Live data from Hacker News

Google collects metadata from Android phones

borncity.com

251–260 of 263 posts

Re: Google collects metadata from Android phones

#251

Earlier quoted context omitted.

On that point, I very recently discovered [1] that connecting an iOS device to an Exchange account via ActiveSync enables the organization's Exchange administrators to remotely wipe the entire contents of the device - not just the content actually provided via the account, but everything . I am astonished and disappointed that Apple saw fit not to warn the user this could happen. Even Google gets this right; when you…

Current versions of iOS do make it clear. http://9to5mac.com/2016/03/02/ios-9-3-makes-it-abundantly-cl...

Well, I'm running 9.3, and I never saw that message, or any other warnings about Exchange connections, while I had my phone connected to work email.

Is all this stuff only a concern when the device is enrolled via MDM? That seems improbable; the (several) sources I've found on the subject don't mention MDM in any context, but just warn that Exchange connection = remote wipe capability. Similarly, while I had my phone connected via Exchange, I visited the devices page in Outlook Web Access and saw that the "Wipe" option was enabled for the device.

Re: Google collects metadata from Android phones

#252

Earlier quoted context omitted.

That's actually a good example. Many honest people and criminals alike who value privacy are buying feature phones with no background apps, GPS turned off, and sometimes battery out. Been going on a long time. Great improvement in privacy or odds someone (outside nation-state) is going to remotely snatch your secrets. There's also regular press releases showing smartphones have lots of hackers targeting them. Yet, pe…

This is a very good reply. My hat off to you. That being said, could you give us a good example for these privacy-enabled phones and apps? I am willing to make a collection out of these and write a guide on hardening Android. And I am not just talking apps that are incredibly hard to use; I mean the better generation of them who are actually mass-audience-friendly. Of course we must not forget that Android phones cou…

I'm going to focus on voice as messengers are all over the place. People originally wanted secure voice. They started out as custom or value-added devices that, if worth a crap, often had special protections like dedicated IC's for crypto and TEMPEST protection:

https://electrospaces.blogspot.com/2012/06/highly-secure-mob...

Those were usually very simple. A good thing compared to modern ones. They all cost in the $1,000-3,000 per unit range due to extra costs and low volume. Sectera Edge was probably most secure and rugged. Cryptophone was easy to use plus had nice features like hardened Windows and published source for crypto. You basically called the person, read out what was on your screen, listened to them do the same, and listen to each other's voices to make sure you recognized them. It was favorite outside of just defense use. Switched to Android later. That's the demo I found.

http://www.cryptophone.de/en/products/mobile/

https://www.youtube.com/watch?v=RchMr2B1KuU

Note: The letters you see are the codes you read.

These were pretty expensive. So, companies started developing software for regular phones... often one or two models... that turned them into encrypted phones optionally with hardening. Prior list had some. SecureStar (PhoneCrypt), SecureGSM, and Cellcrypt come to mind. Eventually, recognizing encryption wasn't enough, this segment sort of combined with Android and other software to produce dedicated phones that were cheaper than older cryptophones. Well, some of them haha. Two examples with second being the open Redphone.

https://www.youtube.com/watch?v=8TIBtOdioYE

http://www.pcmag.com/article2/0,2817,2415410,00.asp

Examples of the phones produced include Boeing Black, Bull Hoox, the Cryptophones, and recently the Blackphones w/ Silent Circle. Blackphone was among the cheapest we saw at regular, smartphone prices. It was common for crypto phones to come with voice and SMS at least. Blackphone added quite a few privacy-oriented apps over most to be all-in-one solution. I remember that as an advantage.

https://www.silentcircle.com/products-and-solutions/devices/

Far as messengers, we have good open ones these days so I mostly forgot the others outside cryptophones and above. Signal is super easy, free, and quite secure. Main recommendation. There was also ChatSecure and TextSecure. Given open ones, no reason to trust commercial ones since subversion and BS is high in this industry. Still worth looking at them for how they do usability aspect to increase adoption. I know Threema got significant adoption. Worth looking at. I'm open to others' suggestions here on crypto apps with good security protocols that also have great usability. Thing is, if it's really end-to-end, usability is inherently lower than centralized one due to verification aspect. Anything truly frictionless is suspect in my view with Signal representing the high end of what I'm expecting.

Bruce Schneier, for Congressional submission, did ask us all to list as many crypto products as possible for him. You might find something of interest there. Here's that thread:

https://www.schneier.com/blog/archives/2015/09/wanted_crypto...

https://www.schneier.com/blog/archives/2016/02/worldwide_enc...

Note: Also, the original way we did this outside expensive cryptophones is called Voice over Secure IP (VoSIP). That means you set up the strongest VPN (or link encryptor) between two points that are communicating. Then, you force a normal app to go through it. One can automate this process so it's painless for users. Often stronger than average secure voice app given what scrutiny goes into some implementations of transport-level security. Or existence of dedicated lines between branches.

