Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

181–190 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#181
On Android, IIRC I've seen a dialer app that stores contacts in its own database instead of the system thing. Seems to be a better approach than this—at least if other apps also don't write to the shared contacts.

(It was probably an open-source dialer on F-Droid, but don't remember exactly which one.)

Anyway, an even better approach of course is to tell data-slurping apps to bugger off.

Edit: come to think of it, maybe alternative Android ROMs could fence the contacts so that an app only sees its own unless the user specifically selects someone. I guess this is similar to Apple's trick with Photos.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#182

Earlier quoted context omitted.

>> some apps check for what apps are installed on the device I can't believe that's allowed by the OS - seems like a horrible policy.

agreed. Id like to see a source or reference for this.

https://arstechnica.com/information-technology/2020/03/4000-...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#183
post #122

Earlier quoted context omitted.

it is trivial to strip suffixes off of aliased email addresses

What is the equivalent to that in the fake phone contacts domain? I guess removing people with the +21 country code would work for this particular approach, but otherwise...?

Good question hmm, I think its just a different strategy with phone contacts

A data broker primarily wants the social graph to make a user profile with a phone number, to show ads later on. Those people wont typically be texting or calling with spam and ads, theyll just match the number and contacts up with information shared in other apps so that ads in your normal internet browser or ad-include app use are more targeted

so if an erroneous contact never logs in thats of no consequence to them, so searching to exclude numbers would be less interesting and less likely than with just sanitizing emails

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#184

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

"Did this cause trauma" is not the bar we're trying to set here, any level of anxiety caused by tech companies misusing contacts is bad.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#185
post #149

All the shady data schemes and dark patterns in todays idea of software business motivated me to look to my phone as an enemy and using the web cautiously all the time. Actually the idea of hyperconnected future in which 24/7 monitoring of the individuals will be normalised and mandatory makes me cringe. The Internet from force of good is turning to dystopian toolchain by the hour. And all is because we as society ca…

Wait until iot becomes mainstream. I foresee tiny chips creating mass scale mutiny against their creators and colonizing us (best case scenario)

I wonder how dystopian sci-fi would read in such future? I mean...what would be their parable of The Matrix?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#187
post #100
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Clubhouse can bite me. I refuse to use tooling from shitbags who try to exort me into compromising others' privacy for shiny toys. I know other shops do it, as if that makes it OK.

Server is in the People's Republic of China to boot. But I know we have many wumaos and apologists here on HN because they tasted blood money.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#188
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

First I have to keep a burner number with a real sim card for things that require signup, now I have to keep a burner phone with no contacts?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#189
Is it possible to create a network of contacts that triggers worst-case memory and cpu scenarios when the network is reconstructed from contacts?

Or, put another way, can a collection of people doing this construct a set of synthetic contacts spread out in various ways across their devices, such that anyone doing contact analysis sees their analyses slow down, drain resources, or crash altogether due to network structure?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#190
post #134
post #47

Earlier quoted context omitted.

"The GDPR also applies to data controllers and processors outside of the European Economic Area (EEA) if they are engaged in the "offering of goods or services" (regardless of whether a payment is required) to data subjects within the EEA, or are monitoring the behaviour of data subjects within the EEA (Article 3(2)). The regulation applies regardless of where the processing takes place. This has been interpreted as…

Countries or groups of countries don't get to impose their law on other countries. That's called colonialism, and Europe is supposed to have given it up.

I wonder when the USA will follow suit?
Post reply on HN