Earlier quoted context omitted.
What settings can you change in the app that are not available through the headphones?
Language, device name, firmware updates, voice-prompts, auto-off-timer, list of paired devices, multi-headset-mode, and so on. The app is almost mandatory, especially since iOS pushes you to download it on connect.
Bose Headphones Spy on Users, Lawsuit Says
161–170 of 215 posts
Re: Bose Headphones Spy on Users, Lawsuit Says
#162(Created an account to post this) I downloaded the app on android and listened to a few songs on Spotify to find out what information was being sent. While the app is running, the app sends a HTTP (edit: HTTPS) request every time the track information changes or the volume changes. When the track information changes it sends the artist, album and song name. When you change the volume it sends the new volume level. Ev…
Did you packet sniff what is being sent out? Or do you have some intermediary running on the device itself? Just curious if it was difficult to do. If more people knew how to, maybe this sort of activity wouldn't sneakily happen as often.
I have used the approach of installing wire shark on a pc operating as an access point, and it was easy enough to set up assuming you have the requisite equipment.
Re: Bose Headphones Spy on Users, Lawsuit Says
#163(Created an account to post this) I downloaded the app on android and listened to a few songs on Spotify to find out what information was being sent. While the app is running, the app sends a HTTP (edit: HTTPS) request every time the track information changes or the volume changes. When the track information changes it sends the artist, album and song name. When you change the volume it sends the new volume level. Ev…
Did you packet sniff what is being sent out? Or do you have some intermediary running on the device itself? Just curious if it was difficult to do. If more people knew how to, maybe this sort of activity wouldn't sneakily happen as often.
Re: Bose Headphones Spy on Users, Lawsuit Says
#164(Created an account to post this) I downloaded the app on android and listened to a few songs on Spotify to find out what information was being sent. While the app is running, the app sends a HTTP (edit: HTTPS) request every time the track information changes or the volume changes. When the track information changes it sends the artist, album and song name. When you change the volume it sends the new volume level. Ev…
1. What's the estimated bandwidth impact of this data collection? Many users have very limited data use, and chatty messages on play/pause/volume change wouldn't be appreciated.
2. HTTP or HTTPS?
3. How does it work with other apps (like Google Music) that might provide more music details? Like does it send more information when the id3 tags have all the fields filled in? Things like comments, encoding, etc might also be transmitted. Streaming services like Spotify probably try to trim that as much as possible, but local files could have a lot more data.
4. Can you see anything about the anonymous id that might make it not that anonymous? I mean, the device serial number alone kind of defeats an anonymous id. But there's been a fair amount of work in reidentification of anonymous data, and many developers take shortcuts when generating their "anonymous" data. (https://arstechnica.com/tech-policy/2009/09/your-secrets-liv...).
5. It's sending this data in the background, correct?
6. What does it send (if anything) during calls, emails, texts, map navigation, and voice commands?
Re: Bose Headphones Spy on Users, Lawsuit Says
#165(Created an account to post this) I downloaded the app on android and listened to a few songs on Spotify to find out what information was being sent. While the app is running, the app sends a HTTP (edit: HTTPS) request every time the track information changes or the volume changes. When the track information changes it sends the artist, album and song name. When you change the volume it sends the new volume level. Ev…
I'd be really curious to see how this data is actually used on their end. I got my QC35s a few months ago and have been loving them, but was super disappointed when I read the article. I'll probably end up uninstalling the app for the time being, at least until it's resolved. On another note, I wonder if any other wireless audio manufacturers are doing similar things.
As a side note. I can imagine why they'd want this information. Seeing what people are listening to and what volume settings are commonly being used would potentially help them tune future products better for their "average user"
Re: Bose Headphones Spy on Users, Lawsuit Says
#166Earlier quoted context omitted.
I've got a Q35, I installed the app to set it up, but deleted it later, and have never been prompted again or anything, and everything works fine. So I think you can just delete it no problem.
I'm sure I could, but I would be missing out on the features I may want to occasionally use/change. Bose is hardly the only app I would want to block. There are dozens of apps I might use only occasionally - a month or a year might go by between uses. But having to reinstall is just a cumbersome step.
I downloaded it again just now. Again, nothing I needed, deleted.
Re: Bose Headphones Spy on Users, Lawsuit Says
#167(Created an account to post this) I downloaded the app on android and listened to a few songs on Spotify to find out what information was being sent. While the app is running, the app sends a HTTP (edit: HTTPS) request every time the track information changes or the volume changes. When the track information changes it sends the artist, album and song name. When you change the volume it sends the new volume level. Ev…
Did you packet sniff what is being sent out? Or do you have some intermediary running on the device itself? Just curious if it was difficult to do. If more people knew how to, maybe this sort of activity wouldn't sneakily happen as often.
Provided you own and have physical access to your phone, you can use any number of proprietary/open free/costly tools to do so. (E.g Fiddler http://www.telerik.com/fiddler, Burp https://portswigger.net/burp/ and mitmproxy https://mitmproxy.org/)
In this case I used fiddler, all I had to do generate a custom root certificate (Be warned this is not a good idea in general, look up super fish if you want an example of why installing custom root certificates can be bad), install that certificate on my device and then proxy my device through the computer running fiddler.
This process is far better documented here http://docs.telerik.com/fiddler/Configure-Fiddler/Tasks/Conf... if you need any more help or advice let me know
Re: Bose Headphones Spy on Users, Lawsuit Says
#168So what are the chances this never goes anywhere thanks to a clickwrap EULA that's shoved into your face in 3pt font the moment the app starts? "Well, your honor, he agreed.."
EULA for other Bose app (Connect EULA seems not to be available online): https://hearphones.bose.com/eula "YOUR USE OF THE SOFTWARE ALSO OPERATES AS YOUR CONSENT TO THE COLLECTION, TRANSMISSION AND STORAGE OF CERTAIN STANDARD NETWORKING INFORMATION, DEVICE USAGE DATA, AND BOSE PRODUCT INFORMATION VIA THE INTERNET TO SERVERS OWNED OR CONTROLLED BY BOSE OR OPERATED BY THIRD PARTIES ON BEHALF OF BOSE"
Listening data was not mentioned under a MAY INCLUDE section, however of course its' covered by the blanket "data".
Re: Bose Headphones Spy on Users, Lawsuit Says
#169This link has an autoplay video with sound. Can we get some kind of title warning on these, like the [pdf] or [1927] warnings? I really don't want to click on these without being prepared. Lacking a better alternative, for now, I'm just flagging it.
"This link has an autoplay video with sound." Are we really getting this finicky now? Like, I'm usually on the more compassionate side of listening to people's concerns, but being offended by a video playing is just... sissified to the max.
Re: Bose Headphones Spy on Users, Lawsuit Says
#170Looks like you need to download a special app to enable this "feature" >The lead plaintiff in the lawsuit is a man named Kyle Zak, who claims he followed the company's suggestion to "get the most out of your headphones" by downloading the Bose Connect app, and supplying information such as his name, phone number and email address.
It's the app you're being pushed heavily into downloading (even by iOS itself as it is the "accessory accompanying app" as detected by the OS when connecting the headset), for things like updating the headset firmware and setting the bluetooth device name.
The ONLY feature I can see using is the managing bluetooth devices. I had 4 devices in my list -- old computer, new computer, old phone, new phone. Unless you're around 3+ devices you regularly connect to, its not really an issue.
My computer and phone are the only 2 devices that will be in range so I'll never need to "manage" this. Again, think of all of the other devices that only support connecting to ONE other device and don't need a proprietary app to manage this.