Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
41–50 of 363 posts
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#42Earlier quoted context omitted.
Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#43Imagine if your fake contact's randomly created email or phone number is on a terror watch list.
The documentation states that it uses a non-allocated country code (+21). So it seems unlikely to happen.
+211 South Sudan
+212 Morocco
+213 Algeria
+216 Tunisia
+218 Libya
Someone putting random numbers after +21 because it's unallocated has a fundamental misunderstanding of international phone numbers.But also, the server side is likely to throw away invalid numbers to start with. It's simple and easy to do, and reduces the data storage by a lot (there's a lot of garbage in people's address books)
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#44Earlier quoted context omitted.
Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#45Earlier quoted context omitted.
Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#46Earlier quoted context omitted.
> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?
I see the point, but if I upload my contract list the non compliance is mine (I didn't ask permission to each one of my contacts) or of Clubhouse (they asked me to do it)?
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#47Earlier quoted context omitted.
Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.
Source: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#48Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…
Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…
The Signal example isn't the worst. It's a mutual connection. It's not like they're emailing hundreds of people saying "Waterluvian wants you to get on signal!"
What's to stop them from doing that when they get sufficiently desperate? I don't even own my contact lists. They seem to grow on their own with anyone I've ever emailed.
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#49Earlier quoted context omitted.
If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.
If some of your users are in the EU you need to be GDPR compliant.
Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning
#50Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…
> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?
It isn't, really, but the question whom to prosecute is complicated. Clubhouse gets the contact list data from you, the user. Usually, somewhere in the ToS, there is a little thing where you confirm to have the right to share all the data you share with Clubhouse. That means that first and foremost, you as a user are responsible.
If you are a non-commercial user using Clubhouse from your private phone, what you do with your private contacts isn't covered by GDPR, private stuff is an exception. However, as consumer, European legislation protects you from surprising and unusual terms, which this might be. Legislation might also protect all your contacts. However, this is a question that still needs to be litigated in court, and I don't remember any decisions around that problem (WhatsApp basically has the same constellation).
If you are a commercial user, because this is your work phone and your contacts are colleagues, business partners, customers, things are quite different. You are, as a data processor, responsible for how you pass on your contact list. You better make sure that you are allowed to do that (because you have a GDPR-compliant reason like legal obligation, contractual obligation with your customer, assent or legitimate interest) and that your contacts have been informed about what you are doing beforehand. Also, you then need a written contract with Clubhouse about the data being passed along, about how it will be used and protected, etc. Also, passing along the contacts to Clubhouse must be necessary for a predetermined, well-defined reason that can be considered more important than your contacts' right to privacy.
So as a private person, you might get away with using Clubhouse. As a company, employee, self-employed, state official, whatever, you are probably in hot water, because surely you didn't do all the required things. But for Clubhouse this might not be a problem, because as current case law stands (imho, iirc, ianal, ...) Clubhouse isn't the party that did something wrong there.