Feeds

Australian government apps access smartmobe cams but 'don't film you'

Department of Human Services says its apps need cameras to deliver better services

Boost IT visibility and business value

Australia's Department of Human Services (DHS) says apparently-excessive permissions sought by its mobile apps are necessary for service delivery, and don't put its customers' privacy at risk.

Last week, The Register quizzed the department over broad permissions sought by self-service apps offered for various DHS services, including income support payments agency Centrelink, health care agency Medicare and family support payments.

Having noted a complaint by a Twitter user that asking for access to a phone's camera “to take pictures and videos” seemed excessive, we checked out the permissions sought by the apps, as shown in the screen captures below.

In addition to seeking permission to use the camera, the apps ask for:

  • Personal information – Adding / modifying calendar events, sending e-mails and reading calendar events;
  • Account access;
  • Reading phone status and ID; and
  • Coarse location.
Centrelink App asking for camera permission
Centrelink Android Permissions

While The Register doesn't view this in the light of government conspiracy, excessive permission-seeking by apps is a serious problem. Permission handling recently turned up serious vulnerabilities, and developers often seem to opt for a default “ask for everything” attitude to permission-seeking.

The DHS has told The Register it doesn't misuse the data, and it believes that the permissions it seeks are necessary for the operation of its apps. In an e-mail, a spokesperson said: “Some permissions are necessary to allow the Express Plus app to work effectively with your device. The department does not use or keep personal information stored on customers' phones for departmental purposes.”

Its specific responses to permissions sought are that: location is required to give correct directions to offices, and is not stored by the DHS; phone access is required to allow you to contact the department while using the app, and calls are not logged; personal information access is required so the app can add appointments to the calendar, and the department says it retrieves no details.

This isn't the first time the Department has had to address these concerns: it posted this privacy notice in December when similar questions arose on social media, which got discussed at Hoax-Slayer. ®

Boost IT visibility and business value

More from The Register

next story
Just TWO climate committee MPs contradict IPCC: The two with SCIENCE degrees
'Greenhouse effect is real, but as for the rest of it ...'
Adam Afriyie MP: Smart meters are NOT so smart
Mega-costly gas 'n' 'leccy totting-up tech not worth it - Tory MP
'Blow it up': Plods pop round for chat with Commonwealth Games tweeter
You'd better not be talking about the council's housing plans
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.