point my finger at people. First off, people assume that just because it's on the Play store, it's safe to install. Obviously not the case. Second, people obviously don't review the privs their apps request and say something like "Why the fuck does a flashlight app need access to my GPS and network?" And third, lazy developers have no incentive not to request every priv in the model.

      Not to mention that although for a very basic app (like a flashlight one) it is possible to spot a nefarious permission, once you start looking a much more feature-rich app then it gets very difficult for users to work out the validity of the permission requested.

      For example, a mobile banking app wants your location. Is this because:

      1. It's sending location data to a server to track you?
      2. It's sending it to third party companies for location based advertising?
      3. It wants that information so it can tell you where the nearest ATM or bank branch is?
      --
      Avantslash - View Slashdot cleanly on your mobile phone.
    2. Re:So No One Thought It Odd by cdrudge · · Score: 1

      Second, people obviously don't review the privs their apps request and say something like "Why the fuck does a flashlight app need access to my GPS and network?"

      How is the user to differentiate legitimate vs illegitimate use of GPS and network access?

      For instance, a restaurant review application wants GPS info to tell you what restaurants are near by, and needs network access to load data. Perfectly legitimate needs for those permissions and without those permissions being granted, the app is pretty useless. But there's nothing stopping the app from also transmitting your location back to someone for some other purpose.

      For another example: I play a variety of free games on my phone and tablet. I acknowledge that they are free in exchange for showing me ads. I'm accepting of the ads as a condition for being able to play for free. I'd like for the ads be relevant and/or localized. So I don't have a problem sharing GPS info across the network if it means that the ads might actually be for something that I might click on once in a while. So again, while you may question why the app needs GPS and network permission, there can be a legitimate reason for it.

      Now in the case of a "flashlight app" that took all of 5 minutes to write if they had no mobile development experience, and requires no continuing support, asking "Why the fuck does a flashlight app need that access" is a legitimate question and the only legitimate answer is because the author wants to whore out your information to make money.

    3. Re:So No One Thought It Odd by Sockatume · · Score: 1

      Unfortunately app permissions on Android are currently "all-or-nothing" and, worse, they're requested all at once at installation, so users are conditioned to just click through it and make the app work. (See also: Windows UAC prompts.) It's a design issue, not a user intelligence issue.

      --
      No kidding!!! What do you say at this point?
    4. Re:So No One Thought It Odd by Anonymous Coward · · Score: 0

      The reason why it would need network and location is for delivering ads.

      This is the fundamental problem with "free" apps - they try to monetize the customer (via ad delivery). This in turn requires that the app have at least network access (to go get the ads). Most apps delivering ads now also want to deliver ads that are relevant to one's location, hence the need for location access.

      And now the genie is out of the bottle, because once you grant network access, the app can do *anything* over the network. There is no way to say "only use the network for getting ads". There is no way to say "don't transmit my location to anyone else".

      The only solution, from a user perspective, is to have an access control mechanism that provides fake responses on the various APIs when the user denies the app access. Location services would always return "Larry Page's House" as the current location, for example. While this would allow users to protect their privacy from overly aggressive apps, it will never happen because it allows users to protect themselves from overly aggressive apps. Those apps drive ad revenue and information harvesting, both of which are in Google's interest, so Android will never allow users to do this.

    5. Re:So No One Thought It Odd by Anonymous Coward · · Score: 0

      Actually, there is one more alternative - don't use "free" apps.

      It takes work on the part of a developer to create those apps. They need to be paid for that work. So stop being cheap and actually *pay* for the apps. Then the developer won't have to try to secretly monetize you via ad delivery and you turn off all the downstream problems that arise from that.

      In fact, many apps have a "free" and a "paid" version of their apps - with the "paid" version removing all the ads-related activity.

      But, of course, most people are too cheap to actually pay for services/products because they cannot do the basic math, so this won't really work either.

    6. Re:So No One Thought It Odd by Anonymous Coward · · Score: 0

      Actually, there is one more alternative - don't use "free" apps.

      I got my first Android phone last month, and so far I'm ignoring Google Play. I don't even have a gmail account.
      I'm happy with the apps I get from F-Droid and Google Code.
      All free software, and nothing weird going on.

