Live data from Hacker News

My Phone Was Spying on Me, So I Tracked Down the Surveillants

twitter.com

121–130 of 176 posts

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#121
post #55

The writer doesn't mention which apps he installed, nor which phone. I'd be interested in the details, does anyone know this underlying data?

Writer: Samsung Galaxy S7. I guess over 70 apps in navigation, weather, games, prayer apps, or relevant due to listing location companies in privacy policy.

I have not named apps / companies I that were not relevant to this feature. I found other things, but I had to focus on a clear story.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#122
post #12

One downside to the security model in popular mobile OSes is that once someone does gain superuser access there's really nothing the user can do short of rebuilding the device since they often don't have it themselves.

Let’s not beat around the bush here: this is a uniquely Android problem. Sure, there are some iOS jailbreaks out in the wild, but these are very few and far between. There was one for then-recent iOS versions earlier this year, but it came many years after the previous jailbreak of that kind. Superuser access to my iOS device isn’t something I need to worry about. But if I ran Android? It would be a real threat.

This isn't really true. Jailbreaks are not the main concern here, privilege escalation vulnerabilities are. Those are discovered somewhat regularly in both Android and iOS. Jailbreaks on iOS make use of such vulnerabilities when they discover them, but most vulnerabilities are not discovered by jailbreakers. These sorts of vulnerabilities are also inherent to any complex operating system, not unique to Android.

Users "rooting" their Android phones also usually doesn't involve any sort of real exploit either. Android devices don't come with the ability for apps to run as root by default, and can have their firmware flashed to add a means of doing so. Doing this requires that the user unlock their bootloader, which wipes the device and often requires manufacturer authorization. Rooted devices have weakened security by being rooted, but this doesn't affect ordinary non-rooted devices.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#123

Earlier quoted context omitted.

> The chaos it would cause for US B2C businesses would be large. Literally who cares? Let them deal with it. It doesn't matter how much money they lose. They should have considered the consequences of abusing people's trust and violating their privacy under questionable consent. Corporations are vastly more powerful compared to individuals. Courts obviously need to favor the latter in the vast majority of cases. To d…

It was not a value judgement, just a prediction. Some judges do look at the impact of a ruling. I personally don't think they should be legally binding (as I suspect most HN readers do). "doesn't matter how much money they lose" -- of course it does, these companies employ people and generate lots of government revenue (even if they skirt corporate taxes).

And if they fold due to privacy violations, another company will usually take their place.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#124
post #121
post #55

The writer doesn't mention which apps he installed, nor which phone. I'd be interested in the details, does anyone know this underlying data?

Writer: Samsung Galaxy S7. I guess over 70 apps in navigation, weather, games, prayer apps, or relevant due to listing location companies in privacy policy. I have not named apps / companies I that were not relevant to this feature. I found other things, but I had to focus on a clear story.

Thank you.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#125

Earlier quoted context omitted.

I think without said "security" model, we wouldn't have so much malware. Because getting your exact location extracted and send to marketing firms and government contractors is worse than quite a few trojans you could get on your local computer by executing random and even malicious code. It is time that security experts get honest about this and that "experts" lower their voice a bit.

Are the experts experts or are the experts "experts"? In my experience, security expert generally are honest about this and should, if anything, raise their voices more .

A lot of "experts" are marketeers or work in the industry and have financial ambitions.

There is a technically correct argument that a locked down environment hinders the execution of malicious code, but for overall security, especially privacy and illegal data access, the current "security" solutions for smartphones perform very badly.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#126
post #6

Earlier quoted context omitted.

Thanks, I don't like Twitter for long form content. It's not designed for this.

I agree with you, but a hacky workaround is @mythreadreader

Yeah, hacky and annoying af when fifty people use it on the same thread, as is usually the case. Makes Twitter’s long-form readability and usability even worse.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#127

Earlier quoted context omitted.

What isn't understandable?

Being able to read the words doesn't mean the comment makes sense. Reading it over and over again, yeah sure I can understand it, but I don't see any "point" or relation to the original comment. Some people just seem to feel "smart" by wording things as convoluted as possible, using fancy words and references. The truth is, it is much harder to express thoughts clearly with simple, yet elegant words. Mostly because t…

Is that post too fancy though? Sure, "Linnaean classification" could/should be replaced with "taxonomy" or something similar for readability, but none of the rest of the post has and uncommon references or words. The point also seems obvious, and the relevance to the post self explanatory. This rant on obscurantism seems unwarranted with reference to a post written at a pretty standard reading level.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#128

Earlier quoted context omitted.

> The chaos it would cause for US B2C businesses would be large. Literally who cares? Let them deal with it. It doesn't matter how much money they lose. They should have considered the consequences of abusing people's trust and violating their privacy under questionable consent. Corporations are vastly more powerful compared to individuals. Courts obviously need to favor the latter in the vast majority of cases. To d…

It was not a value judgement, just a prediction. Some judges do look at the impact of a ruling. I personally don't think they should be legally binding (as I suspect most HN readers do). "doesn't matter how much money they lose" -- of course it does, these companies employ people and generate lots of government revenue (even if they skirt corporate taxes).

> these companies employ people and generate lots of government revenue (even if they skirt corporate taxes).

There are political and economic concerns, not judicial. The fact the company is important does nothing to remedy the fact that it exfiltrated private information to foreign intelligence agencies.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#129
post #3

The thread also mentions https://nrkbeta.no/2020/12/03/my-phone-was-spying-on-me-so-i... which would be a better link than twitter.

> For the sum of 35,000 NOK (3,300 EUR / 4,000 USD), we got access to location data showing where tens of thousands of Norwegians had travelled in 2019. > One of them was 31-year-old Karl Bjarne Bernhardsen from Stavanger. The information made it easy for us to identify him in the data that – according to the data provider – had been anonymised. Here’s that article: https://translate.googleusercontent.com/translate_c…

What causes me the most irritation (to put it mildly) is that I bought the Sygic navigator that seems to be the source of this data. And still they sell my data? Just last week they forced me to agree to some new rules to be able to use the app but I already bought it 7 years ago. I will be requesting my money back as stated by that agreement, and request a GDPR data dump for moving my data to another provider.

Re: My Phone Was Spying on Me, So I Tracked Down the Surveillants

#130

Why is "track and trace" a challenge when this exists?

Because there would (rightly) be an uproar if this were made more public, and “track and trace” is one of the most public things you can do with the data. Instead, we've got an almost completely private Bluetooth-based protocol… with implementations that go ahead and phone home anyway, without even using that phoned-home data for the track & trace system.
Post reply on HN