Sunday, June 14, 2020

Flyhomes Real Estate app for iOS: Duplicate links in text messages and emails

iOS 13.5.1
Flyhomes Real Estate app for iOS (version 2.8)
Date: 06/14/20

Description:

There's a minor problem with the Flyhomes app for iOS.

There are duplicate links to the app in the auto-generated text message and emails from different properties. Please see the screenshots below.

Steps to Reproduce:

1. Download and launch the app
2. Select an property that is for sale
3. Select the share option
4. Select either the text message or email options
5. Note that there are duplicate links in both

Result: There are duplicate links in the auto-generated text message and email messages created by the app

Expected: There should not be duplicate links




Head to any property listed in the app...

Duplicate links in the text message...

Duplicate links in the email!

Tuesday, June 9, 2020

BIGO LIVE for iOS: BIGO LIVE's Privacy Policy and Terms and Conditions links are dead on Twitter Oauth page

iOS 13.5
BIGO LIVE for iOS (version
Date: 06/09/20

Description:

I just wrote about I what I believe to be the overly intrusive Twitter permissions requested by the BIGO LIVE app for iOS.

There's another issue. When a user exits the iOS app to BIGO LIVE's Twitter Oauth page, there are two dead links. BIGO LIVE's "Privacy Policy" and "Terms and Conditions" links on the Oauth page are dead.

Take a look at this screenshot:

The arrows in the screenshot are pointing to two dead links. These links are supposed to link to BIGO LIVE's Privacy Policy and Terms and Conditions. This is provided as one last opportunity for the user to browse these conditions, before handing over authorization for BIGO LIVE to access the user's Twitter account.

These links really should be working. The fact that they are not working when the app is asking for such intrusive access is troubling.

Steps to Reproduce:

1. Download the app
2. Choose the Twitter option to create an account
3. From BIGO LIVE's Twitter Oauth page, click on the "Privacy Policy" or "Terms and Conditions" links

Result: The "Privacy Policy" and "Terms and Conditions" links on BIGO LIVE's Twitter Oauth login page do not work - they do not link to BIGO LIVE's legal information

Expected: The "Privacy Policy" and "Terms and Conditions" links on BIGO LIVE's Twitter Oauth login page really should be working

BIGO LIVE app for iOS: Overly intrusive Twitter permissions required to create an account or share content

iOS 13.5
BIGO LIVE app for iOS (version 4.36.1)
Date: 06/09/20

Description:

BIGO LIVE is a live streaming app that is currently #35 in the social media networking section of the Apple App Store. I had to do a little research to find out more about this company.

According to an article I stumbled across, the term "BIGO" is acronym that stands for "Before I Get Old."

However, one thing really stuck out to me after I download the app. I saw that like TikTok before it, it had an unusual set-up to share videos via Twitter. In my opinion, there appears to be a concerted effort to allow Twitter users to browse videos, and then hook them into granting third party access to their twitter accounts if user wants to simply share a video.

Take a look at what BIGO LIVE requires of people who try to either share content via Twitter, or who want to user their Twitter credentials to create an account:

Their Twitter Oauth page requires Twitter users to allow the BIGO LIVE app to "Send Direct Messages for you and read, manage, and delete your Direct Messages."

Yikes! Full and complete access to Twitter DMs. Access to anything and everything that might be in your average millennial's Twitter DMs is what's required to sign up for this app. Not only that, but full DM access is required to even share a video from the app to Twitter!

Here's a video of the Twitter Oauth a user (who created an account using a different method) sees when trying to share a video to Twitter from inside the BIGO LIVE app...




Last Summer, I spotted the same exact behavior and set-up with TikTok. I sent an email to TikTok corporate. I knew they would just ignore an email, so I made sure to overtly CC European based privacy regulators and American academics. And, of course, TikTok quickly removed the option and claimed that it was a mistake to even ask for the permission.

This probably will also be the case with BIGO LIVE. I will shortly draft an email to BIGO LIVE's legal department. I will make the same arguments that I did with TikTok, and i'll CC some of the same people.

So, wait and see. Perhaps these permission requirements will be changed soon. Perhaps not. We'll see.

Steps to Reproduce:

1. Download and launch the BIGO LIVE app for iOS
2. Choose the Twitter option for account creation
3. Note that the Oauth page requires read/manage/delete direct message access to Twitter DMs

OR:

1. Launch the app
2. Create an account using Google or Facebook login
3. Browse videos
4. Select the share option
5. Select Twitter
6. Head to Oauth page and notice that the app requests read/manage/delete direct message access to Twitter DMs

Result: The BIGO LIVE app for iOS requires full read/manage/delete direct message access to the Twitter direct messages of users who want to user the Twitter credentials to either create an account or share a video

Expected: The requirement of read/manage/delete access to twitter direct messages is too intrusive. I have yet to read any valid justification for a third party app requesting this access. I believe that there is even less reason for a streaming app targeted to young people to request this

Sunday, June 7, 2020

Walmart app for iOS: No way to exit out of the Terms of Service page when it is first entered

iOS 13.5
Walmart app for iOS (version 20.22.1)
Date: 06/07/20

Description:

There's a minor problem with the Walmart app for iOS. I first noticed this some weeks ago, when I was playing around with the app.

At first I thought that this problem was totally random. 

However, after playing around a bit, I figured out a way to easily and consistently reproduce this problem. 

The problem is with the 

Here's a Tweet that includes a video of the issue:


Steps to Reproduce:

1. Download the app fresh, for the first time
2. Select "Skip" to advance through the tutorial 
3. Manually enter in a zip code ("99107" as an example)
4. Select the "Sign In" option at the bottom of the "Hi! Where do you want to shop?" screen 
5. Select the "Create an account" link
6. From the "Create Account" screen, select the "Terms of Use" link

Result: the "Terms of Use" page that is accessible from the initial account creation screen doesn't seem to have a way to back out of it 

Expected: the "Terms of Use" page that is accessible from the initial account creation screen should always have a way to back out of it 

Select the "Sign in" option here...

Select the "Create an account" option...

Select the "Terms of Use" link....

There doesn't appear to be a way for the user to back out of this Terms of Service page!

 

Thursday, June 4, 2020

Bronx House Pizza app for iOS: Link to Instagram account is bad

iOS 13.5
Bronx House Pizza app for iOS (version 1.1.84)
Date: 06/04/20

Description:

Minor problem with the Bronx House Pizza app for iOS.

The link to the Bronx House Pizza Instagram account doesn't work.

There is a valid and active Instagram account for Bronx House Pizza:

Steps to Reproduce:

1. Download and launch the Bronx House Pizza app for iOS
2. Select the Instagram option

Result: The Instagram option in the app does not lead to the Bronx House Pizza Instagram account

Expected: The Instagram option in the Bronx House Pizza app should lead to the Instagram account

Wings Over Pittsburgh app for iOS: Facebook link leads to Content Not Found

iOS 13.5
Wings Over Pittsburgh app for iOS (version 1.1.84)
06/04/20

Description:

There's a minor problem with the Wings Over Pittsburgh app for iOS.

The link to the Wings Over Pittsburgh Facebook page is broken.

Here's what I see when I exit the app:



It should lead to Wings Over PIttsburgh's official Facebook page.

Steps to Reproduce:

1. Download and launch the Wings Over Pittsburgh app
2. Select the "Facebook" option under "Home"

Result: The link to the Wings Over Pittsburgh Facebook page does not work - exiting the app leads to a "Content Not Found" page

Expected: The link to the Wings Over Pittsburg Facebook page should work