    7. Re:So No One Thought It Odd by jonbryce · · Score: 1

      The restaurant app needs to phone home with the location data in order to get the list of nearby restaurants. Once it is on their server, what they do with it is outwith your control, but restaurants will probably pay a referral based commission so they will need to have details of where people use their apps for that purpose.

    8. Re:So No One Thought It Odd by tlhIngan · · Score: 1

      Their flashlight app was requesting network and GPS privs? There's obviously a fundamental problem with the Android security model, and I'm just going to go ahead and point my finger at people. First off, people assume that just because it's on the Play store, it's safe to install. Obviously not the case. Second, people obviously don't review the privs their apps request and say something like "Why the fuck does a flashlight app need access to my GPS and network?"

      The problem with the Android permissions model is it gives power to the technical, while ignoring the typical.

      The thing is, the Dancing Pigs (or rabbits) phenomena is real, and users who get recommended to try an app will want to try it. You can pop up a dozen dialog boxes saying it's bad, but the user will dutifully close them just to run the app.

      Relying on the user to secure themselves has proven to be ineffectual, and it's shown itself repeatedly. Even on iOS - you can get a user to do some pretty amazing things if you walk them through the steps and the outcome is something they want. (It's how various worms that relied on jailbreaks spread - users installed OpenSSH, dutifully installed SSH clients, and failed to change the default password).

      Hell, you probably can harvest a ton of passwords to Google, Facebook, Twitter and others if you set up a site that offers "free porn!" and lets them use those sites to "log into" your site (where you're capturing the usernames and passwords, of course).

    9. Re:So No One Thought It Odd by Anonymous Coward · · Score: 0

      TBH, if the person doesn't care to look out for their own privacy, they probably don't care. It's just us techies that get our panties in a wad.

      If those particular users want to help fund a particular company by selling some of their privacy, who are we to say no?

    10. Re:So No One Thought It Odd by Anonymous Coward · · Score: 0

      Yes. And the solution is Firefox's invalid SSL certificate exception model... Oh wait..

    11. Re:So No One Thought It Odd by k0nane · · Score: 1

      Not experimenting with, implemented. Privacy Guard 2.0 in CM10.2 and up lets you get extraordinarily granular with permissions, beyond just location and ability to read contacts/SMS/phone state/etc. You can opt to have Privacy Guard on by default for all apps, which I have - it will then log all attempts to use sensitive operations.

  17. How dare they! by Opportunist · · Score: 1

    Only the NSA may track every phone on the planet!

    But in their defense, you at least got a free flashlight out of it and your tax money didn't have to pay for it, so...

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  18. Devil's Advocate.. by Anonymous Coward · · Score: 0

    Even if application permissions were granted individually and even if application developers wrote their code in such a way that the application would behave as normally as possible without them, what's there to stop them from sabotaging the application in another manner until it's granted the permission they want? For example, let's say an application requests location access, and until it's granted, it simply "decides" not to work. Another example, one that cannot be simulated, is network access. Rinse, wash, repeat.

    1. Re:Devil's Advocate.. by Sockatume · · Score: 1

      They'd fail the technical requirements checklist and never be allowed on the store.

      --
      No kidding!!! What do you say at this point?
    2. Re:Devil's Advocate.. by hawguy · · Score: 1

      Even if application permissions were granted individually and even if application developers wrote their code in such a way that the application would behave as normally as possible without them, what's there to stop them from sabotaging the application in another manner until it's granted the permission they want? For example, let's say an application requests location access, and until it's granted, it simply "decides" not to work. Another example, one that cannot be simulated, is network access. Rinse, wash, repeat.

      Thats exactly how things should work -- if the app author doesn't want to let the app run without whatever permissions he deems as neccessary, then he should just have the app refuse to run without the permission.

      Then the user can decide if he wants the app enough to let it have whatever permission it wants.

      If I install a flashlight app that wants network access and it refuses to work if I deny that access, then I would uninstall the app and give it a bad review.

    3. Re:Devil's Advocate.. by AK+Marc · · Score: 1

      The user should be able to set the "location" to an arbitrary city, and get a location fed to the app the equivalent to driving around in circles. Network access should be provided through a proxy, with all requests and responses scanned and filtered/blocked as the user sees fit. Contact list will get a blank or dummy sandbox contact list. Same with call history. If they build the app to not work in those situations but the user doesn't want to grant the permissions unlimitedly, then the app should fail. But all-or-nothing permissions where the app demands lots, or doesn't run, is a bad thing.

