Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

141–150 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#141

Earlier quoted context omitted.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

You don't bounce emails you prebounce them and clean up your list. This is part of any sensible data engineers process.

More helpfully, salting their db with real emails but fake contact info requires a more durable hygiene process and often isn't worth the effort for data driven shops.

You serve a variety of email domains that validate as deliverable, then you accept emails and report the sender, which hurts their deliverability.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#142

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

Even if you make your contact list 99% bounces and 1% real (and every user of the app does the same), I don't see how this becomes a problem for the app's operator. Remove a contact after 1-2 bounces and you're golden.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#143

Earlier quoted context omitted.

If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.

If you're operating a business that interacts with customers in the EU, GDPR applies.

I thought US companies had to agree to Privacy Shield if they wanted to be considered GDPR-regulated.

https://www.privacyshield.gov/welcome

Why any US company would voluntarily agree to this is beyond me, unless one of its EU customers insisted on it.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#144
post #80

Earlier quoted context omitted.

Signal does it for anyone in your address book, not just mutuals. Your "anyone I've emailed" example is a great reason not to use the same service you use to host your email to host your contacts. Personally I would never in a million years sync my contacts to Google, which I assume is what you mean here (most people use gmail).

Probably. Contacts have been confusing. I've had Gmail list. My phone. What's in my Sim card. My Sony contact list... I had a really infuriating time trying to clean them all up many years ago and I've just tapped out.

Same here. I recently went to LineageOS and use fastmail for email/contacts/calendar. It's been wonderful.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#145

Earlier quoted context omitted.

Well, a couple of things: (a) You can't take seeing their name, but you keep them in your contacts? Don't you occasionally scroll past it with a call button right there, which is just as easy to hit and put you in touch with them? How is this any different? Seems a bit silly. (b) As far as I know, research suggests hyper-avoidance is not a good way to resolve trauma. So I'm not convinced by the idea that this is harm…

Why do you have the authority to dismiss many's experience of a feature? Because you can think of a way you would handle it and you've read some things?

Because we're all here talking about how things should be designed, which often inherently requires fulfilling some needs at the expense of others? Not quite sure how you expect those decisions to be made without people gathering to discuss the relative merits of each approach.

If you're about to tell me we should just implement every user request that they claim is of 10/10 importance to them personally, then I'm not even sure what to tell you. Have you taken all of a few seconds to consider what happens when two people make conflicting requests? Then we're back to evaluating things and discussing them again. How arrogant of us.

I appreciate the implied authority you've given yourself to be the conversation police, though.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#146

Earlier quoted context omitted.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

You don't bounce emails you prebounce them and clean up your list. This is part of any sensible data engineers process.

what is prebounce?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#147
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

[flagged]

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#148

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

[deleted]

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#149
All the shady data schemes and dark patterns in todays idea of software business motivated me to look to my phone as an enemy and using the web cautiously all the time. Actually the idea of hyperconnected future in which 24/7 monitoring of the individuals will be normalised and mandatory makes me cringe. The Internet from force of good is turning to dystopian toolchain by the hour. And all is because we as society cannot find an effective way to limit the greed.
Post reply on HN