Facebook, Flickr, others accused of reading text messages
Summary: Reports surfacing this weekend claim that popular smartphone applications can access users' text messages amongst other personal data, even when that phone is not being used.
Updates: see below.
Application developers and store operators are in for further rough times, as reports emerged this weekend that a number of popular smartphone applications, including Facebook, YouTube, Flickr, and others, can access private text message data or other personal information.
The Sunday Times (paywall) reported that Android and iPhone users are vulnerable to such invasions of privacy, though it is unclear whether application developers actively access data, or whether it is a result of poor security permissions.
It is claimed that some applications can intercept phone calls, while others can allegedly remotely access a smartphone's camera, or even pinpoint its location without the user's knowledge.
Since the Path debacle, Facebook and Twitter later became embroiled in the privacy row, whereby contact list data was uploaded to their servers.
Apple responded by rolling out a fix --- thought to be currently in development, though no definitive date on when the fix will reach consumers --- which would require explicit user consent before contact list information was accessed.
But as terms and conditions are often criticised for being overly complicated and lengthy, the vast majority of users unwittingly allow such actions through accepting such terms.
The application industry is thought to be worth over $6 billion annually. Arguably the blame does not only fall on the developer, but the major application store owners, like Apple and Google, for allowing the applications to be downloaded. They have also criticised for failing to secure mobile devices against such data harvesting expeditions.
While Apple has an incredibly strict terms and conditions for submitting applications to the Apple App Store, Google does not. The search and mobile giant still removes applications daily that are found to contain malware.
One concern for many is that applications solely created for the purpose of accessing such information are being downloaded, in amidst a transatlantic shift on data protection and consumer privacy rights.
Update 1: Headline edited for accuracy. As per the table, YouTube does not collect text message data, but has the ability to collect calling information "among other things", a Google spokesperson said. They did not wish to comment further.
Update 2: That was quick. A Facebook spokesperson said there is "no reading of user text messages." Facebook calls out the Times piece as "completely wrong", but acknowledges that the Android application permissions require SMS read and write capabilities.
Facebook said that lots of communications apps use these permissions, and the application technically has the capability to integrate with the phone's SMS system, but added that it is for testing purposes.
The company did not respond to the claim that the Times "admitted" to reading text messages, however. One question answered, and another ten questions open up.
Illustration modified; original credit: London's Daily Mail.
Related:
- Apple: Apps using contact data are in "violation"; fix coming soon
- Twitter uploads contact list data without consent; retains for 18 months
- Think before you tweet: Why two teenagers were refused entry to the U.S.
- Google needs to clean up its Android Market malware mess
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
Here's an invasion of privacy for you Zack: eMail is clear text
Funny because, we put letters in envelopes, for what?
(Hint: Answer is P-----y).
See if you can guess the answer! :/
QUi bono?
Testing
They don't test this stuff, do they?
No Clear Text
Backdoors?
More info
So, it makes sense that Flickr has access to the camera; so that you can upload to Flickr directly from it. Were it to say "So that you can upload photos directly ... and that's all we'll do" - that would be fine.
Ditto facebook & texts; were it to say "so that you can update your status by text & get status updates by text [by the way, you can set it so that you can choose which updates you get - many people like to get just messages & status updates from close friends] - we won't do anything else :)"
To me, both of those are explanatory & clear - and are reasons I'd be perfectly happy with (bar the fact I've set Facebook not to send SMS updates at all, but that's by the by)
You are right
Grred or Fear is the question we need to ask.
Clozapine and Lithium
And on it goes
My Fitness Pal