Live data from Hacker News

Spanish football league defends phone 'spying'

bbc.com

1–10 of 54 posts

Re: Spanish football league defends phone 'spying'

#4
post #2

Well... I hope this is something GPDR covers. If there was a case to start seeing the impact of the new law, this seems like a good example.

Would GDPR even cover this? I don't see why La Liga would need to include any personal information about the user in their data. They are concerned with identifying the buisness streaming pirated matches, not who is watching.

Edit: The official statement actually answers this

>The codes will not refer to your name, but to your IP address and the specific ID assigned by the PPP when you register.

Re: Spanish football league defends phone 'spying'

#5
post #2

Well... I hope this is something GPDR covers. If there was a case to start seeing the impact of the new law, this seems like a good example.

This was indeed discovered because as per GPDR, they had to specify why they were using the mic and GPS. As soon as the update hit the store (after the GPDR entered into effect) and some users saw the changelog and user permission requests disclosing this use, it started to hit the news here in Spain.

The Spanish regulator, AEPD, has stated that preliminary steps to begin an official investigation are being conducted already: https://twitter.com/AEPD_es/status/1006115567227559936

For those who understand Spanish, here's a good technical analysis: https://reversecodes.wordpress.com/2018/06/12/analizando-la-...

Re: Spanish football league defends phone 'spying'

#6
The actual statement from La Liga is in spanish, I translated it with DeepL [1] here:

>Privacy policy of the LaLiga app.

>Regarding the new privacy policy of the LaLiga app, we would like to make some clarifications.

>Origin

>LaLiga has the responsibility to protect clubs and their fans from fraud in the broadcasting of football matches by public institutions (HORECA). These fraudulent activities represent an estimated annual loss of 150 million euros for Spanish football, which translates into direct damage to clubs, operators and fans, among others.

>For this reason, LaLiga has implemented a new functionality in its official app with the sole purpose of detecting these fraudulent exploitations, transparently informing about them and asking users for their express and specific consent, with or without their being able to lend it freely.

>This new functionality for fraud detection is enabled in the app since last Friday, June 8, 2018, only for Android system users and nationally*.

>Functioning

>When a user downloads or updates the APP, the operating system of your mobile device will prompt them through a pop-up window to provide their consent for LaLiga to activate the microphone and geopositioning of their mobile device. Only if you decide to accept it, the microphone will pick up the binary code from audio clips, for the sole purpose of knowing if you are watching football matches played by LaLiga teams, but the content of the recording will never be accessible.

>We protect user privacy

>LaLiga has implemented appropriate technical measures to protect your privacy if you authorize us to use this feature. These measures are detailed below:

>LaLiga will only activate the microphone and geopositioning of the mobile device during the time slots of matches in which LaLiga teams compete.

>LaLiga does not access the audio fragments picked up by the device's microphone, as they are automatically converted into binary code on the device itself. LaLiga only accesses this binary code, which is irreversible and does not allow you to obtain the audio recording again.

>If this code matches a previous control code, LaLiga may know that you are watching a particular match. If it does not match, the code is removed.

>The codes will not refer to your name, but to your IP address and the specific ID assigned by the PPP when you register.

>We will periodically remind you that LaLiga may activate your microphone and geo-positioning and ask you to confirm your consent.

>You can revoke your consent at any time in the mobile device settings.

[1] https://www.deepl.com/translator

Re: Spanish football league defends phone 'spying'

#7
> The broadcasting of football matches in public places without a paid licence cost the game an estimated 150 million euros (£132m; $177m) a year, it said.

Sounds suspiciously familiar to the way questionable data have been represented about money lost due to piracy in other industries (software, movies, music). I am very skeptical about those types of claims.

Re: Spanish football league defends phone 'spying'

#8
post #7

> The broadcasting of football matches in public places without a paid licence cost the game an estimated 150 million euros (£132m; $177m) a year, it said. Sounds suspiciously familiar to the way questionable data have been represented about money lost due to piracy in other industries (software, movies, music). I am very skeptical about those types of claims.

That's a bad one I agree. I think a better argument for enforcing their rights is the fact that if they don't, they are effectively punishing establishments that actually do pay to license the broadcast.

Re: Spanish football league defends phone 'spying'

#9
post #8
post #7

> The broadcasting of football matches in public places without a paid licence cost the game an estimated 150 million euros (£132m; $177m) a year, it said. Sounds suspiciously familiar to the way questionable data have been represented about money lost due to piracy in other industries (software, movies, music). I am very skeptical about those types of claims.

That's a bad one I agree. I think a better argument for enforcing their rights is the fact that if they don't, they are effectively punishing establishments that actually do pay to license the broadcast.

> I think a better argument for enforcing their rights

I don't think anyone is arguing that they shouldn't be enforcing their rights. But that they shouldn't use use people's phones as listening devices to do so.

Re: Spanish football league defends phone 'spying'

#10
post #5
post #2

Well... I hope this is something GPDR covers. If there was a case to start seeing the impact of the new law, this seems like a good example.

This was indeed discovered because as per GPDR, they had to specify why they were using the mic and GPS. As soon as the update hit the store (after the GPDR entered into effect) and some users saw the changelog and user permission requests disclosing this use, it started to hit the news here in Spain. The Spanish regulator, AEPD, has stated that preliminary steps to begin an official investigation are being conducted…

Thanks for sharing! Entertaining read.

The app uses rot(4) to obscure data, includes a debug link with the collected data, and has the Fluzo service api key hardcoded, among other gems.

Post reply on HN