Will third-party plugins survive the tech backlash

vtqhtr413

Level 26
Thread author
Verified
Top Poster
Well-known
Aug 17, 2017
1,491
Tech companies are taking more and more heat over other people’s software. An alarming story in The Wall Street Journal this week dove into the world of Gmail plugins, many of which have the power to scan through users’ entire inboxes. Some of that scanning is automated, but in other cases developers have combed through emails by hand, raising obvious privacy issues.

It was an ugly story for Google, not just for its immediate impact but for the difficult assumptions underneath. For decades, platforms have trusted users to make their own decisions about what programs to install and accept the consequences if they choose to install something scammy. After the Cambridge Analytica scandal, that trust is starting to look irresponsible. Facebook and Google are adjusting to the idea that, if they let something bad happen on their networks, they are going to catch the blame for it. After years of light-touch moderation, that means taking an entirely new look at third-party ecosystems -- and facing the hard question of whether it’s worth having them at all.

Is it time for platforms to ditch third-party apps altogether?

Under the old expectations, there’s nothing obviously scandalous about the Journal story. User emails were definitely exposed, but it all happened with the user’s permission. Apps need email access to work as a client, and Google is clear about the permissions when the app is installed, even if most people click through without thinking about it. Google didn’t make the apps or even promote them, and while it could be more strict about weeding out scammy plugins, it’s not clear what rules the offending apps had even broken. As one reporter put it: “if you give something access to your Gmail, it has access to your Gmail.”

But that may not be good enough anymore. Whether permissions were granted or not, Gmail users gave up incredibly sensitive information, sometimes without realizing what they were doing. In a post on Tuesday night, Google defended itself, reminding users of exactly what the permissions they clicked through looked like. “We review non-Google applications to make sure they continue to meet our policies, and suspend them when we are aware they do not,” the company said.

Full article: Will third-party plugins survive the tech backlash?
 

Weebarra

Level 17
Verified
Top Poster
Well-known
Apr 5, 2017
836
There was a story here in the UK yesterday sort of running through the same vein, regarding all the legal gumph we have to wade through which in turn makes people just click "agree" without actually reading it let alone understand it.

There was talk of them getting it simplified to around 4 or 5 key statements on privacy, permissions etc and it took a lawyer to go through all of the terms and conditions that we click on and simplify them to 5 or so key conditions and in plain English so that people can actually understand them. He did do it though after a time so these big platforms should be able to do it too.

These companies/app developers knew what they were doing, they know people don't really read it all so i think it's high time that governments (or whichever body oversees this) took a stance and forced these companies to make the T & C's simpler.

It was only recently (after the FB thing) that i realised that i had given permission to some app which could see my contacts, read my mail etc, and i honestly don't ever remember doing this :unsure:
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top