Live data from Hacker News

Google collects metadata from Android phones

borncity.com

71–80 of 263 posts

Re: Google collects metadata from Android phones

#71

Earlier quoted context omitted.

All thanks to the users of advertising companies who trade privacy for free or cheaper stuff. We used to have paid, more private tech. Still do actually. Almost no money in it with bankruptcies and acquisitions by shady firms more common than getting on Global 2000.

This feels a bit like blaming unsafe working conditions and 12-hour work days at the beginning of the industrial revolution on workers, because they signed the contracts (this was the prevailing narrative from factory owners at the time too). At some point, society came to the conclusion that the workers and factory owners were not on equal footing, and so rules were instated, despite strong protests from the factory…

Also remember that the factory owners at the time screamed that they could not afford any changes and it would bankrupt them and destroy the economy.

Re: Google collects metadata from Android phones

#72

Half the enterprise apps I know stop working on cyanogen. Is there an alternative? Also is there a way to separate work and personal phone usage on a single device? Tools like mobile iron seem to demand all of my info be made available for whatever it deems fit for the corporate I work for.

Depending on your device, you may be able to multiboot. See https://play.google.com/store/apps/details?id=com.tassadar.m...

Re: Google collects metadata from Android phones

#73
post #32

It says this right before the bolded part: "When you use our services or view content provided by Google, we automatically collect and store certain information in server logs. This includes:" I am not sure this applies to regular phone calls, no? Can someone explain here because I am certainly not understanding. Is this only for, say, Google Voice or related services that they have?

I actually imagine it does apply to most regular phone calls. Google offers a reverse lookup service in recent versions of Android. It fills in the name of the caller if it's not in your address book.

In all honesty though, you are prompted about whether you want to use this feature.

Re: Google collects metadata from Android phones

#74
post #12

Earlier quoted context omitted.

Part of the problem is the large percentage of apps that are now tied to proprietary Android, and won't run without Google Apps installed. Even Microsoft apps like Outlook and Skype won't load without Google Play Services installed. (The version of Skype on the Amazon Appstore is around a year old, and won't even take my login credentials.) So even if you find a relatively safe Android version to use, you're getting…

Hmm... so effectively Android is no longer open.

It was never really open.

And even though it uses Linux as kernel, even that doesn't matter.

The API surface that NDK code is allowed to use is so constrained that they could replace the kernel with something else and only OEMs would notice.

Re: Google collects metadata from Android phones

#75

For what it's worth, I have my doubts that this applies to a generic call/sms on any old Android device. I would think it's more likely to apply to services such as the Hangouts calling or Google Voice, and probably Google Fi, all of which make sense to collect that data, but the privacy policy doesn't absolve itself of that. > When this Privacy Policy applies > Our Privacy Policy applies to all of the services offer…

The whole point of big data is to collect whatever is available and reason about how to use it afterwards. So I guess we can be pretty sure that Google collects as much as they can.

Re: Google collects metadata from Android phones

#77

Earlier quoted context omitted.

All thanks to the users of advertising companies who trade privacy for free or cheaper stuff. We used to have paid, more private tech. Still do actually. Almost no money in it with bankruptcies and acquisitions by shady firms more common than getting on Global 2000.

This feels a bit like blaming unsafe working conditions and 12-hour work days at the beginning of the industrial revolution on workers, because they signed the contracts (this was the prevailing narrative from factory owners at the time too). At some point, society came to the conclusion that the workers and factory owners were not on equal footing, and so rules were instated, despite strong protests from the factory…

"This feels a bit like blaming unsafe working conditions and 12-hour work days at the beginning of the industrial revolution on workers, because they signed the contracts (this was the prevailing narrative from factory owners at the time too)."

That would make more sense if various companies didn't sink $1+ billion into more robust systems and software over the decades that most users & developers intentionally avoided in favor of what was faster, cheaper, supported buzzword/feature X, and/or was known unreliable/insecure. They make the same tradeoffs today. Look at use & tradeoffs of Facebook Messenger vs WhatApp vs Signal vs Threema [1]. Even when cheap/free and easy, vast majority will not make slightest effort for increased security and privacy.

[1] Not endorsing Threema so much as to say it was quite marketable & good example of what should get more adoption if users aren't to blame.

Itanium got posted here recently, too. It had enhanced reliability, stack protection, read/write/execute per page, and memory key isolation if one wanted it. Most server software that was mission critical continued to run on Xeon x86 instead of leveraging improvements in Itanium even when portable source was available for mere re-compile to Itanium. Why? Xeon was cheaper and took no extra effort.

Rinse, repeat for all kinds of software and tooling. There's often supply but little demand that pays. Which sucks extra here given high reliability or security costs more not less for producers. There has to be sustained demand that will pay at least 30-50% premium to develop each component or app. Since there's not, the companies are entirely justified in producing unreliable, insecure or surveillance-oriented garbage for people that exclusively use or buy such things. And the buyers are to blame wherever there were clear alternatives that were inexpensive given their choices collectively decide the issue.

"Perhaps it's time for regulation to solve this dilemma?"

I supported that on Schneier's blog with specific points showing where market consistently fails (even for itself) and how regulation would help:

https://www.schneier.com/blog/archives/2011/09/an_interestin...

Despite low demand, I also actually write a counterpoint justifying continued focus on niche that cares about quality/security with recommendations for "low-cost but high-value" practices to deliver that profitably as a differentiator. What's in this post is an example of how my software liability argument in other one might play out. Regulations would enforce stuff known to knock out problems consistently to form a better baseline without driving up cost or having vague stuff prone to frivilous lawsuits.

https://www.schneier.com/blog/archives/2013/03/is_software_s...

Re: Google collects metadata from Android phones

#78
post #17

before we jump to conclusions not based by facts..BB collects same info as part of device metric measuring..its a common secret that most mobile OSes both open source and closed source do this.. While BB gave Canda authorities access..Google by default does not..

Are we really comparing BB to Android? http://cdn.bgr.com/2016/05/screen-shot-2016-05-23-at-9-03-37...

We're not comparing market share, but privacy policies.

Re: Google collects metadata from Android phones

#80

Half the enterprise apps I know stop working on cyanogen. Is there an alternative? Also is there a way to separate work and personal phone usage on a single device? Tools like mobile iron seem to demand all of my info be made available for whatever it deems fit for the corporate I work for.

If the phone is rooted, you should be able to just uninstall the Google Apps. For good measure, you could also block Google's IP-addresses in the hosts-file.

As for ways to use the same device for work and personal, newer Android-versions (I believe from Lollipop onwards) have the option to create different user-profiles. I think that would work, although I've never actually used them myself...

Post reply on HN