Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

81–90 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#82
post #38

Earlier quoted context omitted.

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

I see the point, but if I upload my contract list the non compliance is mine (I didn't ask permission to each one of my contacts) or of Clubhouse (they asked me to do it)?

It should be blaringly obvious to Clubhouse that they don't have the right to even store most of this data, let alone use it for anything.

So even if you are at fault, I can't imagine that would help them a lot, if some data protection authority looked into this.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#83
post #53

Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app. This allows the user to respond positively to an access request, but allow the app to see only a subset (or zero) actual photos. It would be a very useful feature for Apple to do the same for contacts: the app would think it's getting access to your contacts, but would only actually receive a subset of them…

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

They have added that, but it's written by the app developers so you still can't trust what they claim they're gathering from you.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#84
post #75

Earlier quoted context omitted.

This is what the law says, but I don’t understand how this is expected to work: without some kind of treaty from the US government, the EU has no way to make US companies comply.

The US and EU have a treaty specifically about enforcing each other's laws. (More accurately, the nations that comprise the EU are individual signatories to such treaties.)

Source? This lawyer seems to think that there’s no applicable treaty.

https://tinyletter.com/mbutterick/letters/you-re-not-the-bos...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#85

Is there a limit on the number of contacts Clubhouse would sync?

It's incredibly unlikely. This kind of social graph information is gold .

I suspect it is less valuable than call logs. I have never deleted contacts so I have over twenty years of entries with pretty low value (e.g. call this number to find out about this real estate offering; my old mechanics for on 2003 old phone number) or accuracy. I only call about seven people but those are significant links.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#86
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

App Store guidelines forbid using the Contacts for anything except the intended purpose: https://appleinsider.com/articles/18/06/12/apple-disallows-d...

Do we give CH the benefit of the doubt =p ?

In any case, I also hope (and expect) Apple to implement better controls for sharing contacts.

EDIT: Typo

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#87

Remember: some apps check for what apps are installed on the device, and if they see this installed they can deduce you're poisoning the well. Also if you want to research obfuscation and how it thwarts surveillance, check these: https://www.schneier.com/blog/archives/2019/11/obfuscation_a... https://www.science20.com/news_articles/obfuscation_how_to_h... https://www.theguardian.com/technology/2015/oct/24/obfuscati..…

If they saw this app installed, what might they actually do about me or my contact list?

Remove all contacts that first name and last name start with Z.

Docs say that they prefix every first & last name with Z so that would be a start.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#88
post #80

Earlier quoted context omitted.

Yep. I can't claim to know how everyone else responds to these things. The Signal example isn't the worst. It's a mutual connection. It's not like they're emailing hundreds of people saying "Waterluvian wants you to get on signal!" What's to stop them from doing that when they get sufficiently desperate? I don't even own my contact lists. They seem to grow on their own with anyone I've ever emailed.

Signal does it for anyone in your address book, not just mutuals. Your "anyone I've emailed" example is a great reason not to use the same service you use to host your email to host your contacts. Personally I would never in a million years sync my contacts to Google, which I assume is what you mean here (most people use gmail).

Probably. Contacts have been confusing. I've had Gmail list. My phone. What's in my Sim card. My Sony contact list...

I had a really infuriating time trying to clean them all up many years ago and I've just tapped out.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#89
post #63

Earlier quoted context omitted.

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

> It shouldn’t be possible for apps to say you have to agree to this or I won’t run. It's not - that's a violation of the App Store TOS. That's also not what's happening here - you can use clubhouse without allowing contacts access, but you can't invite someone to the closed beta without allowing it.

They must know that I have disallowed access in that case.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#90
I don't see what the point is.

"Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones?

Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database?

If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that.

I don't get it.

Post reply on HN