Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

51–60 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#51
Remember: some apps check for what apps are installed on the device, and if they see this installed they can deduce you're poisoning the well.

Also if you want to research obfuscation and how it thwarts surveillance, check these:

https://www.schneier.com/blog/archives/2019/11/obfuscation_a...

https://www.science20.com/news_articles/obfuscation_how_to_h...

https://www.theguardian.com/technology/2015/oct/24/obfuscati...

https://adnauseam.io/

https://bengrosser.com/projects/go-rando/

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#52

Earlier quoted context omitted.

If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.

If you're operating a business that interacts with customers in the EU, GDPR applies.

The EU says it applies but, AFAICT there’s no legal mechanism by which it applies.

Here’s a lawyer’s take on this: https://tinyletter.com/mbutterick/letters/you-re-not-the-bos...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#53

Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app. This allows the user to respond positively to an access request, but allow the app to see only a subset (or zero) actual photos. It would be a very useful feature for Apple to do the same for contacts: the app would think it's getting access to your contacts, but would only actually receive a subset of them…

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app."

What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app.

I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to utilize and which of them are required to function.

It would be trivially easy to list that in the app store, for each app.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#54
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I have an old iPhone with an empty address book for testing dodgy apps that require contacts access, I use that for sending Clubhouse invites. OTOH, Clubhouse seem work fine on my primary phone, where I haven't given it contacts access.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#55
post #13

Earlier quoted context omitted.

It is like signing up with an e-mail +suffix for services, or the non-existent streets on digital maps; if you come across your fake contact elsewhere, you know that information has been shared.

it is trivial to strip suffixes off of aliased email addresses

If you control your own email routing, by using your own mail server, Google Workspace, Microsoft 365, etc, you can choose whatever convention you want.

How would you know to strip everything after my first name?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#56

Remember: some apps check for what apps are installed on the device, and if they see this installed they can deduce you're poisoning the well. Also if you want to research obfuscation and how it thwarts surveillance, check these: https://www.schneier.com/blog/archives/2019/11/obfuscation_a... https://www.science20.com/news_articles/obfuscation_how_to_h... https://www.theguardian.com/technology/2015/oct/24/obfuscati..…

If they saw this app installed, what might they actually do about me or my contact list?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#57
post #22

Earlier quoted context omitted.

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

Why would you want to be GDPR compliant?

https://www.jdsupra.com/legalnews/clubhouse-app-faces-court-...

On a side note, Germans are obsessed with Clubhouse.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#58
Can someone please explain to me how the collection of contact data is in any way legal under the GDPR and why Microsoft (Windows), Apple/Google haven't been required to make changes to prevent abuse of this permission (such as selecting specific contacts).

I'd also like to not know why if my contact data is shared, I am not informed of this. If my data is uploaded by Google to their servers, I should know. If somebody chooses to share my data with $app I should know, and, be able to "opt-out" of being included, perhaps (although it should be opt-in!)

Being able to mass collect what is often the most sensitive information means that consistent data is now a liability; keeping the same number/email can be useful for cross-referencing. Ideally you should rotate what data you can (physical address/location is obviously extremely difficult). Everything else is possible (browsers/IP addresses/emails/User Agent strings, phone numbers etc etc)

The best idea is to "troll" with your data; put insane items in your logged in basket (ebay/amazon etc), like sex toys. You can even make an order (and refund it) to further poison the well. Log in to Google and do some disgusting searches, and train algorithms to have the "wrong idea" about you, this is a reality we're now facing as this data can (and will) be used against you at any opportunity.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#59

Can someone please explain to me how the collection of contact data is in any way legal under the GDPR and why Microsoft (Windows), Apple/Google haven't been required to make changes to prevent abuse of this permission (such as selecting specific contacts). I'd also like to not know why if my contact data is shared, I am not informed of this. If my data is uploaded by Google to their servers, I should know. If somebo…

The best idea is to not use their services. Switch from Windows to Linux, de-google and if you must use Android keep the data on your phone to a minimum.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#60
post #6

This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts.

"This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts."

We (rsync.net) have a handful of dummy/fake users in our database whose emails we monitor. The email addresses are cryptic and random and use a different domain, etc.

We should never see an email sent to one of these "canary" email addresses and, so far, we have not.

I am also aware that many of our customers sign up with service-specific email addresses, using the '+' character ... something like john+rsync@mydomain.com.

I personally have a rich and well developed pseudonym that I use for all online non-governmental transactions but in some rare cases I need to use my actual name and email - and in those cases I create '+' aliases.

Post reply on HN