      This is one case where Android is less user configurable than iOS.

  19. Re:As a user by Opportunist · · Score: 1

    Should have said "products".

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  20. The true cost of free by sinij · · Score: 3, Insightful

    As someone that used to work with mobile security - this is tiny minority that got caught. If you carry your mobile phone with you, then you have no reasonable expectation of privacy. Treat your smartphone as a combination of public WiFi and a court-assigned GSP tracking ankle bracelet.

    1. Re:The true cost of free by Mr.+Spock · · Score: 1

      As someone that used to work with mobile security - this is tiny minority that got caught. If you carry your mobile phone with you, then you have no reasonable expectation of privacy. Treat your smartphone as a combination of public WiFi and a court-assigned GSP tracking ankle bracelet.

      This. The entire business model of the internet has shifted to one of sharing geolocation, identity, and preference data that many people would consider private if given the opportunity to provide or withhold their informed consent. We do know that our phones are on the internet, right?

  21. Alternative by Anonymous Coward · · Score: 0

    What is the best/simple alternative? Thank you in advance.

    1. Re:Alternative by jonbryce · · Score: 1

      TeslaLED

    2. Re:Alternative by Anonymous Coward · · Score: 0

      Bestest Flashlight Free

  22. Oh! by lagomorpha2 · · Score: 1

    flAshlight app. With an 'a'. Had me worried for a bit.

    1. Re:Oh! by Anonymous Coward · · Score: 0

      Why would a Fleshlight app (which I guess you meant with that joke) make you worry?

    2. Re:Oh! by lagomorpha2 · · Score: 1

      Why would a Fleshlight app (which I guess you meant with that joke) make you worry?

      A Fleshlight app by itself wouldn't. A "Location-Sharing Fleshlight App" on the other hand...

  23. Redundant and weird. by rel4x · · Score: 1

    Part of my job involves inspecting outbound network connections from android apps. Practically every ad network is sending your coordinates or location anyways. It seems a bit weird the FTC cared that the app was doing the same when it already had ads on it...

    --

    Before you mod me funny, think, perhaps I was insightfully funny?
    1. Re:Redundant and weird. by Gavagai80 · · Score: 1

      I'm assuming the ad networks only send IP location data (not very accurate, generally only gives the nearest big city and is often off by hundreds of miles) while the app sends GPS data.

      --
      This space intentionally left blank
  24. What's the problem by Anonymous Coward · · Score: 0

    Isn't it just metadata?

  25. "Brightest Flashlight Free" by TangoMargarine · · Score: 1

    Just the name of the app already triggers my warning bells. Poor grammar (why is "Free" in the app name, let alone at the end?!) and the "Brightest!" modifier (reminds me of all those countries with "People's" and "Democratic" in the names) make me suspicious. And this was in the Google store? Shame, Google.

    --
    Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
    1. Re:"Brightest Flashlight Free" by mattack2 · · Score: 1

      Presumably Free is in the name to contrast it with a potential non-free version. Many iOS apps do it that way, though now I think you could use in app purchase to turn off the ads (in the free version) instead.

    2. Re:"Brightest Flashlight Free" by TangoMargarine · · Score: 1

      Thanks for reminding me--a flashlight app with ads?! So very wrong. I love it when people try to make money off of something I could probably code myself in less than a day.

      --
      Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
    3. Re:"Brightest Flashlight Free" by Anonymous Coward · · Score: 0

      Day? Don't you mean minutes? This is hello world with a button that toggles a boolean and calls a function.

    4. Re:"Brightest Flashlight Free" by TangoMargarine · · Score: 1

      Having no experience with the setup, I suspect it would take a little time for me to familiarize myself with how to package it. And are there any platform considerations? As this is Android...

      Note also that I said "probably less than a day," which would cover "minutes."