"I view this sort of like the people who got away from the Matrix in the movies; as the Architect and the Oracle implied, as long as these people aren't an escalating threat for the entire system, they're allowed to live however they choose."

Possibly but don't count on it. Depends where you live. The U.S. increasingly targets harmless citizens with anything it can up to and including just stealing their money without charges under civil forfeiture laws. Just using Tor or crypto is grounds for NSA to put increased scrutiny on you per the leaks. So, this isn't guaranteed. Keep real secrets off online or wireless devices period. Face-to-face only. The rest we have to keep doing more and more to protect. Can incrementally deploy it, though, where sales drive increases in not just features but assurance of more of the stack. My recommendation.

"What's your opinion on the Turing Phone and Sailfish OS in general, by the way? Do you think that it gives us a fair progress in the direction of the more snoop-proof end-user tech?"

Let me help you out by showing you what all they have to protect. You can look at this list, look at the marketing/technical material, and usually tell if it's going to be victim to future attacks.

https://news.ycombinator.com/item?id=10906999

By those standards, the above aren't even close. I haven't studied these phones where I can say much more, though. I do like aspects of Sailfish in terms of a more open phone but it's still owned by one company from Wikipedia's description. That one also licenses key I.P. in proprietary fashion. So, there is risk of it being another Google Android situation. Turing Phone article I read on Wired sounds like a pile of marketing BS plus lock-in waiting to happen. People are better off using apps like Signal, Redphone, Cryptophone, or Silent Circle that at least come from people who know what they're doing. Who we know have a track record. That's my (common) initial impression.

Re: Google collects metadata from Android phones

#253

Earlier quoted context omitted.

And imagine the online world loosing both Google and Mozilla. Or development of Firefox, Chrome, and Android slowing to a crawl as they went paid or donation-only. Big companies would win in browser and mobile market by default.

Red Herring. Fixing the funding model is an independent problem. I'm not saying that advertising and software development aren't prresently linked through funding. But the process is _fundamentally_ unbundled, through the vehicle of Free Software development and licensing. The costs for advertising are approximately $500 per year per capita in the developed world (~1 billion persons), plus all the associated privacy,…

"Fixing the funding model is an independent problem."

Oh no, it's a very, intertwined problem. One is only likely to succeed in business using models that are shown to work. A browser, secure platform, and so on is usually tens to hundreds of millions in labor. The only companies that have pulled that off either used premium, licensed software (eg Microsoft) or advertising (the rest). There's scores of attempts at alternative, business models to break into all these ad-dominated markets. Almost none of them work. So, this is important.

"through the vehicle of Free Software development and licensing."

It's possible but few have been built that way. There's a bunch of small players trying in the secure collaboration space. Making almost no money. Used iMessage, Facebook Messenger, WhatApp, and SMS instead. The ones making it, almost none in privacy, seem to be outliers that have lasted quite a while or VC-funded ones that we shouldn't trust due to sell-out risks.

"The costs for advertising are approximately $500 per year per capita in the developed world (~1 billion persons), plus all the associated privacy, surveillance, security, and chilling-effects risks."

Better to look at what it costs to develop top-notch products vs what they make on advertising, proprietary licensing, and FOSS licensing/support. What they make and if it justifies continuing the offering matter more than the $500/yr they probably haven't heard of. It's new to me, too.

"Treating both writing of content (fiction, nonfiction, journalism, research) and software development as public goods could achieve some very strong social benefits (or at least present a different set of problems for us to jaw over on HN, though the concept of a technology startup incubator might also see some ground shifts)."

I agree. It's just that 90-99% of buyers don't consistently for a decade or so.

"Detachable headphones and mics."

Mine and some others' designs call for simple switches that cut power or connection to mic, camera, and so on. That's doable if people want it. I'm also for jumper- and/or crypto-enabled updates of firmware that are tamper-evidence. Also doable.

"Bust out of that box a bit, Nick."

The model I've been considering is to get proprietary vendors to each contribute a bit of their revenue to the development of OSS dependencies. These might even be new proprietary vendors that are starting for the purpose of pushing better, paid software plus new models. The idea is that each of them contribute to say a mobile OS, a SSL library, a Linux/BSD, disk encryption, secure backup, and so on. As they improve and succeed, so do the critical components they are sponsoring. They can include it in the marketing material for customers along with examples like Heartbleed that came from supporting competition that didn't invest in critical infrastructure. So, there's immediate benefit, long-term maintenance, and public good all in one package. Selling the participants is the hard part here.

Note: I also thought getting CompSci people developing bug hunting or code generation tools to use them on these projects with their grant money would be nice, too.

