Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

101–110 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#101
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I have an old iPhone with an empty address book for testing dodgy apps that require contacts access, I use that for sending Clubhouse invites. OTOH, Clubhouse seem work fine on my primary phone, where I haven't given it contacts access.

For Android I can recommend "Shelter"[1] which lets you setup a work profile, so you dont have to share your contacts, files, etc.. Downside: If you have already a work profile, it does not work (Android allows only one work profile)

[1] https://f-droid.org/en/packages/net.typeblog.shelter/

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#102
post #75

Earlier quoted context omitted.

The US and EU have a treaty specifically about enforcing each other's laws. (More accurately, the nations that comprise the EU are individual signatories to such treaties.)

Source? This lawyer seems to think that there’s no applicable treaty. https://tinyletter.com/mbutterick/letters/you-re-not-the-bos...

Here's the one between the US and the largest economy in the EU:

https://www.congress.gov/treaty-document/108th-congress/27

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#103
post #42

Earlier quoted context omitted.

If some of your users are in the EU you need to be GDPR compliant.

This is what the law says, but I don’t understand how this is expected to work: without some kind of treaty from the US government, the EU has no way to make US companies comply.

There's a slew of individual things that can be done. EU companies can be prevented from doing business with a (willfully) noncompliant company. Wire transfers going through the EU and other operations can be blocked. And, of course, the service itself, its apps, its sites, its traffic, can be blocked from accessing the EU internet (or being accessed from it).

That's not even getting into international pressure levers.

I don't know that we've seen any of those kinds of actions yet, but they're clearly on the table if a company breaking the rules became a real "problem".

The thing is, if you're just completely avoiding doing any business with the EU, having any EU customers or users, and just not touching the EU with a 1000 mile pole and avoiding the GDPR in such a fashion - well, then there's no reason to go after you. The legislation has done its job.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#104
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

It's disingenuous of them to say they "have to" do contact upload. Why can't I type in a phone number to invite? Completely hostile. Consequently, I have invited nobody.

Same here. It also seems to burn through battery more quickly than other apps.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#106

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#110

Earlier quoted context omitted.

Well, a couple of things: (a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly. (b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harm…

A contact list often operates as a database of what number belongs to who, for guarding incoming calls. It can be a security tool.

In iOS and Android, incoming call blocks are in a separate database and explicitly not the contacts database.
Post reply on HN