Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

71–80 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#71
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

When you leak your contacts, you harm others, not just yourself.

This, among other reasons, is why I never give out the number of my SIM card, or my residential address, et c, to anyone. They're just going to click "allow" and give it to a thousand shady companies, starting with Facebook.

I never give people data I don't want stored in my shadow profile.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#72
post #55

Earlier quoted context omitted.

it is trivial to strip suffixes off of aliased email addresses

If you control your own email routing, by using your own mail server, Google Workspace, Microsoft 365, etc, you can choose whatever convention you want. How would you know to strip everything after my first name?

I wouldn't care about the people using their own mail server

I would just strip everything after a + sign

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#73

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

> but I suppose most people are not really traumatised by merely seeing someone's name

I mean there are cases where that can be devastating.

"Ohai here's your old abusive ex, here's a chat box just for good measure, good luck!".

There are people who I'd never ever want to be within a textbox and tap away from accessing me, for any reason, period.

You can get restraining orders in the physical world, the digital world however has no boundaries when the apps themselves are too stupid and are defined by real-world-illogical programming code. I wouldn't expect an app to understand a 'court order' but that's a real human construct. How do we design against that in the digital space, when you are so accessible that if you have a crazy dude following you you're basically forced to retreat as there's no effective measures/guards against this?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#74
post #29

Earlier quoted context omitted.

Because in European Union it is regulation, and you (as a company) are fined if you are not compliant. I recommend having a look over the Wikipedia page on the subject: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.

[deleted]

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#75
post #42

Earlier quoted context omitted.

If some of your users are in the EU you need to be GDPR compliant.

This is what the law says, but I don’t understand how this is expected to work: without some kind of treaty from the US government, the EU has no way to make US companies comply.

The US and EU have a treaty specifically about enforcing each other's laws. (More accurately, the nations that comprise the EU are individual signatories to such treaties.)

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#76
post #60
post #6

This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts.

"This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts." We (rsync.net) have a handful of dummy/fake users in our database whose emails we monitor. The email addresses are cryptic and random and use a different domain, etc. We should never see an email sent to one of these "canary" email addresses and, so far, we have not. I am also aware that many of our customers sign up w…

I've noticed a bunch of spammers starting to strip out anything after the + and before the @. This is why I've long used a catch-all e-mail domain (subdomain.example.net) where I can put anything I want to the left of the @ sign and no one is the wiser for my real e-mail address.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#77
post #67

Earlier quoted context omitted.

it is trivial to strip suffixes off of aliased email addresses

"it is trivial to strip suffixes off of aliased email addresses ..." This actually is not a bad point to make ... it would, in fact, be simple to strip +aliases but ... economically I don't think it makes any sense. You'd have to have a high level decision maker dictating an engineering fix in order to increase email authenticity by ... .01% ? ... and that assumes that the "engineers" down the chain understand how '+…

My response here is that I think this discussion is naive, as the data brokers themselves already do it.

So who cares about what some engineer at a random new business thinks.

Aliasing isn't new. So this isn't a cat and mouse game that just got started.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#78

Can someone please explain to me how the collection of contact data is in any way legal under the GDPR and why Microsoft (Windows), Apple/Google haven't been required to make changes to prevent abuse of this permission (such as selecting specific contacts). I'd also like to not know why if my contact data is shared, I am not informed of this. If my data is uploaded by Google to their servers, I should know. If somebo…

> and why Microsoft (Windows), Apple/Google haven't been required to make changes

I don't believe there's anything in the GDPR that gives it the ability to regulate entities several steps removed from the violations. If company A uses a posted letter to ask for PII then stores it in violation of the GDPR, would you then regulate the post office?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#80

Earlier quoted context omitted.

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

Yep. I can't claim to know how everyone else responds to these things. The Signal example isn't the worst. It's a mutual connection. It's not like they're emailing hundreds of people saying "Waterluvian wants you to get on signal!" What's to stop them from doing that when they get sufficiently desperate? I don't even own my contact lists. They seem to grow on their own with anyone I've ever emailed.

Signal does it for anyone in your address book, not just mutuals.

Your "anyone I've emailed" example is a great reason not to use the same service you use to host your email to host your contacts.

Personally I would never in a million years sync my contacts to Google, which I assume is what you mean here (most people use gmail).

Post reply on HN