      --
      Unity? Screw that: XFCE. Slashdot Beta? Screw that: SoylentNews. Australis? Screw that: Pale Moon. UX developers DIAF
  26. GPS spoofing via root? by Anonymous Coward · · Score: 0

    Does anyone have any experience with this? I'd love to have an app where I can spoof the GPS info sent to apps on a per app basis. I.E. tell everything except Maps, Yelp and Cerberus that I'm located in the NSA offices at Fort Meade. Not only would that get me a little more privacy, but also corrupt the data being collected by these shady app companies.

  27. Yeah, and what a hammer it is *sarcasm* by sirwired · · Score: 1

    This settlement meant that the company had to do NOTHING other than to go forth and sin no more. They did not have to pay a single solitary dime, consent to long-term monitoring, or do anything really, beyond promising they would not continue to do something they unambiguously should never have been doing in the first place.

    Yeah, that'll teach 'em!

  28. Andorid tells you app permissions by JustNiz · · Score: 1

    When you install an app, Andorid tells you the permissions the app needs and asks you to confirm.

    If your'e dumb enough to not question why a flashlight app would need access to GPS and the internet, and you still install the app anyway, then you deserve all you get.

    1. Re:Andorid tells you app permissions by Anonymous Coward · · Score: 0

      Loads of apps request internet access and location data, simply to use for targeted advertising. When I first looked for an Android flashlight app I had to go through about half a dozen apps before finding one with what I considered reasonable permissions, and if I wasn 't knowledgeable enough to know that coding a flashligh app should be fairly trivial and thus someone would be likely to make a free version without adverts or other egregious permission requests maybe I wouldn't have carried on looking.

  29. "The Government" by Anonymous Coward · · Score: 0

    The government has a lot of balls pointing fingers like that...

    Strange thing about the (US) government: it's friggin' huge, with millions upon millions of people working for hundreds, if not thousands, of departments, agencies, and bureaus. They don't all want the same things; sometimes, different departments and agencies want diametrically opposed things. Some of them are charged with spying on group A, some with protecting the privacy of group B, and vice versa.

    (Many people would argue that this is a major a problem. Other people would argue that this is by design. And some in the first group would argue that that is the real problem. At which point, some in the second group would allege that they, in fact, are the problem. After that, both groups just start arguing about the health care law.)

  30. That'll get the data back! by halcyon1234 · · Score: 1

    Great, the FCC told them not to do it. Let's just say that actually gets them to stop harvesting the data (hahahaha)... what about the data that's already been harvested? They've already stolen a valuable resource which they can continue to sell to 3rd parties.

    For that matter, what about the data already in the hands of the 3rd parties? They can do whatever they want with it with impunity.

    Maybe we need to hold 3rd party marketers liable, too. Pawn shops are on the hook if they buy stolen items. Let's make marketers pay the same way. Did you buy marketing data from a skeevy company, and that company just got fined? You get fined too, for at least the same amount. Or double. Just watch how quickly the industry starts policing itself, overnight.

  31. Re:As a user by CubicleZombie · · Score: 2

    When I read the access request for any Android app, I end up declining. SD card, network, contacts, and location access, for a kitchen timer? No thanks. That's why I have no apps on my phone and why I miss my Startac.

    And I just don't have the time to mess around with custom roms or rooting the phone.

    --
    :wq
  32. I was offered money to add spyware to my app by efalk · · Score: 5, Interesting

    I have a couple of calculator apps on the Android market. Obviously, a calculator has zero need for any of your personal data, and that's how much I collect -- zero.

    I recently received an email from "Appayable.com". They provide me with a spyware module to add to my apps. The spyware module collects users' personal data and uploads it to Appayable.com. I get paid. Profit!

    They say they only sell anonymized data, but I still thought it was a pretty reprehensible business model. I suspect it's pretty common practice, though.

    The letter:

    I noticed that RpnCalc Financial -- HP 12C has seen a growing number of downloads in recent weeks. I wanted to reach out and discuss how my company, Appayable, offers developers the opportunity to monetize their app without placing ads or impacting user experience

    We pull the social profile of your users, anonymize the data, and identify the mobile device. Appayable's SDK does not take up screen real estate on your application, maintaining the great user experience, and providing more revenue for you. Plus, we do not rely on impressions - as we do not place ads within your app - thus, you generate revenue based on a single download and install. No need to retain the user - only have them open the application once.
    The revenue stream created is ongoing based on our data partnerships, regardless of continued use of the mobile application.

