Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

31–40 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#31
post #22

Earlier quoted context omitted.

Why would you want to be GDPR compliant?

To avoid substantial financial risk.

Has the EU sued and won against any company who is not located in the EU?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#32
Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app. This allows the user to respond positively to an access request, but allow the app to see only a subset (or zero) actual photos.

It would be a very useful feature for Apple to do the same for contacts: the app would think it's getting access to your contacts, but would only actually receive a subset of them, and be none the wiser. This would be a tremendous boon for privacy.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#33
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

I think this is a wording issue if you haven't used Clubhouse.

You don't need to share contacts in order to get invited, like you don't have to do it to use the platform. You have to do it to invite others (like your friend that you told about Clubhouse) after you are already on the platform, so that is not regulated by GDPR.

It is a shitty user experience and I also want Apple to control this at the OS level. Let me select which contacts if I want to do it at all.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#34

Earlier quoted context omitted.

To avoid substantial financial risk.

Has the EU sued and won against any company who is not located in the EU?

That's not a good test, because the law is still relatively new, and it takes a while for litigation to make its way through the system. We also don't necessarily know who has settled out of court.

Would you like to be a test case for us?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#35
post #29
post #22

Earlier quoted context omitted.

Why would you want to be GDPR compliant?

Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#36

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then.

Having said that, I think it would be nice for Apple to implement what you describe.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#37
post #13
post #12

Earlier quoted context omitted.

What do you mean by "canary" in this context? How do you detect that the canary is dead? I assume that the "canary being dead" ~= "an adversary added the contact to their watch list". But I don't think you can detect that. The best you could do is to add a random physical address hoping that you can detect physical surveillance (which is probably not realistic anyway).

It is like signing up with an e-mail +suffix for services, or the non-existent streets on digital maps; if you come across your fake contact elsewhere, you know that information has been shared.

it is trivial to strip suffixes off of aliased email addresses

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#38
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

I see the point, but if I upload my contract list the non compliance is mine (I didn't ask permission to each one of my contacts) or of Clubhouse (they asked me to do it)?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#39
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Would never sign up or use a service that has such an invasive requirement..I only use my google voice number for any type of public to even dating transaction. Spam and robocall that all you want which I surprising never receive/received many such calls.
Post reply on HN