News: 1677221946

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Mozilla says 80 percent of Google Play's app safety labels are inaccurate

(2023/02/24)


The Mozilla Foundation has accused Google of incorrectly labelling apps as "Data Safe" as much as 80 percent of the time in its Play digital bazaar – with TikTok, Facebook and Twitter among the misdescribed software.

"Google Play Store's Data Safety labels would have you believe that neither TikTok nor Twitter share your personal data with third parties," [1]declares the Foundation's report on the matter. "The apps' privacy policies, however, both explicitly state that they share user information with advertisers, Internet service providers, platforms, and numerous other types of companies."

A privacy-focused research group at Mozilla examined 40 apps (out of 2.7 million on the Play store) and the accuracy of the self-reported information their developers submitted to Google's Data Safety Form – used to determine the ad giant's data safety labels.

[2]

Mozilla's folk [3]found four out of five of the resulting ratings were inaccurate, while 40 percent had major discrepancies that should have earned apps a "Poor" rating for data safety. Only 15 percent would have received an "OK" grade, had Mozillans done the grading.

[4]NASA: Yup, thousand-pound meteorite exploded over Texas

[5]Save $7 million on cloud by spending $600k on servers, says 37Signals' David Heinemeier Hansson

[6]Microsoft hijacks Google's Chrome download page to beg you not to ditch Edge

[7]China's Zhurong rover may be dead: NASA images show no sign of life

[8]Titanic mass grave site to be pillaged for NFTs

Apps that earned the researchers' stamp of approval included: Stickman Legends Offline Games, Power Amp Full Version Unlocker, League of Stickman: 2020 Ninja, Google Play Games, Subway Surfers, and Candy Crush Saga.

Paid apps were mostly worse than unpaid apps. Half of Google Play's top 20 paid apps landed in the “poor” category, including Minecraft, Hitman Sniper, and Geometry Dash. Six of the store's top 20 free apps rated as “poor,” including Facebook, Messenger, Samsung Push Services, SnapChat, Facebook Lite and Twitter.

[9]

[10]

According to Mozilla, one major flaw with the self-reporting scheme is that it doesn’t require developers to report that their apps share data with "service providers" – and uses a problematic definition of "service providers". The scheme also uses narrow definitions for data "collection" and "sharing" which allow app developers to escape negative labels via loopholes. Data deemed "anonymous" is also exempt.

The researchers conceded that while Google's Data Safety form is flawed, it at least constitutes a step toward proper privacy disclosures for consumers. But the Mozillans also wrote Google and app developers "share the blame for the failure to improve data privacy transparency in Google's Play store."

[11]

"But the responsibilities of each are not the same," wrote the Mozilla privacy team. "Google has an additional responsibility as the host of the Play store to ensure that bad actors aren't permitted to flourish at the expense of the consumer, many of whom are from vulnerable populations, like young people."

And, as Mozilla also points out, Google – which has a profit motive – "has not devoted the resources necessary to counter the threat."

Google has unsurprisingly criticized the report.

[12]

"This report conflates company-wide privacy policies that are meant to cover a variety of products and services with individual Data Safety labels, which inform users about the data that a specific app collects," a spokesperson told The Register . "The arbitrary grades Mozilla Foundation assigned to apps are not a helpful measure of the safety or accuracy of labels given the flawed methodology and lack of substantiating information." ®

Get our [13]Tech Resources



[1] https://foundation.mozilla.org/en/blog/mozilla-study-data-privacy-labels-for-most-top-apps-in-google-play-store-are-false-or-misleading/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y-iY0Bv@MGhAFEComRXk3gAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://foundation.mozilla.org/en/campaigns/googles-data-safety-labels/

[4] https://www.theregister.com/2023/02/22/texas_meteorite_nasa/

[5] https://www.theregister.com/2023/02/22/cloud_repatration_savings_calculated_basecamp/

[6] https://www.theregister.com/2023/02/23/microsoft_edge_banner_chrome/

[7] https://www.theregister.com/2023/02/23/zhurong_rover_mars/

[8] https://www.theregister.com/2023/02/22/titanic_nfts/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-iY0Bv@MGhAFEComRXk3gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-iY0Bv@MGhAFEComRXk3gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y-iY0Bv@MGhAFEComRXk3gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y-iY0Bv@MGhAFEComRXk3gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



I love how the word 'sharing'

Neil Barnes

Has become synonymous with 'selling'.

wiggers

I use the DuckDuckGo browser that has an app tracker-blocker. Astonishing to see the number of tracking attempts. Santander's app is the worst, 10,000-20,000 in a day most days. When I've raised this with them they seem completely clueless, mutter something about essential cookies. One app, Eufy Clean, they didn't even know the app had trackers until I pointed it out to them!

devin3782

I complained to lloyds bank about all the tracking they were doing on their website and was told "Its for your security" even my personal bank statement data is pulled from a CDN

imanidiot

"This report conflates company-wide privacy policies that are meant to cover a variety of products and services with individual Data Safety labels, which inform users about the data that a specific app collects"

Because those company wide policies should be informing those individual Data Safety labels and if the policies are shit the labels will be too?? Maybe?

I call bullshit

Pascal Monett

" This report conflates company-wide privacy policies that are meant to cover a variety of products and services with individual Data Safety labels, which inform users about the data that a specific app collects "

You put a Data Safe label on the Facebook app, ergo you are wrong.

How many billions?

ludicrous_buffoon

We asked to manage our data privacy, not have our perceptions of data privacy managed by PR hacks. Somehow that was misheard by the advertising corporations.

Q: What does a WASP Mom make for dinner?
A: A crisp salad, a hearty soup, a lovely entree, followed by
a delicious dessert.