Live data from Hacker News

Bose Headphones Spy on Users, Lawsuit Says

fortune.com

211–215 of 215 posts

Re: Bose Headphones Spy on Users, Lawsuit Says

#211

So what are the chances this never goes anywhere thanks to a clickwrap EULA that's shoved into your face in 3pt font the moment the app starts? "Well, your honor, he agreed.."

EULA for other Bose app (Connect EULA seems not to be available online): https://hearphones.bose.com/eula "YOUR USE OF THE SOFTWARE ALSO OPERATES AS YOUR CONSENT TO THE COLLECTION, TRANSMISSION AND STORAGE OF CERTAIN STANDARD NETWORKING INFORMATION, DEVICE USAGE DATA, AND BOSE PRODUCT INFORMATION VIA THE INTERNET TO SERVERS OWNED OR CONTROLLED BY BOSE OR OPERATED BY THIRD PARTIES ON BEHALF OF BOSE"

IANAL but in the EU it doesn't matter what the EULA says unless the app makes it very explicit that it's tracking this kind of personal usage data.

Re: Bose Headphones Spy on Users, Lawsuit Says

#212

Earlier quoted context omitted.

I use NoScript, uBlock Origin AND uMatrix on most of my instances. Noscript as the first line of defense against 3rd party scripts, uBlock in advanced mode for fine-tuning what content goes through, and uMatrix for being the safety net as well as providing cookie control and spoofing/referrer masking, since Cookie Monster still cannot work with multi-process mode. I really wish uMatrix and uBlock would just combine f…

Don't you find that your surfing is a configurational nightmare? Using uMatrix was doable, but I finally gave it because it always interupted my browsing. Adding NoScript to the mix would probably drive me insane. Do you have any special techniques? :)

I use NoScript and uBlock.

If it's too much bother with NoScript making the page work, it probably wasn't worth wasting any time on it in the first place. So I gained time instead of lost!

Re: Bose Headphones Spy on Users, Lawsuit Says

#213

Earlier quoted context omitted.

Don't you find that your surfing is a configurational nightmare? Using uMatrix was doable, but I finally gave it because it always interupted my browsing. Adding NoScript to the mix would probably drive me insane. Do you have any special techniques? :)

It usually only takes a moment to configure uMatrix for any given site. However, adding NoScript into the mix means that, each time I allow a new script or group of scripts, I have to refresh so that previously unallowed external requests can be made and uMatrix can register them. uBlock is usually not a problem and I usually don't have to touch it, but sometimes I have to let a request or two through. Sometimes it's…

Sorry for going meta, but I find it very odd your comment was dead, as your GP post was not.

I've been seeing this quite a lot in the last 2-3 months, perfectly reasonable comments that are [dead] for no discernible reason; could this be trolling or a form of botting?

Re: Bose Headphones Spy on Users, Lawsuit Says

#214

Earlier quoted context omitted.

Did you packet sniff what is being sent out? Or do you have some intermediary running on the device itself? Just curious if it was difficult to do. If more people knew how to, maybe this sort of activity wouldn't sneakily happen as often.

Unless an android app uses certificate pinning ( https://security.stackexchange.com/questions/29988/what-is-c... ), it is usually trivial to MITM its traffic passing through your phone. Provided you own and have physical access to your phone, you can use any number of proprietary/open free/costly tools to do so. (E.g Fiddler http://www.telerik.com/fiddler , Burp https://portswigger.net/burp/ and mitmproxy https://mit…

I recall older versions of one of those (forget which) generated a non-unique custom certificate, meaning anyone who had used it could be MITM'd with the same cert. It was changed later on, but it's a risk if you go with something poorly designed.

Re: Bose Headphones Spy on Users, Lawsuit Says

#215

Earlier quoted context omitted.

An age where "idiots are getting promoted for baseless ideas" is closer to the truth. This is why people who were traditionally more humble now have the obligation to speak out - but I often see them silenced at the tech companies they work for... These companies are often selectively listening to exactly the wrong people, who are usually in the minority in the company anyway!

>These companies are often selectively listening to exactly the wrong people, who are usually in the minority in the company anyway! You don't appreciate the diversity?

You don't appreciate democracy? That's a pretty annoying way to start a discussion, if that's your intention here...
Post reply on HN