Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

91–100 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#91

Earlier quoted context omitted.

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

> but I suppose most people are not really traumatised by merely seeing someone's name I mean there are cases where that can be devastating . "Ohai here's your old abusive ex, here's a chat box just for good measure, good luck!". There are people who I'd never ever want to be within a textbox and tap away from accessing me, for any reason, period. You can get restraining orders in the physical world, the digital worl…

Well, a couple of things:

(a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly.

(b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harmful, especially when you can control it through (a).

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#92
post #87

Earlier quoted context omitted.

If they saw this app installed, what might they actually do about me or my contact list?

Remove all contacts that first name and last name start with Z. Docs say that they prefix every first & last name with Z so that would be a start.

Also: check for contacts with weird country-code prefixes that don't match the country the user is based in

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#93
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

Fomo is a helluva drug.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#94
post #60

Earlier quoted context omitted.

"This makes me wonder if anyone has set up canary emails or phone numbers in their phone contacts." We (rsync.net) have a handful of dummy/fake users in our database whose emails we monitor. The email addresses are cryptic and random and use a different domain, etc. We should never see an email sent to one of these "canary" email addresses and, so far, we have not. I am also aware that many of our customers sign up w…

I've noticed a bunch of spammers starting to strip out anything after the + and before the @. This is why I've long used a catch-all e-mail domain (subdomain.example.net) where I can put anything I want to the left of the @ sign and no one is the wiser for my real e-mail address.

Is there some service where I can easily create unlimited custom email addresses for a flat monthly fee? I want to use a unique email for each new website/service. That would go a long way to solving some data leak/privacy problems. The problem with custom domain is I have to maintain it right? I want a service which I don't have to maintain. I used to use new Yahoo accounts but they are a hassle and recently they disabled free auto-forwarding.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#95

Earlier quoted context omitted.

> but I suppose most people are not really traumatised by merely seeing someone's name I mean there are cases where that can be devastating . "Ohai here's your old abusive ex, here's a chat box just for good measure, good luck!". There are people who I'd never ever want to be within a textbox and tap away from accessing me, for any reason, period. You can get restraining orders in the physical world, the digital worl…

Well, a couple of things: (a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly. (b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harm…

A contact list often operates as a database of what number belongs to who, for guarding incoming calls. It can be a security tool.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#96
post #63

Earlier quoted context omitted.

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

> It shouldn’t be possible for apps to say you have to agree to this or I won’t run. It's not - that's a violation of the App Store TOS. That's also not what's happening here - you can use clubhouse without allowing contacts access, but you can't invite someone to the closed beta without allowing it.

GP means that it shouldn't be technologically possible, not just that it shouldn't be possible as a matter of policy.

The policy solution clearly doesn't work in all scenarios because Clubhouse is still on the store. But an on-they-fly permission model that allowed the user to deny the permission invisibly or share a subset of their contacts would completely solve the problem regardless of whether or not Apple was effective at moderating.

Apple could still do whatever moderation they wanted to reduce annoyances for the end user, but the sandboxing approach would catch any apps they missed or refused to moderate.

This would also solve the problem where an app legitimately needs some access to contacts to run, but doesn't need access to the entire list. Clubhouse does need access to some contacts to invite someone to the beta, but it does not need access to the entire contacts list, and there's no reason for it to have the ability to tell whether or not a user is providing the full list.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#97
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

App Store guidelines forbid using the Contacts for anything except the intended purpose: https://appleinsider.com/articles/18/06/12/apple-disallows-d... Do we give CH the benefit of the doubt =p ? In any case, I also hope (and expect) Apple to implement better controls for sharing contacts. EDIT: Typo

Huh, so Clubhouse is explicitly breaking Apple's rules.

Surely Apple knows this, but is allowing it because... it's mega-popular?

What's the point of having rules if clawing your way to popularity by leveraging their violation is deemed permissible?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#99

Earlier quoted context omitted.

Well, a couple of things: (a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly. (b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harm…

A contact list often operates as a database of what number belongs to who, for guarding incoming calls. It can be a security tool.

You can generally block calls by number, without having them as a named contact.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#100
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Clubhouse can bite me.

I refuse to use tooling from shitbags who try to exort me into compromising others' privacy for shiny toys.

I know other shops do it, as if that makes it OK.

Post reply on HN