Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

151–160 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#151
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

What about dividing your contacts into circles and only give permission to a specific set?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#152
post #50

Earlier quoted context omitted.

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

> How is this GDPR compliant? It isn't, really, but the question whom to prosecute is complicated. Clubhouse gets the contact list data from you, the user. Usually, somewhere in the ToS, there is a little thing where you confirm to have the right to share all the data you share with Clubhouse. That means that first and foremost, you as a user are responsible. If you are a non-commercial user using Clubhouse from your…

On Android if you use Work Profile your work contacts are in a separate partition and can only be accessed by approved company apps. This works really well for gdpr compliance with dual-use (company & mobile) devices.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#153

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

Pretty nifty side point:

> If enough people do this the cost of those bouncing emails would become prohibitive.

This idea got a ton of attention in early days tech that led to what's known as proof of work: see bitcoin. The primitives of btc show up in a lot of interesting areas.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#154

Remember: some apps check for what apps are installed on the device, and if they see this installed they can deduce you're poisoning the well. Also if you want to research obfuscation and how it thwarts surveillance, check these: https://www.schneier.com/blog/archives/2019/11/obfuscation_a... https://www.science20.com/news_articles/obfuscation_how_to_h... https://www.theguardian.com/technology/2015/oct/24/obfuscati..…

>> some apps check for what apps are installed on the device I can't believe that's allowed by the OS - seems like a horrible policy.

agreed. Id like to see a source or reference for this.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#155
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Here's how to get around Clubhouse uploading contacts. We shouldn't have to do this, but here we are.

1. Disable contacts for all your configured accounts 2. Add a dummy Gmail account, enable contacts. 3. Add invitee to dummy account 4. Give contacts access to Clubhouse 5. Send invite 6. Remove contact access 7. enable contacts disabled in 1

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#156
post #134
post #47

Earlier quoted context omitted.

"The GDPR also applies to data controllers and processors outside of the European Economic Area (EEA) if they are engaged in the "offering of goods or services" (regardless of whether a payment is required) to data subjects within the EEA, or are monitoring the behaviour of data subjects within the EEA (Article 3(2)). The regulation applies regardless of where the processing takes place. This has been interpreted as…

Countries or groups of countries don't get to impose their law on other countries. That's called colonialism, and Europe is supposed to have given it up.

I am not a lawyer, and I don't claim I understand the legal mechanisms involved. I don't even claim GDPR is perfect.

But, as I see it, EU is protecting its citizens. If you want to do business with EU citizens you must abide by EU regulations. It's that simple. I don't get how this came to be all of a sudden about colonialism. Any business is free to stay out of EU.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#157
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

What about dividing your contacts into circles and only give permission to a specific set?

Sure, as long as it’s possible to create a circle containing only one contact, the way giving permission to access photos now works on iOS.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#158

Earlier quoted context omitted.

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

I've got a dead friend that I'm reminded about every time I open signal. "DeceasedFriend is on signal!". No, no he is not. I'm sure I could clear it, but I don't really want to yet. On the whole, I still like the feature.

I'm sorry about your friend. I've had similar experiences with tech products, but I tend to think that unexpected reminders (of any kind) are all part of the process of dealing with loss. That hyper-avoidance seems an unhealthy route, popular though it is in modern discussions about emotionally difficult subjects.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#159
post #53

Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app. This allows the user to respond positively to an access request, but allow the app to see only a subset (or zero) actual photos. It would be a very useful feature for Apple to do the same for contacts: the app would think it's getting access to your contacts, but would only actually receive a subset of them…

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

I didn't realize iOS doesn't have that. Google Play shows each app's permissions on the listings page.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#160

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

It will be interesting to see if these fake contacts show up in a leak somewhere someday. Almost like how people do myname+yourcompany@gmail.com, we could create similarly fake contacts to see who is selling or leaking data.
Post reply on HN