Note 2: We haven't even gotten to the risk of patent suits on these companies whose business models have nowhere near as much money for lawyers or buying patents as those suing. That makes situation more dire at least in U.S..

Re: Google collects metadata from Android phones

#254

Earlier quoted context omitted.

Red Herring. Fixing the funding model is an independent problem. I'm not saying that advertising and software development aren't prresently linked through funding. But the process is _fundamentally_ unbundled, through the vehicle of Free Software development and licensing. The costs for advertising are approximately $500 per year per capita in the developed world (~1 billion persons), plus all the associated privacy,…

"Fixing the funding model is an independent problem." Oh no, it's a very, intertwined problem. One is only likely to succeed in business using models that are shown to work. A browser, secure platform, and so on is usually tens to hundreds of millions in labor. The only companies that have pulled that off either used premium, licensed software (eg Microsoft) or advertising (the rest). There's scores of attempts at al…

The problem is separable in that it is conceptually possible to make organisation for software development independent of the business organisation that uses it. We've had this in the past, we have it now, though typically in smaller pieces. It's largely how Unix was developed (an unlikely consortium of a company which quite literally wasn't allowed to sell the product, but could make use of it, and a group of academic institutions in need of both computing tools and training projects), Usenet, the WWW, Linux, Apache, Debian, and more.

Your point that many Free Software projects make little money (at least as Free Software projects) misses the more salient point that they generally don't need to. Scratching itches, low barriers to collaboration, and solving problems in other application spaces makes this possible.

The giants' very reliance on vast revenue flows is also a vulnerability.

And no, I'm not arguing that costs disappear (though efficiencies do appear), but rather that they're distributed and loaded throughout numerous other organisations and activities making money on their own.

The "90-99% of buyers" problem is precisely why you look at funding alternatives which bypass per-copy market sales. I've been looking into the history of publishing and creative works, it's an interesting space. Patronage, busking/performing, crown sanction (essentially a content tax), BBC tax, etc. Information goods and markets interact very poorly: https://redd.it/2vm2da

(UC Berkely / Google economist Hal Varian has an extremely similar treatment which I ran across recently.)

The detachable headphones and mics comment was a reference to an earlier exchange we had, I thought you might recall it.

Your bust-out-of-the-box model isn't too far from what I'm suggesting for content tax/syndication. Whether voluntary (free-rider problem) or compulsory (politically difficult but possibly inevitable) you're distributing contribution to a shared resource. Much as, say, we ended up with language or the law.

Patent threats are also somewhat diminished through small pockets (less attractive target), or might be addressed specifically via legislation and/or international treaty. Say, something with a different philosophy than the TTP, TTIP, TiSA, and BITS crud being shoved down our throats by Google, Apple, Amazon, Microsoft, IBM, AT&T, et al.

Re: Google collects metadata from Android phones

#255
I’m managing editor of mobilsicher.de (https://mobilsicher.de), the news site this story originated from. We are a relatively new site (launched in Sept. 2015) and only now looked into this.

The fact that it had remained undetected because no one had taken a closer look at it for several years does not mean that the questions we ask are unwarranted.

Peter Schaar, former German federal commissioner for data security and - at the time - chairman of the ARTICLE 29 Data Protection Working Party of the EU, says Google’s practices may even violate fundamental rights under German and European law.

The current German federal commissioner for data security is looking into it because of our reporting, so does the commissioner for data security of the German federal state of Hamburg, which has authority over Google because the company’s German headquarters are located there.

We will hopefully hear from them shortly on how they assess the situation. Also, a request for a statement from the Irish DPC (Google’s EU headquarters are located in Dublin) is under way.

Researching our original story, we of course asked Google to answer our questions on whose data exactly is collected under the provisions of the private policy, what data is collected, for how long, where it is stored and why Google thinks it can justify this data collection and processing on consent to their terms and services alone.

Now, after the story was picked up by dpa, Germany’s largest national news agency, and several influential tech news sites (German language only, Golem: http://www.golem.de/news/ueberwachung-google-sammelt-gesprae... | heise: http://www.heise.de/newsticker/meldung/Google-Wirbel-um-priv...), Google has now issued a statement that poses more questions than it answers. We published our story today (https://mobilsicher.de/aktuelles/google-speichert-telefondat...) and also provided an English language version (Google admits it collects telephony log information, doesn’t specify which exactly - https://mobilsicher.de/uncategorized/google-admits-it-collec...) because we think this discussion is very relevant for an international community.

We are a small team but will keep reporting on this, trying to clarify the legal situation as well as the technical details. For this we’ll be doing more of our own analysis. In case any of you has helpful information, i.e. logs showing telephony data being transmitted to servers, please let us know (m.spielkamp at mobilsicher.de). But please make sure it can be reproduced by us, otherwise we’ll have a hard time using it.

