Live data from Hacker News

Tracking my phone's silent connections

kushaldas.in

51–60 of 110 posts

Re: Tracking my phone's silent connections

#51

Regarding iOS: I stopped using iPhones and (edit typo) quot the ecosystem altogether (apart from an app I still sell in apple app store) because with the lack of an untethered Jailbreak I could no longer install "Firewall IP" and I could not edit the hosts file. Regarding Android: I switched to Android for the "NoRoot Firewall" and since most Android phones are Root-able I can also edit my hosts file. The article giv…

Unfortunately, i seriously doubt whether using Android (and thereby supporting Google) will improve your privacy, even when using a firewall. A simple example: https://www.bloomberg.com/news/articles/2018-08-13/google-tr...

That depends. If he isn't using google play at all, then I think it would.

Re: Tracking my phone's silent connections

#52
post #51

Earlier quoted context omitted.

Unfortunately, i seriously doubt whether using Android (and thereby supporting Google) will improve your privacy, even when using a firewall. A simple example: https://www.bloomberg.com/news/articles/2018-08-13/google-tr...

That depends. If he isn't using google play at all, then I think it would.

I tried no root firewall and found that Google groups literally everything under a kitchen sink service that talks to blind IPs with SSL. There is no way to allow Maps without inviting Google to share your bed with you.

Re: Tracking my phone's silent connections

#53

Some patterns I've found useful that most of my non-tech savvy friends can use (for Android) without going through hassle of setting up a VPN. 1. Use AdGuard DNS. https://news.ycombinator.com/item?id=18788410 2. Do not install the app if there's a website equivalent you could use (Facebook, Banking Apps). 3a. Force Stop or Disable apps you use frequently despite web equivalents (Google Maps). 3b. Enable permissions r…

> 3b. Enable permissions required by apps used occasionally only when in use. Disable them again, once usage is complete (Banking Apps).

Bouncer - Temporary app permissions seems to be a brilliant tool for this. I installed it the other day together with Glasswire. Both are paid, and I happily pay (reasonable amounts) for good tools.

Together they should hopefully mitigate the risk connected to useful apps with broad permissions.

Haven't tested them too much yet, so if anyone knows problems with those apps, feel free to let me know.

Bouncer is available here:

https://play.google.com/store/apps/details?id=com.samruston....

Glasswire is here;

https://play.google.com/store/apps/details?id=com.glasswire....

Of course, depending on your threat model some of you might never be safe with a smartphone or any portable phone at all. Personally however I feel this might solve it for me for now.

Re: Tracking my phone's silent connections

#55
post #52
post #51

Earlier quoted context omitted.

That depends. If he isn't using google play at all, then I think it would.

I tried no root firewall and found that Google groups literally everything under a kitchen sink service that talks to blind IPs with SSL. There is no way to allow Maps without inviting Google to share your bed with you.

I think you misunderstand me.

What I mean is you wipe the phone, reinstall either AOSP or LineageOS (or other custom ROM), do NOT install any Google Apps (to include Google Play Services, Google Store, Google Maps, etc.). Use F-Droid (https://f-droid.org/) as your App Store.

I have been using OsmAnd (https://osmand.net/) as my map service.

Re: Tracking my phone's silent connections

#56
post #47
post #41

Earlier quoted context omitted.

Which app did you use? I’ve done similar things with Charles and Burp Suite.

It's this one: https://itunes.apple.com/us/app/adblock/id691121579 I've got it on my list to play with Charles proxy. I'm curious to peer into a few of the requests if possible. But I've read that, especially with mobile apps, they may use cert pinning which defeats something like Charles.

Adblock? Don't they allow "approved ads"?

Re: Tracking my phone's silent connections

#57
post #35

To clarify, outside of the CDN providers or AWS calls and the big 3 (Facebook, Google, Apple), the vast majority of the calls seem to be to marketing providers or developer tools Branch - these guys provide deep links into phones and tools to analyze who clicked on the links and if they worked. mParticle, Appsflyer, Braze formerly Appboy, Appboy all provide internal app marketing teams tools like mobile push or analy…

With regard to your last paragraph: that would probably be an excellent application of Ben Thompson's aggregation theory. It would increase Apple and Google's moat by making them the hardware gatekeeper for all mobile app analytics. And battery life is also a strong cover for the business reasons for doing it.

But the public claim, "it saves battery life!" would not make it defensible for most analytics companies, in my opinion. That would mean Google and Apple get duplicated access to just about all mobile analytics data in the world overnight. They already get vast data from the mobile phones through telemetry and their own apps; I think the largest third party analytics providers would revolt. They would all be at the mercy of Apple and Google's benevolence, which is basically backing their business into a corner. You don't want to be reliant on the whims of a giant tech company.

There are probably also some (maybe weak) anti-trust arguments against it, because all analytics other than e.g. Google Analytics become literal second class citizens on the phone. That would basically be telling app developers they're not allowed to send requests to specific hosts within their apps, only Apple and Google can do that (on their respective phones).

So I don't know if this is a missed opportunity, so much as Apple and Google realizing it would burn their walled gardens to the ground.

Re: Tracking my phone's silent connections

#58

Regarding iOS: I stopped using iPhones and (edit typo) quot the ecosystem altogether (apart from an app I still sell in apple app store) because with the lack of an untethered Jailbreak I could no longer install "Firewall IP" and I could not edit the hosts file. Regarding Android: I switched to Android for the "NoRoot Firewall" and since most Android phones are Root-able I can also edit my hosts file. The article giv…

Apps like AdGuard Pro let you block domains for all apps by intercepting and blocking DNS locally on iOS.

Disconnect Pro for iOS is also a great tool. Hasn't failed me yet and makes adding custom trackers super easy via the list of recent connections. I blocked 30.8k trackers and saved 3 GB of data last month. :)

Re: Tracking my phone's silent connections

#59
post #47

Earlier quoted context omitted.

It's this one: https://itunes.apple.com/us/app/adblock/id691121579 I've got it on my list to play with Charles proxy. I'm curious to peer into a few of the requests if possible. But I've read that, especially with mobile apps, they may use cert pinning which defeats something like Charles.

Adblock? Don't they allow "approved ads"?

It's an unfortunate naming coincidence. The app I linked has no affiliation with that Adblock

Re: Tracking my phone's silent connections

#60
post #53

Some patterns I've found useful that most of my non-tech savvy friends can use (for Android) without going through hassle of setting up a VPN. 1. Use AdGuard DNS. https://news.ycombinator.com/item?id=18788410 2. Do not install the app if there's a website equivalent you could use (Facebook, Banking Apps). 3a. Force Stop or Disable apps you use frequently despite web equivalents (Google Maps). 3b. Enable permissions r…

> 3b. Enable permissions required by apps used occasionally only when in use. Disable them again, once usage is complete (Banking Apps). Bouncer - Temporary app permissions seems to be a brilliant tool for this. I installed it the other day together with Glasswire. Both are paid, and I happily pay (reasonable amounts) for good tools. Together they should hopefully mitigate the risk connected to useful apps with broad…

I will strongly second Bouncer. It's an amazing app for keeping permissions in line on my phone. It's also a shame I rarely have to open the app itself because Sam Ruston is a master of clean UIs.
Post reply on HN