Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's no way that I trust the developers of a company like Ticketmaster to install their app on my device.


What is the worst that can happen? I have it installed on my iPhone and deny whatever permissions it asks for.

I have enough confidence in the sandbox that "installing an app" is basically never an issue (though I don't out of the principle that most things companies have apps for just shouldn't be apps).


> What is the worst that can happen?

I don't know the worst, but juice is not worth the squeeze in my opinion. If you recall, Ticketmaster was just recently hacked, so the worst pretty much happened in that any data they had collected on their users is potentially been leaked. So if they can't protect that data, then I'm not participating in giving them data.


Sure, but the data you give them is pretty much a condition of attending their shows, not whether you use their app, Chrome, or a PC in the library to buy the ticket. Regardless, they will get some contact and basic financial info for you unless you avoid all their concerts (which is certainly a principled and defensible choice!)


They do not need to know my address, my phone number, credit card number or any of the other BS that "they need" including my name. Their website has a ton of trackers uBlock blocks, so their website is trying to collect even more data than what their "forms" request.


How would an iPhone app (I don’t know about android) collect any of that?


I mean...they tell you they do in the listing in the AppStore. Like, how are you not realizing this?


Of course they list those things as things the app 'collects,' because the app literally asks you for all that info as billing info when you buy tickets in that app and when you provide it, it collects it. The app isn't somehow extracting your personal info from some API. Yes, it's probably got the same adtech as the next app, but overall it's just collecting what you tell it.


How though? My phone does not contain my address, or my credit card number.


You don't trust your OS to sandbox it? With a threat model like that, I wouldn't use any apps other than the browser


If anyone is in the situation that they need to put an untrustworthy app on their android device, the "work profile" feature can segment it off further.

Insular is an app that lets you create and manage one of these profiles on the device itself: https://gitlab.com/secure-system/Insular


Work profile is really neat, yeah. I'm using Shelter for this, it's quite nice: https://f-droid.org/en/packages/net.typeblog.shelter/


Maybe you are using a fully open phone, but mine has an OS made by Google and almost every app tracks my location without my consent.


For the past 9 years, Android has allowed users to disable location permission per app. More recently, you can choose to share "noisy" location, which just provides an approximation of your location.


Google will never stop spying themselves but will give you the ability to stop their competitors from spying on you. Heh..


I'm an app dev. How exactly would I track your location without your consent?


For example, based on my IP address, nearby wifi networks, and camera footage.


> IP address

Great. So an app can plug my IP address into a geolocation query, and might ultimately determine that I'm somewhere in $city. Or maybe the next city over. Or maybe half a continent away.

But sure, this "works" without consent, since there is no extra step to enable networking for an app.

> nearby wifi networks

This doesn't work without consent.

> camera footage

This doesn't work without consent.


Web apps also get your IP. Why aren't you using a VPN if you care about that?

Web apps can also get the rest if you click accept when it asks for camera access. What exactly do you lose by installing an app?


From the AppStore:

Data Linked To You:

Purchases, Location, Search History, Usage Data, Financial Info, Contact Info, Identifiers, Sensitive Info.

Nope Nope Nope.


That explains nothing. I'm pretty sure it's talking about info that you type into form fields in the app. Same reason FB "links" your health info even though it has no access to the health info stored by your OS.

The same applies if you use their website. It'll still ask for that info with a web form.


> Same reason FB

...is not installed on any of my devices



Yeah that has literally nothing to do with their app. If you submitted your data on their website, it'd be leaked just the same


You're implying that the data from the app is stored in a different more secure manner than the data from the website? That makes zero sense. The fact that they got hacked and is the only thing that matters, not which mode of input you provided the data they did not protect.


No, I'm asserting that the app acquires as much data as the website (ie. whatever you typed into their forms) and it gets leaked all the same. Refusing to install the app makes no sense if you still use the website


An app absolutely can track more data than a website. You don't have the website open/active on your phone at all times, but you have the app installed at all times, even when it's not running.

You do know that apps can record data in the background, right?

A website is also sandboxed by your browser in a much stricter manner than an app is on your phone, at least by default.

I don't have specific information on the Ticketmaster app here, but to say that an app is the same as website from a tracking perspective on a phone is absurd.


I'm an app dev. What can I record in the background? What can I track?


If you're an app dev you're more qualified than me to answer that question.

Perhaps you'd like to re-frame your comment or ask a different question?


My point is that you and the other guy are just making stuff up and spreading misinformation. At the API level, an app that doesn't have the user's explicit permission to get location, camera, run in the background, etc is not that different from a web app. My question was obviously rhetorical.


There you go, getting to the meat of it..

So your position is that an app installed on my phone is not able to track or collect any more data, and does not have access to any other information, than a website that I load in my device browser (assuming I log into that website with the same credentials I use in the native app)?

I agree that this might be true in some cases. Note that I never said or implied that an app could do things without permission - but my fault if that wasn't clear.

Now, that said, would it perhaps be fair to say that the average user is much more likely to grant additional permissions to a native app on their phone than they would to a website?

If a website asks for your location, or access to the camera or to your contacts or whatever, I think many people would refuse. There's still a sense that a website is "out there" on the Internet, and you shouldn't necessarily trust it.

But when an app you've installed on your device asks for these things, in order to "operate properly" or provide functionality, then I think people are much more likely to grant it.

After all they've installed the app on their device, they've already trusted the vendor that much, it's only an incremental step at this point.

And once the device does have this elevated access, and access to more data, then there are absolutely more opportunities to collect data on users without their understanding.

I say "understanding" here rather than "consent" because typically consent is given via some long and complicated T&Cs that no one reads. Which is of course on the user, but again if you don't grant permission in the first place (because you're on a website not an app), it's not a problem.

And we have historically seen that some companies (not all companies of course) take advantage of this app access to collect data for themselves without your knowledge. I hope that part isn't up for debate here..




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: