Slashdot Mirror


Apple Tells App Developers To Disclose Or Remove Screen Recording Code (techcrunch.com)

An anonymous reader quotes a report from TechCrunch: Apple is telling app developers to remove or properly disclose their use of analytics code that allows them to record how a user interacts with their iPhone apps -- or face removal from the app store, TechCrunch can confirm. In an email, an Apple spokesperson said: "Protecting user privacy is paramount in the Apple ecosystem. Our App Store Review Guidelines require that apps request explicit user consent and provide a clear visual indication when recording, logging, or otherwise making a record of user activity." "We have notified the developers that are in violation of these strict privacy terms and guidelines, and will take immediate action if necessary," the spokesperson added.

It follows an investigation by TechCrunch that revealed major companies, like Expedia, Hollister and Hotels.com, were using a third-party analytics tool to record every tap and swipe inside the app. We found that none of the apps we tested asked the user for permission, and none of the companies said in their privacy policies that they were recording a user's app activity. Even though sensitive data is supposed to be masked, some data -- like passport numbers and credit card numbers -- was leaking.

33 comments

  1. No problem by JustAnotherOldGuy · · Score: 1

    I'm sure that no one would ever misuse all that sweet sweet private information like password and account numbers and logins and private nude pics.

    --
    Just cruising through this digital world at 33 1/3 rpm...
    1. Re:No problem by Anonymous Coward · · Score: 0

      Ugh, Donald Trump mushroom dick pics?

    2. Re:No problem by Anonymous Coward · · Score: 0

      Worse. Trump and Bezos.

      Historians will refer to it as the "War of the Dicks".

    3. Re: No problem by Anonymous Coward · · Score: 0

      What is this 3rd party tool? I want to get it for my app, users never give any feedback these days and itâ(TM)s a good way to see where they are having problems.

    4. Re: No problem by Anonymous Coward · · Score: 0

      You just need a man, baby. Yeah!

  2. first :) by Anonymous Coward · · Score: 0

    comment

    1. Re:first :) by Anonymous Coward · · Score: 0

      Nope. You missed by a minute. Twenty lashes for you!

  3. Jeff Bezo vs Pecker by Anonymous Coward · · Score: 0

    Ain't nobody want to see Jeff Bezo's semi-erect manhood!

  4. Micro$haft Blows by Anonymous Coward · · Score: 0

    This has got to be there fault somehow, amirite, my fellow slashditters?!

    1. Re:Micro$haft Blows by Anonymous Coward · · Score: 0

      It sure isnt apples. Its never apples fault with all the blind apple worshippers here.

    2. Re:Micro$haft Blows by Anonymous Coward · · Score: 0

      It sure isnt apples. Its never apples fault with all the blind apple worshippers here.

      Sure it is.

      It's always Apple's fault with all the blind Apple Haters here.

  5. Crazy Conspiracy Theories by Anonymous Coward · · Score: 0

    Corporate entities are heavily regulated by duh gubmint and there's no way duh gubmint would let them do that to the people. We had Obama for eight years and he fixed all that privacy stuff because real TV news says so. This might be Putin and Trump's fault though... lets investigate... for years and years and years. ae911truth dot org

  6. "Screen recording" by Dan+East · · Score: 2

    And once again the misnomer "Screen recording" is being used inaccurately in the headline to draw more attention. "Screen recording" is a phrase that has a specific meaning, and there is no screen recording going on. I don't feel like typing it all again... https://slashdot.org/comments....

    (I'm not condoning or defending this practice, but just clarifying that the screen is not literally being recorded and streamed as video)

    --
    Better known as 318230.
    1. Re:"Screen recording" by Anonymous Coward · · Score: 1

      Glassbox does also send screenshots back to the developer: http://theappanalyst.com/aircanada.html

    2. Re:"Screen recording" by Anonymous Coward · · Score: 0

      HERBERT WEST RULES DAN EAST DROOLS

      Filter error: Don't use so many caps. It's like YELLING.

  7. Sure, that will solve the problem by Anonymous Coward · · Score: 2, Interesting

    Did you know that every app in the App Store is required to link to a privacy policy if it records data? If you did, do you know how to find that link?

    It's in the "information" box that is helpfully hidden way at the bottom - but not all the way at the bottom - of an app's page on the App Store. If you scroll to the bottom you won't see if because you'll have gone past it.

    So all this is going to do is make the apps doing this add it to that privacy policy most people probably aren't aware even exists because it's hidden below the "app compatibility" and "supported languages" sections.

    1. Re:Sure, that will solve the problem by Dru+Nemeton · · Score: 1

      Hyperbole much?

      It's not hidden. It's very easy to find since in the "Information" box (2 of 3 for each app) it's the only blue link and the only entry with an icon. (A blue hand which is the same icon used in iOS for "Privacy" as you can see in the Settings app.)

    2. Re:Sure, that will solve the problem by Anonymous Coward · · Score: 0

      Uh, no, you're wrong: it's the only blue entry if that's the only link included in the app metadata. Otherwise it's hidden in a list of links along with the developer's website and the license agreement. (Did you know you also agree to that license agreement that's linked in the information box just by installing an app?)

      And the information box is not easy to find: it's scrolled off the bottom of the app page by reviews when you first pull up the page, but also scrolled off the top if you scroll to the very bottom, as the bottom is taken up by "also by this developer" and "you might also like" sections. It's very intentionally designed to be a thing you carefully scroll to but otherwise would never notice.

