Jump to content

Recommended Posts

Posted (edited)
I hope that the ICO will be looking at this.

 

And when they do, they'll find all the affected users granted the app permission to do this.

 

Yes, the wording could make it clearer that might mean humans not just AI, but I would prefer to see an at-a-glance summary what permission I'm granting, rather than read long caveat-filled paragraphs saying what I might be granting.

Edited by enjay
  • Thanks 1
Posted
And when they do, they'll find all the affected users granted the app permission to do this.

+1. If the user just clicks the 'Allow' button without reading what the app does once granted permission it's not really Google's fault.

 

www.blog.google/technology/safety-security/ensuring-your-security-and-privacy-within-gmail

 

We make it possible for applications from other developers to integrate with Gmail—like email clients, trip planners and customer relationship management (CRM) systems—so that you have options around how you access and use your email. We continuously work to vet developers and their apps that integrate with Gmail before we open them for general access, and we give both enterprise admins and individual consumers transparency and control over how their data is used.

 

You can visit the Security Checkup to review what permissions you have granted to non-Google apps, and revoke them if you would like. For G Suite users, admins can control which non-Google apps can access their users’ data through whitelisting.

 

Keeping your data secure is our top priority, so we want to provide you with details about our vetting process and user controls for both enterprise and consumer accounts:

 

gsuite_gmail_security_checkup_third_party_.max-1000x1000.jpg

  • Thanks 1
Posted

I guess this will come down to whether a message saying "sample application can view your email" tells you a human might read it, versus an AI.

 

Or possibly whether the intended purpose was made clear. For example, the cycling computer I use has a linked mobile app. That app has access to my phone, SMS and contacts so when I get a call while cycling, the computer "rings" and tells me who is calling, or displays a text message. This is fine, and I'm happy for that purpose BUT I wouldn't be happy if I found out staff at the company were reading my messages, even though technically I've given permission for that.

 

Maybe a good compromise would be to keep the permission-granting process simple (as per the screen shot above) but require app developers to explain/justify the permissions in the app description on the Store. I've seen some which do that, and say "this app will ask for access to your phone, but this is why, and we promise we won't call anyone".

Posted

I've seen plenty of comment online around this story, where people are essentially saying "Well duh! Blame the users".

 

I think it's understandable for someone approving an app permission to think that it's "the app" that is accessing email data, rather than "some company, with staff and everything". Especially since that's how it's presented. Most of us here would understand that the two are hard to separate, but we're probably not normal.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...