Email or username:

Password:

Forgot your password?
Dale Price

This is what the iOS contact permission prompt should be

Newer model iPhone mockup. At the top of the screen is a grid of contact pictures and the text “You have 579 contacts. Contact information includes names, emails, photos, phone numbers, addresses and more”.

In the lower half of the screen, there is a header “Get permission before sharing contact info” with the text “We're not going to let you betray your friends that easily. You'll need to get their permission to allow ‘Flashlight+ Pro Free HD’ to access their contact info.”

At the bottom are two buttons: “Request Permission From 579 Contacts” and “Don’t Share”
57 comments
Maarten Sneep

@dale_price Exactly, get even with the “We and our 1465 partners value your privacy”. This one is from vice.com.

GDPR dialog.

We value your privacy
We and our partners store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised advertising and content, advertising and content measurement, audience research and services development. With your permission we and our partners may use precise geolocation data and identification through device scanning. You may click to consent to our and our 1465 partners’ processing as described above.
Leeloo

@mrtnsnp @dale_price
1465? Are they insane?

That's why I call them "American popup notices".

If they had anything to do with the EU, then every time they got a deletion request, their GDPR officer would have to call each of those 1465 "partners", and ensure that they delete the data.

Of course you can also tell that this has nothing to do with EU regulation by the lack of a no button.

Maarten Sneep

@leeloo Compliance with GDPR is severely lacking, also on sites within the EU. I see the dialogs with the no button hidden several layers deep all the time. But to answer your first question: yes, they are insane. @dale_price

Maarten Sneep

@fedor They value the privacy, with a fraction of a cent. @dale_price

bigiain

@dale_price You left out the “Delete my name and all my details from John’s contacts.”

Montgomery Gator

@dale_price There are programs on Android that kinda do this by misusing the work apps profile feature. This is where I throw social media and fast food apps. There are no contacts in the work mode address book, and when I hit the freeze button they all get chloroform naps.

An app named shelter, a shortcut labeled freeze apps, and a bunch of social media apps with the shelter icon in the corner.
TobTobXX

@MontgomeryGator Waitwaitwait... That's AWESOME why didn't I hear about this yet? What App is that?

Montgomery Gator

@tobtobxx Shelter by PeterCxy of F-Droid. There's another called Insular by proletarius101 that's the same idea also on F-Droid. While I got you there, NeoStore is my preferred F-Droid client over the official one, it works a bit faster and looks a bit nicer.

TobTobXX

@MontgomeryGator Thanks! Does Neo Store have unattended background updates? (ie. Without the "update APK" popup?) Because that's the reason I'm using F-Droid Basic.

EDIT: Without root.

Montgomery Gator

@tobtobxx I don't think so, that being said I'm not entirely sure. I know having both applications doesn't cause conflicts, they both can manage the same apps jointly.

Daniel Django :verified_rainbow: :ferris:
@dale_price imagine getting this request from a contact you haven't talked to in years. Would you block and delete, or only reject the request?
Eli the Bearded

@dale_price

If you can't remotely revoke the contact info from the dipshit, what good does it really do?

Radlerin 🚴‍♀️

@dale_price
There is a problem with this:
How should Flashlight+ Pro Free HD be able to contact me to ask for my permission to access my data if it has not already accessed my data?

Fred Brooker

@dale_price bullshit

imagine controlling 500 people sharing habits in real life

Jernej Simončič �

@fredbrooker @dale_price You don't get to share my personal data with 3rd parties.

h3artbl33d :openbsd: :ve:

@fredbrooker @dale_price

So, you'd rather have your contacts sharing your data without your consent?

I do not. And I'd permanently block folks if they did share my details without making sure I'd consent to that.

翠星石
@dale_price That's not what demon rectangles are about.

If they weren't about doxing absolutely everyone, it wouldn't be possible for a cr...app to access any contact except for the ones you explicitly permit it to.
Mer-fOKxTOwl

@dale_price recently someone in an element call had an error and their "element call" part of element crashed. when that happend everyone of us got a popup with a request to give permission for them to share the crash logs.

first time i have ever seen such a thing happen.

Farshid Hakimy / فرشید

@dale_price this is how EVERY contact permission prompt should look like, not only the iOS one.
And there should be an option to share fake data with the app for it to stop asking for this permission.

su_liam

@farshidhakimy @dale_price That would be an option if we ever found ourselves in the position of owning the things we pay for.

h3artbl33d :openbsd: :ve:

@farshidhakimy @dale_price

GrapheneOS has contact scopes which is a working implementation of this. It allows to select which contacts you want to share (if any) and offers that to the application. If you seleted none, then it'll be just an empty address book.

Advanced Persistent Teapot

@dale_price yes except the default option and alternate should be the other way around

TheOldBloke

@dale_price People need to look up consent and permission before submitting contact details via any sharing features too lol

Aday

@dale_price the fact that they can share a photo of you with any gen AI seems a more pressing issue to me.

zetabeta

@dale_price

i edited little bit!

possible copyrights belong to actual owner, not for me.

edited picture. prompt in a smartphone screen for asking permission. first option is "allow". second option is "don't allow". third is much bigger than other two, it says "Block John Doe and Delete from contacts!".
impossibleibex 4Harris

@dale_price is there any reason why a flashlight app needs contact permissions?

Hans van Zijst
@impossibleibex 4Harris I would say no.

I had a photo gallery on Android once that claimed to need access to my storage (which I understand), my camera (huh?), my network, contacts and agenda.

Needles to say I deleted that app.

@Dale Price
@impossibleibex 4Harris I would say no.

I had a photo gallery on Android once that claimed to need access to my storage (which I understand), my camera (huh?), my network, contacts and agenda.
David

@dale_price The only third party app I’ve ever allowed access to contacts is @signalapp, that’s after seeing in their court responses that, as their published source code implies and privacy commitments claim, they don’t misuse that access.

Dušan Mitrović

@dale_price I've unfortunately just accepted this as a fact of human nature. Nobody, and I mean nobody, ever asked me before sharing my contact with a third party, be it another human or, in this case it's even less likely, an app.

★Pope Miller the Defondor

@dale_price a fucking _Flashlight_ App should have no access to contacts at all!
Period.

Free Soft&Hardware Enthusiast

@dale_price nice except dont share should be selected by default ;)

Kevin Karhan :verified:

@dale_price +9001%

And it should demand that in writing by notarized letter and to be compliant not just with #GDPR, not push anythibg to #iCloud (which falls ubder #CloudAct aht thus *can'r comply) and preemtively sort out #minors (as they can't consent as per #BDSG, nor can their parents on their behalf!)...

David

@dale_price
Also, I wish the model of requesting a single contact was more common. On Android, you don't need address book permissions to open the phone contacts so the user can pick a person. It's only necessary to vacuum up all that personal data (and present it in your own UI).

Briefly looking at CNContact, it looks like iOS doesn't have a similar "pick one contact to share with app" API? What could make them add it?

Dale Price

@idbrii I think iOS’ CNContactPickerViewController does that, but you’re right that it’s not commonly used

h3artbl33d :openbsd: :ve:

@dale_price

This mockup is fantastic and something we really need.

Sabrina Web :privacypride:

@dale_price there should be one more button, labeled "why the heck a flashlight needs my contacts info???"

Saupreiss #Präparat500

@dale_price

Im mildly concerned - were used that pretty much all our contact Info is automatically shared with at least one, usually two companies whose whole purpose are advertisement and data abuse. One of them is even praised as „open system“ by many.

Go Up