  8. Did they bother to protect users by AHuxley · · Score: 1

    from PRISM?

    --
    Domestic spying is now "Benign Information Gathering"
  9. Proprietary software = Spy vs. Spy by jbn-o · · Score: 0

    No, nor did they bother to immediately disclose this even to their users. That would interfere with the effectiveness of the spying. Most people learned about this from Ed Snowden's disclosures (three cheers for Snowden!). So when Apple tells you "What happens on your iPhone stays on your iPhone" there's no reason to believe them. After all, I'll bet people running iTunes thought they were getting a media player, not opening a remotely-exploitable hole despite Apple knowing about this problem for years and licensing iTunes such that nobody else was allowed to fix it and distribute an improved version of the software. The power of proprietary software (non-free software, user-subjugating software) is what makes this entire story indistinguishable from one spy agency telling other competing spies to buzz off—on Apple's turf the users are exclusively Apple's to exploit.

    1. Re:Proprietary software = Spy vs. Spy by Anonymous Coward · · Score: 0

      apple has always been an untrustworthy corporation. Right from day 1.

    2. Re:Proprietary software = Spy vs. Spy by jbn-o · · Score: 1

      Apple is part of the UAE's "secret hacking team of American mercenaries" which seek to "help the United Arab Emirates engage in surveillance of other governments, militants and human rights activists critical of the monarchy".

      What Apple tells people via its ads: "What happens on your iPhone, stays on your iPhone"

      Some of what Apple won't comment on: "The operatives utilized an arsenal of cyber tools, including a cutting-edge espionage platform known as Karma, in which Raven operatives say they hacked into the iPhones of hundreds of activists, political leaders and suspected terrorists." (source: the aforementioned Reuters article)

      Additional commentary from the only comedy news program worth watching, Redacted Tonight.

  10. Experienced something similar as a developer by cerberusss · · Score: 4, Informative

    I'm an app developer and years ago, started with an app in the App Store and included one of those free analytics libraries. It's quite useful, you get the crash reports coming in as they occur in the field. At some point, I was very proud to have solved nearly all crashes.

    Then I felt like people needed to be able to opt out. So I built a screen with a simple checkmark, and looked at their API to turn off data collection. Turns out, it's not there. To opt out as a user you needed to go to a web page, and fill in your email adres. I thought to myself, what? What the fucking what? How can you relate crash reports with an email address? Then I realized that's what free means. I should never have started with it.

    Note: this was in 2012/2013, and as a starting iOS developer, I was pretty naive. First of all I should've built my own light weight crash reporter. Second of all, it should've been opt-in.

    I've tried Localytics, Crashlytics and Flurry. They all have severe privacy problems in my opinion. I have simply removed them from my app, because I kept feeling bad for my users.

    --
    8 of 13 people found this answer helpful. Did you?
    1. Re:Experienced something similar as a developer by Anonymous Coward · · Score: 0

      That's an interesting experience you shared, thanks.

    2. Re:Experienced something similar as a developer by AmiMoJo · · Score: 1

      Fortunately that's illegal now. GDPR requires explicit opt-in. Opt-out and requiring an email address to do so are not allowed.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    3. Re:Experienced something similar as a developer by BringsApples · · Score: 1

      Thank you! I hope there are many more developers like you out there that keep the users privacy in mind.

      --
      Politics; n. : A religion whereby man is god.
  11. Stupid genius Apple App review by ReneR · · Score: 0

    How this slipped their review is beyond me, bur our fine paperless office applications, like ExactScan, they reject because they would "ask for an access the user's Contacs" (which we don't): https://www.youtube.com/watch?... And yet every other time they approve the updates, ..! And I swear we have no code to access the Contacts, ..! And they can't even answer with a backtrace where it would happen, ..! :-/ In the meantime I suspect our "crash reporter" optional "directly sending it to us" code accessing some "~/Library/Logs/CrashReporter/" to trigger this. But only time and more data points will show if disabling this avoid the every 2nd App Store review reject, https://exactscan.com/

  12. Like AirCanada app using Glassbox by grumpy-cowboy · · Score: 1

    Extract : "Air Canada is unsuccessful in obfuscating credit card and password information. As a result, sensitive data is being captured as images and potentially stored."

    ref: http://theappanalyst.com/airca...

    --
    Will $CURRENT_YEAR be the year of the Linux Desktop?
  13. Bloody gobshites at Apple by Anonymous Coward · · Score: 0

    The fact TechCrunch had to discover this is appalling. It strains credulity to think that Apple simply "missed" this. And if it did, that's almost worse than allowing apps that abuse consumer trust simply for the sake of the almighty dollar. Fuck you, Apple.

  14. Oh really? by null+etc. · · Score: 0

    Protecting user privacy is paramount in the Apple ecosystem.

    Oh really? Then how come Apple only takes action after these issues get exposed to the press? Surely someone at Apple knows each and every trick that app developers use to create and promote their apps.

  15. Apple talks but does nothing by found404 · · Score: 1

    I can't reconcile the two statements below, like I can't reconcile nearly everything Apple does. If you're so serious about privacy and an app (or apps) completely violated this in such a violent and litigious way - why wait to do something? Toss them off the store... for good!

    What they captured without consent is so over the line, the response needs to be equally strong.

    ""Protecting user privacy is paramount in the Apple ecosystem."" ... ""and will take immediate action if necessary""