Regarding iOS: I stopped using iPhones and (edit typo) quot the ecosystem altogether (apart from an app I still sell in apple app store) because with the lack of an untethered Jailbreak I could no longer install "Firewall IP" and I could not edit the hosts file. Regarding Android: I switched to Android for the "NoRoot Firewall" and since most Android phones are Root-able I can also edit my hosts file. The article giv…
Unfortunately, i seriously doubt whether using Android (and thereby supporting Google) will improve your privacy, even when using a firewall. A simple example: https://www.bloomberg.com/news/articles/2018-08-13/google-tr...
Tracking my phone's silent connections
51–60 of 110 posts
Re: Tracking my phone's silent connections
#52Earlier quoted context omitted.
Unfortunately, i seriously doubt whether using Android (and thereby supporting Google) will improve your privacy, even when using a firewall. A simple example: https://www.bloomberg.com/news/articles/2018-08-13/google-tr...
That depends. If he isn't using google play at all, then I think it would.
Re: Tracking my phone's silent connections
#53Some patterns I've found useful that most of my non-tech savvy friends can use (for Android) without going through hassle of setting up a VPN. 1. Use AdGuard DNS. https://news.ycombinator.com/item?id=18788410 2. Do not install the app if there's a website equivalent you could use (Facebook, Banking Apps). 3a. Force Stop or Disable apps you use frequently despite web equivalents (Google Maps). 3b. Enable permissions r…
Bouncer - Temporary app permissions seems to be a brilliant tool for this. I installed it the other day together with Glasswire. Both are paid, and I happily pay (reasonable amounts) for good tools.
Together they should hopefully mitigate the risk connected to useful apps with broad permissions.
Haven't tested them too much yet, so if anyone knows problems with those apps, feel free to let me know.
Bouncer is available here:
https://play.google.com/store/apps/details?id=com.samruston....
Glasswire is here;
https://play.google.com/store/apps/details?id=com.glasswire....
Of course, depending on your threat model some of you might never be safe with a smartphone or any portable phone at all. Personally however I feel this might solve it for me for now.
Re: Tracking my phone's silent connections
#54Re: Tracking my phone's silent connections
#55Earlier quoted context omitted.
That depends. If he isn't using google play at all, then I think it would.
I tried no root firewall and found that Google groups literally everything under a kitchen sink service that talks to blind IPs with SSL. There is no way to allow Maps without inviting Google to share your bed with you.
What I mean is you wipe the phone, reinstall either AOSP or LineageOS (or other custom ROM), do NOT install any Google Apps (to include Google Play Services, Google Store, Google Maps, etc.). Use F-Droid (https://f-droid.org/) as your App Store.
I have been using OsmAnd (https://osmand.net/) as my map service.
Re: Tracking my phone's silent connections
#56Earlier quoted context omitted.
Which app did you use? I’ve done similar things with Charles and Burp Suite.
It's this one: https://itunes.apple.com/us/app/adblock/id691121579 I've got it on my list to play with Charles proxy. I'm curious to peer into a few of the requests if possible. But I've read that, especially with mobile apps, they may use cert pinning which defeats something like Charles.
Re: Tracking my phone's silent connections
#57To clarify, outside of the CDN providers or AWS calls and the big 3 (Facebook, Google, Apple), the vast majority of the calls seem to be to marketing providers or developer tools Branch - these guys provide deep links into phones and tools to analyze who clicked on the links and if they worked. mParticle, Appsflyer, Braze formerly Appboy, Appboy all provide internal app marketing teams tools like mobile push or analy…
But the public claim, "it saves battery life!" would not make it defensible for most analytics companies, in my opinion. That would mean Google and Apple get duplicated access to just about all mobile analytics data in the world overnight. They already get vast data from the mobile phones through telemetry and their own apps; I think the largest third party analytics providers would revolt. They would all be at the mercy of Apple and Google's benevolence, which is basically backing their business into a corner. You don't want to be reliant on the whims of a giant tech company.
There are probably also some (maybe weak) anti-trust arguments against it, because all analytics other than e.g. Google Analytics become literal second class citizens on the phone. That would basically be telling app developers they're not allowed to send requests to specific hosts within their apps, only Apple and Google can do that (on their respective phones).
So I don't know if this is a missed opportunity, so much as Apple and Google realizing it would burn their walled gardens to the ground.
Re: Tracking my phone's silent connections
#58Regarding iOS: I stopped using iPhones and (edit typo) quot the ecosystem altogether (apart from an app I still sell in apple app store) because with the lack of an untethered Jailbreak I could no longer install "Firewall IP" and I could not edit the hosts file. Regarding Android: I switched to Android for the "NoRoot Firewall" and since most Android phones are Root-able I can also edit my hosts file. The article giv…
Apps like AdGuard Pro let you block domains for all apps by intercepting and blocking DNS locally on iOS.
Re: Tracking my phone's silent connections
#59Earlier quoted context omitted.
It's this one: https://itunes.apple.com/us/app/adblock/id691121579 I've got it on my list to play with Charles proxy. I'm curious to peer into a few of the requests if possible. But I've read that, especially with mobile apps, they may use cert pinning which defeats something like Charles.
Adblock? Don't they allow "approved ads"?
Re: Tracking my phone's silent connections
#60Some patterns I've found useful that most of my non-tech savvy friends can use (for Android) without going through hassle of setting up a VPN. 1. Use AdGuard DNS. https://news.ycombinator.com/item?id=18788410 2. Do not install the app if there's a website equivalent you could use (Facebook, Banking Apps). 3a. Force Stop or Disable apps you use frequently despite web equivalents (Google Maps). 3b. Enable permissions r…
> 3b. Enable permissions required by apps used occasionally only when in use. Disable them again, once usage is complete (Banking Apps). Bouncer - Temporary app permissions seems to be a brilliant tool for this. I installed it the other day together with Glasswire. Both are paid, and I happily pay (reasonable amounts) for good tools. Together they should hopefully mitigate the risk connected to useful apps with broad…