Re: Google collects metadata from Android phones

#256

I’m managing editor of mobilsicher.de ( https://mobilsicher.de ), the news site this story originated from. We are a relatively new site (launched in Sept. 2015) and only now looked into this. The fact that it had remained undetected because no one had taken a closer look at it for several years does not mean that the questions we ask are unwarranted. Peter Schaar, former German federal commissioner for data security…

When is the story about Google storing the emails of all Gmail users coming out?

I've heard rumors they don't even just collect the metadata - they store the entire email! Indefinitely. Even if the sender wasn't using gmail, but included a single Gmail or Gapps user among the recipients, they're said to record the entire email, as well as the addresses of the sender and all the other recipients, who never consented to Google's privacy policy to begin with.

I mean, the scale of the violations, it boggles the mind.

Re: Google collects metadata from Android phones

#257

Earlier quoted context omitted.

This is a very good reply. My hat off to you. That being said, could you give us a good example for these privacy-enabled phones and apps? I am willing to make a collection out of these and write a guide on hardening Android. And I am not just talking apps that are incredibly hard to use; I mean the better generation of them who are actually mass-audience-friendly. Of course we must not forget that Android phones cou…

I'm going to focus on voice as messengers are all over the place. People originally wanted secure voice. They started out as custom or value-added devices that, if worth a crap, often had special protections like dedicated IC's for crypto and TEMPEST protection: https://electrospaces.blogspot.com/2012/06/highly-secure-mob... Those were usually very simple. A good thing compared to modern ones. They all cost in the $1…

The big issue with Signal at the moment, is that it doesn't work on AOSP.

You can't use it without installing closed-source Google Apps (Play Services for GCM at minimum), and means you agree to hand over your phone metadata to Google (per the OP's top-thread). Moxie has stated he is open to consider high quality PR's to add Websocket functionality. (Removing close-source binary blobs would be a prerequisite to distributing on anything other than Google Play to though, which Moxie's also said isn't on the roadmap - I assume primarily because of resources).

In the meantime, Conversations.IM has OMEMO and Vector.IM has Olm/MegOlm.

There's not a lot of good voice options. Vector.IM's just added WebRTC, which is meant to be DTLS secured. CSipSimple does ZRTP, but it hasn't been updated in a long time.

None of the apps mentioned above has been audited and scrutinised to the extent Signal has.

If you really need privacy & security, CopperheadOS is the only Android distro AFAIAA that fits the bill at the moment.

Re: Google collects metadata from Android phones

#258

Earlier quoted context omitted.

I'm going to focus on voice as messengers are all over the place. People originally wanted secure voice. They started out as custom or value-added devices that, if worth a crap, often had special protections like dedicated IC's for crypto and TEMPEST protection: https://electrospaces.blogspot.com/2012/06/highly-secure-mob... Those were usually very simple. A good thing compared to modern ones. They all cost in the $1…

The big issue with Signal at the moment, is that it doesn't work on AOSP. You can't use it without installing closed-source Google Apps (Play Services for GCM at minimum), and means you agree to hand over your phone metadata to Google (per the OP's top-thread). Moxie has stated he is open to consider high quality PR's to add Websocket functionality. (Removing close-source binary blobs would be a prerequisite to distr…

Thanks for the tips on other apps and the Android distro. Much appreciated. Far as Signal issue, I did find this:

https://www.reddit.com/r/gnu/comments/4cd451/libresignal_sig...

Perhaps some more volunteers putting effort in could remedy the situation.

Re: Google collects metadata from Android phones

#259

Earlier quoted context omitted.

This is a very good reply. My hat off to you. That being said, could you give us a good example for these privacy-enabled phones and apps? I am willing to make a collection out of these and write a guide on hardening Android. And I am not just talking apps that are incredibly hard to use; I mean the better generation of them who are actually mass-audience-friendly. Of course we must not forget that Android phones cou…

I'm going to focus on voice as messengers are all over the place. People originally wanted secure voice. They started out as custom or value-added devices that, if worth a crap, often had special protections like dedicated IC's for crypto and TEMPEST protection: https://electrospaces.blogspot.com/2012/06/highly-secure-mob... Those were usually very simple. A good thing compared to modern ones. They all cost in the $1…

Thanks a lot! Bookmarking and downloading your reply. I'll most certainly use the following months to try and find the perfect balance between usable and secure app.

Sadly, on the topic of the Turing Phone, I suspected as much. I really like to believe but yes, they're quite new to the market and are still closed in terms of what they use for this alleged "more secure" phone/OS. I'm still interested but my enthusiasm is not so high compared to the time of the original announcement...

I wanted to use Signal several times but I have to admit, it's use-case and convenience points aren't looking well. I'll take a more serious look, though.

Post reply on HN