Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The flaw seems pretty obvious here.

AppStore = lots of "walls/rules", supposed protection, apps have free access to contacts

Market = few "walls/rules", but accessing contacts was a declared and required permission attribute

Apple's walled garden did nothing to prevent apps from freely helping themselves to contacts without user interaction or notification. Android didn't have to curate to solve this problem, they simply implemented it "correctly" at the platform level on the first go.

Frankly, I'm not sure what I think of this criticism of Apple anyway. Where is it declared that your Address Book is absolutely secret information? Windows doesn't protect my Thunderbird contacts, hell, Thunderbird doesn't even try to. Yet I don't blame them for spyware that steals that information. Quite honestly it scares me how much people are totally okay with being dependent on Apple and running to them for protection. It's a losing game this way. There will always be some sort of information, even if acquired via the user or declared permissions, that we won't expect them to want/use/sell. We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.

(My scare quotes aren't commentary so much as they are me trying to stay neutral. I don't know what is the "right" position on these things, frankly I don't worry about this aspect of my privacy that much, and I'm currently with an Android phone.)

edit: I guess my post changes a bit if it really was against the Apple Developer agreement to do this. I guess I would be miffed that they weren't enforcing and protecting against it.



> Quite honestly it scares me how much people are totally okay with being dependent on Apple and running to them for protection. It's a losing game this way.

They build the OS, why shouldn't they protect me? Is there a practical alternative?

> We should be focusing on expecting more "ethical privacy" stances by the companies that write these apps.

I agree, but many people expect stuff to be free and ad-driven. As soon as an otherwise honest developer drops in a fishy Ad framework, it's basically game over. I would be surprised if none of them would send AB data over the wires. They certainly send everything else they can get.


It was indeed against the developer agreement to do this.

But more importantly, we simply don't know whether Android is actually protecting customers or not.

If people are just clicking through a warning and having their address book copied against their wishes, that may technically shift responsibility onto them, but it doesn't mean they are 'protected' by a 'correct' platform. It just means that Android is protected from accusations.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: