Live data from Hacker News

Never-Googlers: Web users take the ultimate step to guard their data

thehour.com

101–110 of 115 posts

Re: Never-Googlers: Web users take the ultimate step to guard their data

#101

Earlier quoted context omitted.

> Google requires all apps that are on Google Play to use Firebase, which is baked into the OS, for notifications. Only for apps on the Play Store. This is much less restrictive than iOS, which requires you to use APNS for notifications without any workarounds. Also, Firebase is not "built into the OS" and doesn't exist at all in AOSP. > The current versions of the stock keyboard, clock, calendar, contacts manager, a…

What nonsense. Google's panoptic data collection is not excused by AOSP, side loading, or vendor shovelware, all of which are completely irrelevant. Google's detailed picture of the daily physical movements of everyone, cross referenced with their email, web searches, site visits, and who knows what else, is not somehow worse than Apple requiring a credit card to develop for the app store. Apple Maps doesn't know who…

You've fallen for a simple marketing campaign. What Google does with data has nothing to do with what data Android collects out of the box, which I have demonstrated (and you have not refuted) is less than what iOS collects. You can just as easily send your location, email, and search data to Google on iOS as you can on Android. The difference is that on Android, it is possible (even easy) to choose not to send data to Google or Apple.

> If you actually cared about this stuff, you'd be applauding Apple.

If you actually cared about privacy, you would be damning Apple for handing over the iCloud keys for Chinese users' data to the PRC allowing the PRC to implement dragnet surveillance on iCloud documents, iCloud email, iMessages, etc. to find and disappear dissidents. This is worse than anything Google or even Facebook has done by a stupendous margin.

> iMessage is E2E encrypted.

Since Apple controls the keyserver, Apple has the ability to wiretap any iMessage conversation (https://blog.quarkslab.com/imessage-privacy.html). Since China controls the keyserver inside the great firewall, China has the ability to wiretap any conversation that occurs with at least one user in China. Compare to Android, where you can set Signal as your default SMS handler. One pretends to support privacy, while the other actually does.

> Apple Maps doesn't know who you are.

But it does know where you are and every address link you click on. From there, you are very easy to deanonymize. Compare to Android, which lets you run fully offline mapping applications and set them as the default address handler. Apple's apps are systematically both less useful than alternatives and less private than other alternatives. The only thing that saves them is slick marketing.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#102
post #82

Earlier quoted context omitted.

For any regular non-technical user locking down most Android phones (presumably some phones come with hardened settings and possibly with no Google services) and keeping the data away for Google is a huge challenge. The default settings are almost always very permissive, you have to dig down through settings to disable everything, and a lot of stuff isn't very obvious for anyone who doesn't expect such behavior. Oh e…

It is much less of a challenge than keeping your data away from Apple on iOS as my previous comment demonstrated. > Oh even when the WiFi is off it will still scan for nearby SSIDs to get your position? Again, this is opt in even on Google-flavored Android devices. There is no digging through settings required — the opt in checkbox appears in the setup flow. On iOS, there is nothing you can do to stop your device fro…

You don't have to do anything to get decent privacy on iOS because it comes like that out of the box.

Do you honestly believe that Google has less data on Android users, compared to Apple for iOS users?

> Again, this is opt in even on Google-flavored Android devices

No, it's opt-out. For example see http://www.youtube.com/watch?v=b2uSGGl0LWc&t=3m41s - setup on a Pixel and all the location stuff is on by default.

> On iOS, there is nothing you can do to stop your device from doing this

Oh, how do I turn this on for iOS?

When I turn off WiFi it says that "improved location accuracy require Wi-Fi".

Re: Never-Googlers: Web users take the ultimate step to guard their data

#103
post #45
post #13

Earlier quoted context omitted.

That doesn't prevent Google from collecting information about you. Even though you don't actively use Google on your Android device, doesn't mean it doesn't phone home and reports information to Google. For example, if you don't actively disable it, your phone sends the names of all Wifi-networks in your proximity to Google, so Google can tell you where you are faster and more accurate than with GPS. Even if you disa…

And this is the sort of thing GDPR is meant to prevent. Unless you explicitly allow it (and a popup checked by default doesn't count), Google cannot use that data for purposes other than providing you with positioning information.

> And this is the sort of thing GDPR is meant to prevent.

Sure. But Google being the immoral company it is has instead chosen to lawyer up, tell people it's compliant with the GDPR, and keep on collecting everything it can get its hands on anyway.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#104
post #82

Earlier quoted context omitted.

For any regular non-technical user locking down most Android phones (presumably some phones come with hardened settings and possibly with no Google services) and keeping the data away for Google is a huge challenge. The default settings are almost always very permissive, you have to dig down through settings to disable everything, and a lot of stuff isn't very obvious for anyone who doesn't expect such behavior. Oh e…

It is much less of a challenge than keeping your data away from Apple on iOS as my previous comment demonstrated. > Oh even when the WiFi is off it will still scan for nearby SSIDs to get your position? Again, this is opt in even on Google-flavored Android devices. There is no digging through settings required — the opt in checkbox appears in the setup flow. On iOS, there is nothing you can do to stop your device fro…

> Again, this is opt in

It's not and it's not even suggested that it exists as a feature on any of the Android devices I ever owned or played with. The dialog for setting up location has no option that absolutely turns off every method that is directly used to determine/infer location. Ok, this is also a user education problem but Google certainly isn't doing anything to suggest the "precise location" won't just provide a precise location to the user.

And most people take the common sense approach and assume turning off WiFi will actually turn it off. Instead not only are they still tracked, they lose battery life too.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#105

Earlier quoted context omitted.

