Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

111–120 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#111

Not exactly on topic, but historical context maybe: Long ago (early 90s?) when it was guessed/assumed that intelligence agencies were scanning emails, emacs was still among the best ways to read and send email. So emacs provided a handy function to append a random list of "hot" words to each outgoing email in the signature, just to degrade the signal-to-noise of such surveillance. It's still there today, and you can…

Such an interesting context. Thanks for sharing this. I appreciate the nostalgia poetics of this today.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#112
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

In my case, I don't even remember giving them permission to use my contacts, yet I got accepted because one of my contacts sent me an invite.

I might have given them permission without realizing it, but what could've also happened is that they saw my phone number in someone else's contact list, and assumed we were contacts.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#113
This is a common technique in the mailing list industry. It's called "salting". You add fake names, but real email addresses, street addresses, or post office boxes. You then monitor what shows up in these places addressed to "Mr. Fake Name". It's how mailing list companies monitor who is using their lists and helps control misuse.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#114

Not exactly on topic, but historical context maybe: Long ago (early 90s?) when it was guessed/assumed that intelligence agencies were scanning emails, emacs was still among the best ways to read and send email. So emacs provided a handy function to append a random list of "hot" words to each outgoing email in the signature, just to degrade the signal-to-noise of such surveillance. It's still there today, and you can…

That used to be the case on usenet too - people would put attention-grabbing words in .signature as "NSA Food" - to overwhelm the NSA data capture algos. It seemed like a futile gesture even at the time, but particularly poignant looking back from a post-Snowden world.

The real poignancy is the shift in hacker political views. Call it post-software-is-sexy world. Those usenet sigs were by hackers who lived in a world where software engineer or programmer were social reject code words. That world changed after geeks came into money. Suddenly but soon thereafter, paranoia about privacy was rewarded by tinfoil hats. (And then yes, years later, came along this guy called Snowden.)

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#115

Earlier quoted context omitted.

> but I suppose most people are not really traumatised by merely seeing someone's name I mean there are cases where that can be devastating . "Ohai here's your old abusive ex, here's a chat box just for good measure, good luck!". There are people who I'd never ever want to be within a textbox and tap away from accessing me, for any reason, period. You can get restraining orders in the physical world, the digital worl…

Well, a couple of things: (a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly. (b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harm…

Why do you have the authority to dismiss many's experience of a feature? Because you can think of a way you would handle it and you've read some things?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#116
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

They are in california. They can give the finger to the gpdr. It's irrelevant to most people in the world

People tend to forget that it is not applicable. For instance nothing I build will ever comply to it regardless of users that might be in europe

Clubhouse has no duty to obey european law

The question is: why do you think the need to be compliant?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#117
Sad state of affairs. AOL couldn't kill the open web, but "apps" have.

The user agent should respect your wishes, but instead we are reduced to this insane work-around.

Surveillance capitalism needs to die in a fire. To anybody working on that shit: I hate you. Personally, as an individual, I wish you harm.

OK, that was hyperbole, but I do love the open web. RIP.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#118

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

You don't bounce emails you prebounce them and clean up your list. This is part of any sensible data engineers process.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#119
post #75

Earlier quoted context omitted.

The US and EU have a treaty specifically about enforcing each other's laws. (More accurately, the nations that comprise the EU are individual signatories to such treaties.)

Source? This lawyer seems to think that there’s no applicable treaty. https://tinyletter.com/mbutterick/letters/you-re-not-the-bos...

There is no legal mechanism because such exist mostly for criminal law and civil and public debt collection. So the EU maybe cannot use most of the enforcement mechanisms, except one: You can be fined some amount of money, creating a public debt which can then be collected if there is a treaty about such collections.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#120

Earlier quoted context omitted.

I've noticed a bunch of spammers starting to strip out anything after the + and before the @. This is why I've long used a catch-all e-mail domain (subdomain.example.net) where I can put anything I want to the left of the @ sign and no one is the wiser for my real e-mail address.

Is there some service where I can easily create unlimited custom email addresses for a flat monthly fee? I want to use a unique email for each new website/service. That would go a long way to solving some data leak/privacy problems. The problem with custom domain is I have to maintain it right? I want a service which I don't have to maintain. I used to use new Yahoo accounts but they are a hassle and recently they di…

Protonmail allows wildcard emails from 1 custom domain if you pay for the ~$5/mo plan. No maintaining a mail server, just point your MX records to their servers.
Post reply on HN