{"id":50506,"date":"2022-08-02T21:47:54","date_gmt":"2022-08-02T13:47:54","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=50506"},"modified":"2022-08-02T21:47:57","modified_gmt":"2022-08-02T13:47:57","slug":"life-hacks-from-kaspersky-on-how-to-strengthen-google-privacy-controls","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/08\/02\/life-hacks-from-kaspersky-on-how-to-strengthen-google-privacy-controls\/","title":{"rendered":"Life hacks from Kaspersky on how to strengthen Google privacy controls"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Google recently launched a new privacy section called Data Safety, and it now <a rel=\"noreferrer noopener\" href=\"https:\/\/www.theverge.com\/2022\/7\/17\/23259385\/google-play-store-developers-accurate-app-data-collection-information-safety\" target=\"_blank\">appears<\/a> that another security section \u2013 App Permissions \u2013 is hidden from users. It seems that moving forward, Google will rely solely on developers and their responsible actions in relation to the Data Safety section.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In light of the new rule, Kaspersky experts explore possible risks for users and how the situation will change in the future:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>The permission model in Android has become more complicated over time. Sensitive permissions are now dynamic, and requested while the application is running. In addition, most permission values no longer include just \u201callowed\/not allowed\u201d options but additional ones, depending on the permission itself. For example, \u201callow only while using the app\u201d, \u201cask every time\u201d, \u201cnot allowed\u201d. This makes the process of managing apps\u2019 permissions and accessing personal data more accurate and reduces the risk of leaking any sensitive information.<\/li><li>In general, the Google initiative helps users check what will happen to their personal information and brings more clarity to the understanding of all stages of data processing. Users also have the ability to abandon the app in favor of an alternative, if they believe that the disclosure of data is unreasonable.&nbsp;<\/li><li>Data Safety and App Permission sections relate to Google Store information that the user should receive before installing an app. Nevertheless, if some points in this section cause concern, users still have the option to manage permissions on their devices in the Settings app under Apps. Moreover, apps have no access to any APIs or personal data before being installed on the device, so confidential information will be protected and kept private, ensuring there is no recourse for users.&nbsp;<\/li><li>As for further improvements to personal data protection, the next steps could include not just controlling app access to sensitive information (such as received, used and \u201cforgotten\u201d data) but understanding its future fate (such as saving, storing, transferring to third parties etc.). In particular, key aspects could relate to:<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">a. What data an app collects (and not just one-time access, but future storage. It must have a purpose)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">b. Where does app transfer such information &#8211; to whom, why and under what conditions?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">c. Handling &#8211; an explanation to the user, what access to data is necessary for the app to operate (without which it cannot work), and what is optional<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">d. Additional information &#8211; such as whether there is the ability to revoke or delete information, or the app and whether data is encrypted during transmission, etc.<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"5\"><li>Another practice that can lead to enhanced user data protection is providing more checks (e.g., a compliance audit) to ensure a high level of defense and a clear way of processing sensitive information. We see that Google is making steps in this direction by connecting to <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/github.com\/OWASP\/owasp-masvs\">MASVS<\/a>.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Additional tips and lifehacks from Kaspersky on how to strengthen privacy controls:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>A good option is to choose and install <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/android-security\">a reliable security solution<\/a> which provides users with features that let them optimize storage space on their devices. It is also a good option for users to view the list of apps installed on their devices, see which ones they don&#8217;t use, uninstall them, and free up storage space on their devices.<\/li><li>It\u2019s better to avoid installing browser extensions unless you really need them. Carefully check the permissions before you allow them. The full list of permissions is available in the \u201cSettings\u201d page \u2192 \u201cApps\u201d \u2192 \u201cAbout this app\u201d section \u2192 \u201cPermissions\u201d.<\/li><li>A safe practice is also to update an operating system and important apps as updates become available. Many safety issues can be solved by installing updated versions of software.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>It seems that moving forward, Google will rely solely on developers and their responsible actions in relation to the Data Safety section.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":50507,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[337,286,101,54,2103,96,2727,1656],"class_list":["post-50506","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-google","tag-it-security","tag-kaspersky","tag-security","tag-security-breach","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/50506","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=50506"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/50506\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/50507"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=50506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=50506"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=50506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}