    We've worked hard to make it really simple for you to integrate our service into your app, and as a result have over 6,500 applications on our platform in only 6-months! Whe you have a few minutes, I'd love to talk to you or the appropriate person about working with us.

    1. Re:I was offered money to add spyware to my app by tlhIngan · · Score: 1

      I have a couple of calculator apps on the Android market. Obviously, a calculator has zero need for any of your personal data, and that's how much I collect -- zero.

      I recently received an email from "Appayable.com". They provide me with a spyware module to add to my apps. The spyware module collects users' personal data and uploads it to Appayable.com. I get paid. Profit!

      They say they only sell anonymized data, but I still thought it was a pretty reprehensible business model. I suspect it's pretty common practice, though.

      So a question is - are your apps free? Or do I have to cough up $$$ for them?

      If they're free, then how do you eat? Do you just do this as a side hobby?

      And that's the key - a lot of people do this to make money, and the problem is the Android business model makes it very hard to do so (Google Play store revenue for developers is but a tiny fraction of Amazon App Store, - something like 1/3rd or less). This is in part due to the limitations of Google Wallet making non-free apps have less visibility. Especially in the early days where Android was everywhere, but paid apps was US-only. (The irony being that as a Canadian company that released an app, we couldn't even BUY OUR OWN APP!)

      So people hitched onto the ad-supported model (adware) - developers need the money, and the longer you can keep users using your app, the more money you make.

      Naturally, Google benefits, owning one of the larger mobile advertising companies out there. But there are others.

      And yes, developers seeking to make money from apps will integrate those modules in - easy money and they get to set the price to free, eliminating a lot of barriers to installation.

    2. Re:I was offered money to add spyware to my app by Anonymous Coward · · Score: 0

      I FBd and Tweeted this great comment about personal integrity, but canceled due to Slashdot wanting to access my accounts, personal information, followers and contacts on both plus have the ability to post (It did not say "Just this once.")

    3. Re:I was offered money to add spyware to my app by Anonymous Coward · · Score: 0

      If you're relying on a calculator app to eat, you're doing it wrong.

    4. Re:I was offered money to add spyware to my app by Anonymous Coward · · Score: 0

      Kudos to you sir. I'm buying your app.

    5. Re:I was offered money to add spyware to my app by alostpacket · · Score: 1

      I get this too. Also get emails where people have uploaded my apps and created an account for me to some korean market.

      I think the ones I hate the most though are the emails asking if I want to buy fake ratings.

      --
      PocketPermissions Android Permission Guide
  33. Giggity by Anonymous Coward · · Score: 0

    I must have read the title wrong.

    I thought it allowed you to find other people using the app near you while you were using your flashlight.

    You know, because, when the power's out, there's only ONE thing worth doing . . .

  34. Simple LED Widget by slinches · · Score: 3, Informative

    I just recently got a Nexus 5 to replace my aging Nokia N9 and was amazed by the near complete lack of simple tools that don't want access to your data in return. For the N9, there were a ton of useful free open source tools provided by the community over at maemo.org. That community was great. Every time I thought that there was something that was missing or new capability I wanted, I'd look there and find an app that already exists or a group of people in the process of building it.

    The contrast between that experience and the excessive commercialism of Android was startling. After looking around for a while I did find this Simple LED Widget that is just what it says and doesn't require any unnecessary permissions, but I had to sift through dozens of apps like the one in the TFA.

    Is there anything even close to maemo.org for Android? I've heard some good things about F-Droid, but I haven't looked into it enough yet to know if it's the best option.

    --
    Knowledge Brings Fear
    1. Re:Simple LED Widget by Anonymous Coward · · Score: 0

      F-Droid is great. You actually can find a good amount of apps on there that are on the Google Play store, but in F-Droid have their spy/ad -ware removed. All of the apps listed also include links to their source code.

    2. Re:Simple LED Widget by Anonymous Coward · · Score: 0

      I have a N900 and face the same problem, my touchscreen is ever so slightly wonky so im using a old Iphone 3GS on the side, but the interface requires more interaction to do the same basic things and the appstore is horribly bloated and filled with nonsense which makes it difficult to find anything interesting.

