Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From a technical sense it's not. If an app can read data, and an app has Internet access, it can send that data to it's server, and there's nothing your OS can really do about it if it is letting the app run arbitrary code.


I am on the same boat here.

Technically it is NOT google's fault to open those access to Apps.

Just like credit card CVV, the right to grant you the access to it, prohibit you to store in your server. For personal information, I think social networks need to be held responsible to live up to the same standard.

By granting Facebook permission to read my contact, my understanding is that they should only use my contact to match against their DB and find those who are on FB. I don't think this require them to persist all my contact/conversation history in their own server.


Bear in mind, if you give your credit card to a website, the only thing prohibiting them from storing it on their server is fear of getting their PCI DSS certification revoked if they get caught doing it. There's no technical limitation... and there should be.

That's why, of course, chips for physical purchase have moved to one-time codes, effectively, so that your credit card number can't be stored without permission. Ideally, someday our online purchases will work the same way.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: