Tuesday, May 16, 2017

ZerAppa iOS apps – Twitter sign-in requires “full access to Direct Messages”

Numerous ZerAppa apps
Date: 05/16/2017

Description:

Looks as if many (perhaps all) apps released by ZerAppa require “full access to Direct Messages” if you want to use your Twitter credentials to create a new account inside of the app.

That’s asking for a permission that very few apps ask for. It’s also something that large corporations have routinely had to apologize for - namely, trying to trick users into granting them access.

This should be changed, and small restaurants, bars or exercise places shouldn’t be giving the impression they are able to peek into the private messages of users who use Twitter to create accounts.

Please see the attached screenshots taken from the HonestAbe’s Tap & Grill app.

I’m not OCD enough (at least not yet!) to download all 121 apps released by ZerAppa to see if they all require this permission. But, since the first seven I downloaded all did require this permission, I am willing to guess this is pretty common with apps released by ZerAppa.



Steps to Reproduce:

1.     Download Honest Abe’s Tap & Grill for iOS
2.     Launch the app, dismiss the pop up messages
3.     Select the settings icon in the upper right hand corner of the screen (above Abe)
4.     From “Accounts” select the “Connect >” next to Twitter
5.     Note that “full access to Direct Messages” is a requirement for creating an account using your twitter credentials

Result: Numerous apps released by ZerAppa require “full access to Direct Messages” for users who want to use their Twitter credentials to create an account

Expected: The requirement of “full access to Direct Messages” should NOT be required for users who want to use their Twitter credentials to create new accounts in ZerAppa apps

Select the settings option in upper right...

Choose the connect option for Twitter...

No comments:

Post a Comment