    3. Re:Simple LED Widget by nblender · · Score: 1

      Me too. I just switched from iphone to N5. I couldn't find the built-in flashlight app that I assumed would have been standard fare at this point. Go to the Play store and the first 10 or so flashlight apps all want access to your phone calls, sms, filesystem, and network.... I finally found one that wanted only Camera access and Network. I still don't know why an app to toggle a GPIO would want access to the network... Other things that are basic functionality on IOS are apps you have to download and monkey about like displaying incoming text messages on your lockscreen... The widget that does that wants access to kitchen.sink as well..

      I'm going to keep on trying to love the N5 but so far I miss my iphone...

    4. Re:Simple LED Widget by Anonymous Coward · · Score: 0

      I like F-Droid, but they don't have everything you might want and would expect to be in an open source app repository (like an ssh server) and also their apps can sometimes be quite out of date. For my Nexus 5 I ended up having to install K-9 Mail from the Play Store because the version F-Droid had was two stable releases out of date and it just didn't work on my Nexus 5 for some reason. But still it can be worthwhile looking there first because it can save you wading through loads of adware ridden crap on the Play Store.

  35. Re: As a user by iamhassi · · Score: 0, Flamebait

    I'm going to get flamed for this, but.... buy an iPhone? can't happen in iOS, apps can not access contacts or location without asking first, the operating system won't allow it, and you can remove the access anytime in settings. I know, flame on, but if this was Windows and someone said how can I stop getting viruses and someone recommended Linux it would be +5 insightful

    --
    my karma will be here long after I'm gone
  36. the missing app by Tom · · Score: 3, Insightful

    What's obviously missing is a Mock App - something that will satisfy all those requests and provide them with the data they want - fake data.

    Sadly, I don't expect Google - whose revenue stream is largely based on advertisement - would make that possible in Android.

    --
    Assorted stuff I do sometimes: Lemuria.org
    1. Re:the missing app by Anonymous Coward · · Score: 0

      A rooted phone/tablet running:

      LBE Security... Chinese app but here is the link that attempts English translations:

      http://forum.xda-developers.com/showthread.php?t=1422479

      Also, you can use Xposed Framework with xPrivacy... this is a more lightweight application, but I have had issues in apps knowing they are being locked down and refusing to run...

      http://forum.xda-developers.com/showthread.php?t=1574401

      http://forum.xda-developers.com/showthread.php?t=2320783

    2. Re:the missing app by Anonymous Coward · · Score: 0

      I have system-wide AdBlock Plus on my android phone. Sure, there are weird glitches when a game loads an unskippable (ha!) fullscreen null video. I usually have to hit the phone's back button to get back to the game.

      I only went full nuclear when stupid Battlefield 4 ads began interrupting my bejeweled-clone gaming sessions and crashing the game. Yes, Battlefield 4 is such a crappy, buggy POS that video ads for it crashed other games. Ringing endorsement, right there.

    3. Re:the missing app by JackieBrown · · Score: 1

      I was playing candy crush (I know, you can laugh or cry), when I got one of those full screen video ads. Since my volumes controls aren't linked to the ringer, I was pretty startled by the noise. Glad I wasn't sneaking a game during a meeting....

      Adaway is the first app I install now.

  37. Re:As a user by hawguy · · Score: 1

    When you installed it, didn't you look at the list of what it has access to? If I saw it wanting to get my location I would have stopped right there and not installed it. No flashlight app needs to know my location to work.

    Many ad supported apps want your location so they can serve geo targeted ads.

    Though there are plenty of free non, ad-supported flashlight apps. The only permission the app I'm using has is the ability to access the camera.

  38. But the NSA didn't tell me either by TheCastro1689 · · Score: 1

    So when will the Government fine itself or the NSA for gathering my location info without telling me. Heck, I didn't even download their app.

  39. I downloaded the US citizen app decades ago by Anonymous Coward · · Score: 0

    The NSA never disclosed that they were tracking my location etc. where's the hammer for those schmucks?

  40. Up front permissions bad plan by SuperKendall · · Score: 1

    It's a pain, but the average user needs to start actually paying attention to app permissions.

    Except the "average user" literally CANNOT understand the permissions being asked for.

