Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

11–20 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#12
post #6

This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts.

What do you mean by "canary" in this context? How do you detect that the canary is dead?

I assume that the "canary being dead" ~= "an adversary added the contact to their watch list". But I don't think you can detect that.

The best you could do is to add a random physical address hoping that you can detect physical surveillance (which is probably not realistic anyway).

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#13
post #12
post #6

This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts.

What do you mean by "canary" in this context? How do you detect that the canary is dead? I assume that the "canary being dead" ~= "an adversary added the contact to their watch list". But I don't think you can detect that. The best you could do is to add a random physical address hoping that you can detect physical surveillance (which is probably not realistic anyway).

It is like signing up with an e-mail +suffix for services, or the non-existent streets on digital maps; if you come across your fake contact elsewhere, you know that information has been shared.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#14
post #12
post #6

This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts.

What do you mean by "canary" in this context? How do you detect that the canary is dead? I assume that the "canary being dead" ~= "an adversary added the contact to their watch list". But I don't think you can detect that. The best you could do is to add a random physical address hoping that you can detect physical surveillance (which is probably not realistic anyway).

Detection would require a call/sms/email. The idea would be just to detect, if your leaked data has been acted upon.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#15
> The app is designed to be very simple and fail silently. If you deny permission to access contacts, the app will not complain, it just will not work.

I don't understand the reason behind "designed to...fail silently" in this way, in a privacy&security measure.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#16
post #13
post #12

Earlier quoted context omitted.

What do you mean by "canary" in this context? How do you detect that the canary is dead? I assume that the "canary being dead" ~= "an adversary added the contact to their watch list". But I don't think you can detect that. The best you could do is to add a random physical address hoping that you can detect physical surveillance (which is probably not realistic anyway).

It is like signing up with an e-mail +suffix for services, or the non-existent streets on digital maps; if you come across your fake contact elsewhere, you know that information has been shared.

Exactly!

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#17
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#19
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

> Clubhouse requires contact list in order to get invites, which are required to sign up right now

How is this GDPR compliant?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#20
Not exactly on topic, but historical context maybe: Long ago (early 90s?) when it was guessed/assumed that intelligence agencies were scanning emails, emacs was still among the best ways to read and send email. So emacs provided a handy function to append a random list of "hot" words to each outgoing email in the signature, just to degrade the signal-to-noise of such surveillance.

It's still there today, and you can see the output via M-x spook.

Post reply on HN