It is much less of a challenge than keeping your data away from Apple on iOS as my previous comment demonstrated. > Oh even when the WiFi is off it will still scan for nearby SSIDs to get your position? Again, this is opt in even on Google-flavored Android devices. There is no digging through settings required — the opt in checkbox appears in the setup flow. On iOS, there is nothing you can do to stop your device fro…

You don't have to do anything to get decent privacy on iOS because it comes like that out of the box. Do you honestly believe that Google has less data on Android users, compared to Apple for iOS users? > Again, this is opt in even on Google-flavored Android devices No, it's opt-out. For example see http://www.youtube.com/watch?v=b2uSGGl0LWc&t=3m41s - setup on a Pixel and all the location stuff is on by default. > On…

> You don't have to do anything to get decent privacy on iOS because it comes like that out of the box.

It's amazing that somebody who works in tech would fall for that marketing when it is so obviously a lie. Consider that iOS sends every GPS location ever requested by your phone to Apple, and there is nothing you can do about it. Likewise, you can't stop Apple from knowing about every app you install on your phone or every address link you click on. If you want to develop apps for your own device, you have to hand over card details. "Out of the box," iOS tells Apple every phone number you SMS and when. And worst of all, if you're Chinese, you have no privacy at all on an iOS device.

> Do you honestly believe that Google has less data on Android users, compared to Apple for iOS users?

For users who care about privacy, absolutely. For users who care about usability, Google has more data but provides a more useful experience. That's a trade-off that is possible to make on Android. On iOS, you are stuck with poor privacy and worse usability.

> No, it's opt-out.

You are correct. That is still much better than not being able to opt out of sending every GPS lookup to Apple at all.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#106

Earlier quoted context omitted.

You may or may not be right about this. The only way to verify this is to install some system level firewall and carefully inspect all logs. Until you do that, we simple don't know.

Or you can inspect AOSP itself and bring your device to AOSP-like state. Sure, you won't know whether the vendor of your device didn't modify the firmware itself, but what motivation is there for Samsung, Sony or Huawei to help Google to get user data?

> what motivation is there for Samsung, Sony or Huawei to help Google to get user data?

I'm not sure about their motivation, but several vendors are famously known for bundling spyware with their phones. Usually within the keyboard app or some telemetry system.

> bring your device to AOSP-like state

That's a solution but is impossible without having a clean ROM at your disposal. Google's spyware is contained within Google Play Services, which you can't get rid of that easily.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#107
post #4

(disclaimer: I work at a big tech firm, but I've had this opinion before working here) I'm confused by the lengths people have gone through to "protect" themselves from internet giants while freely giving away their info to credit card companies, traditional retailers, small businesses. Credit card transaction data have been sold for years without most of us knowing about it. Small startups, boutique stores rarely ha…

> while freely giving away their info to credit card companies, traditional retailers, small businesses.

No, we don't. We are just not given a choice by this bullshit capitalist society. Just like many people "freely live on the streets" or "freely get murdered by the police".

Re: Never-Googlers: Web users take the ultimate step to guard their data

#108
post #66

Earlier quoted context omitted.

Google is worse without question. Having your card number stolen is a minor inconvenience whose danger is inflated by services offering to protect you from it. Happened to me once, they charged $1500 before my credit union called me. I had to spend a total of an hour on the phone with a few different people, and the money was credited back to my account within 48 hours. This is with a debit card , which are constantl…

Note that you provided reasons as to why having debit/credit card information stolen isn't such a big deal, if you get protection from fraudulent transactions, but haven't provided any reasons as to why Google targeting ads based on some profile they built on you is worse than that.

Because one is a minor inconvencience, the other is psychological warfare used to modify behaviour.

It's baffling why you'd think the Google example is somehow less dangerous, especially considering its a given that they have profiled your political views as well as your spending habits, among every other aspect of your life.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#109
post #4

(disclaimer: I work at a big tech firm, but I've had this opinion before working here) I'm confused by the lengths people have gone through to "protect" themselves from internet giants while freely giving away their info to credit card companies, traditional retailers, small businesses. Credit card transaction data have been sold for years without most of us knowing about it. Small startups, boutique stores rarely ha…

I think you're thinking of a different threat model from these users. If you're concerned about breaches by malicious actors, then yes this defense makes sense. However, if you're worried about data mined from tracking your personal behavior, which is what the users here are worried about, then it makes sense to spread your data out. Traditional stores are not going to send each other your transaction history to buil…

>Traditional stores are not going to send each other your transaction history to build a profile of interest and personality, and each store won't have a complete enough history or even the expertise to mine it.

"Traditional" as in "before the age of Amazon"? They do, through store rewards cards. Harris Teeter knows what I have bought and has figured out what I only buy on sale, Target can identify pregnant women with stunning accuracy, and I'd be surprised if other retailers didn't do similar stuff. You're probably thinking of independent/mom and pop shops.

Re: Never-Googlers: Web users take the ultimate step to guard their data

#110

Earlier quoted context omitted.

Or you can inspect AOSP itself and bring your device to AOSP-like state. Sure, you won't know whether the vendor of your device didn't modify the firmware itself, but what motivation is there for Samsung, Sony or Huawei to help Google to get user data?

> what motivation is there for Samsung, Sony or Huawei to help Google to get user data? I'm not sure about their motivation, but several vendors are famously known for bundling spyware with their phones. Usually within the keyboard app or some telemetry system. > bring your device to AOSP-like state That's a solution but is impossible without having a clean ROM at your disposal. Google's spyware is contained within G…

When one wants an AOSP-like state, they can install LineageOS. That doesn't include Google Play Services, so it isn't difficult to get rid of it.
Post reply on HN