    That's why an up-front model for permissions is inherently broken. If an app sneaks in location in the set of permissions an "average user" will never see it. If it asks them if the flashlight app can have their location when they run it, or access to contacts - there's few people that would agree to that.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  41. You kids and your apps! by kheldan · · Score: 1

    You people have no idea what you're loading onto your phones or what it's doing with your data and your life!

    Why isn't there more comprehensive oversight of these apps before they're released to the public? Can't they require the source code be submitted to the 'app stores', and proofread to prevent this sort of thing from happening?

    --
    Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
  42. Re:As a user by lgw · · Score: 1

    When I read the access request for any Android app, I end up declining. SD card, network, contacts, and location access, for a kitchen timer? No thanks. That's why I have no apps on my phone and why I miss my Startac.

    I'm looking for a feature phone to replace my smartphone now. There just are no apps I'm willing to install, plus I want physical buttons.

    --
    Socialism: a lie told by totalitarians and believed by fools.
  43. They might as well of gave them hookers and by ralphaostrander · · Score: 1

    And paid for the blow jobs too.

  44. YAA - com.volsa.torch (Simple Torch) by SpaceLifeForm · · Score: 1

    Just google it. You don't need to get from play store.
    It is as clean as possible. Only does what it needs to do.

    --
    You are being MICROattacked, from various angles, in a SOFT manner.
  45. Sad state of the Android Market by MobyDisk · · Score: 1

    1) Use DroidLight. It's by Motorola, but it works on non-motorola phones too. It requires no permissions.

    2) We are in a sad state of affairs.

    9 out of 10 flashlight apps in the Android store require unnecessary permissions. The Android store needs ONE flashlight app. Maybe 2. Unfortunately, idiots download apps that requires 100 permissions, then rank it a 5/5. This is such a trivial problem for Google to solve: one Google Play Store employee could ban 90% of those apps with a day of research and resolve the problem for the most part.

    Even in the wild wild world of PC shareware, malware wasn't as bad as it is in the Google Play store.

    1. Re:Sad state of the Android Market by wonkey_monkey · · Score: 1

      1) Use DroidLight. It's by Motorola, but it works on non-motorola phones too. It requires no permissions.

      The ability to control the flashlight is a permission.

      It also, perhaps for non-nefarious reasons, requires the "Take pictures and videos" permission.

      My Samsung Galaxy SIII Mini, for what it's worth, came with a home screen widget called "Assistive Light" which turns on the flash instantly, unlike every single app I tried, all of which took seconds.

      --
      systemd is Roko's Basilisk.
  46. Dropping the Hammer by Anonymous Coward · · Score: 0

    Ahhh, the day and age when "dropping the hammer" means "you're changing this stuff in this software, but don't worry about a fine or anything".

    BOOM! HAMMER DOWN!

  47. For non-evil Android apps, see F-Droid by Phil+Urich · · Score: 2

    What app do u make?(desperately seeking non-evil android apps)

    Whenever I'm looking for an app of some kind, I check F-Droid first.

    --
    I remember sigs. Oh, a simpler time!
  48. NSA doesn't like copy-cats? by Anonymous Coward · · Score: 0

    It's completely fine for the NSA to gather data without your consent or knowledge... but for a phone app to do the same? HERESY!!!

  49. FOSS flashlight app by Compaqt · · Score: 1

    The answer is the user can't differentiate, unless we have access to the source code.

    So here's an open source flashlight app you should be using:
    MrWhite: https://fdroid.org/wiki/page/org.bc_bd.mrwhite

    Or Torch: https://fdroid.org/wiki/page/com.colinmcdonough.android.torch

    Install them by installing the F-Droid (FOSS for Android) package manager from Google Play.

    --
    I'm not a lawyer, but I play one on the Internet. Blog
    1. Re:FOSS flashlight app by cdrudge · · Score: 1

      But how do I know that F-Droid is clean? :)

      I wasn't looking for suggestions for a flashlight app. It was more of a specific example in an abstract discussion. My comment's parent asked the specific question why a flashlight app needs gps and network permissions to which I suggested legitimate reasons why such permissions would be requested. They may not be needed for the app to operate correctly, but they may be needed to support the developer's work.