Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

231–240 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#231
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

And this tells me that there is a need for another step up for this app - to not only poison the contacts, but to temporarily 1) backup => 2) delete => 2a) share poisoned list => 3) restore contacts.

So we can share the list, but they'll never get our real contacts, only trash data. Enough use it, maybe they'll stop

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#232
post #156

Earlier quoted context omitted.

I am not a lawyer, and I don't claim I understand the legal mechanisms involved. I don't even claim GDPR is perfect. But, as I see it, EU is protecting its citizens. If you want to do business with EU citizens you must abide by EU regulations. It's that simple. I don't get how this came to be all of a sudden about colonialism. Any business is free to stay out of EU.

And any EU citizen is free to not do business with a company outside the EU. Do you think the EU laws should apply to people selling things to EU citizens while they are on vacation in other parts of the world? If someone from Germany travels to Brazil and buys something from a store, are they required to abide by EU rules? If someone from the EU leaves the EU digitally to buy something in another country, it isn't u…

There's an asymmetry of information and power in the relationship between a business and a citizen. Governments, generally, attempt to mitigate this asymmetry. Hence, we have consumer protection laws, GDPR and the likes.

While these solutions may be incomplete, or imperfect, having none is definitely worse.

> If someone from the EU leaves the EU digitally to buy something in another country, it isn't up to the seller to enforce EU rules.

> Unless you have an entity (either yourself or your business) under EU jurisdiction, you don't have to follow their rules.

Please _do_ read the link I already posted in a previous comment [0]. It clarifies many things, but I don't want to paste too much content here.

[0]: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#234
post #227
post #156

Earlier quoted context omitted.

I am not a lawyer, and I don't claim I understand the legal mechanisms involved. I don't even claim GDPR is perfect. But, as I see it, EU is protecting its citizens. If you want to do business with EU citizens you must abide by EU regulations. It's that simple. I don't get how this came to be all of a sudden about colonialism. Any business is free to stay out of EU.

> If you want to do business with EU citizens you must abide by EU regulations. No, no more than if I want to do business with Saudis I'm liable for punishment if I drink a beer.

But that's not really a good analogy (not that analogies are proof). A better analogy would be you selling beers in Saudi Arabia.

I urge you to read this, it should clarify things:

Applicability outside of the European Union:

https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#235

Is it possible to create a network of contacts that triggers worst-case memory and cpu scenarios when the network is reconstructed from contacts? Or, put another way, can a collection of people doing this construct a set of synthetic contacts spread out in various ways across their devices, such that anyone doing contact analysis sees their analyses slow down, drain resources, or crash altogether due to network struc…

Wouldn't any worthy graph explorer handle cycles ?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#236

This is not achieving anything positive. I don’t which privacy threat it’s fixing, other than adding a new app into the mix that could at some point in the future suck up the contacts itself:)

That is pretty insightful. Do you have an email ?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#237

To everyone talking about Clubhouse, there isn't an android version so this code is not useful as it is only for android

TIL The vast userbase of HN is 95% Apple, 3% Android, 0.0005% Pinephone. The remaining ~1% don't even make a digital footprint since they use the old Nokia 3310 type phones.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#239

Is it possible to create a network of contacts that triggers worst-case memory and cpu scenarios when the network is reconstructed from contacts? Or, put another way, can a collection of people doing this construct a set of synthetic contacts spread out in various ways across their devices, such that anyone doing contact analysis sees their analyses slow down, drain resources, or crash altogether due to network struc…

Wouldn't any worthy graph explorer handle cycles ?

If I had a nickel for every time an algorithm was found to have an exploitable weakness due to unforeseen alignments of input, I’d certainly have some nickels. We know what the common screwups in crypto are, and we could know what common screwups in network graphs are. I’m just wondering if anyone actually does know of any of those.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#240

Earlier quoted context omitted.

> Clubhouse requires contact list in order to get invites, which are required to sign up right now How is this GDPR compliant?

They are in california. They can give the finger to the gpdr. It's irrelevant to most people in the world People tend to forget that it is not applicable. For instance nothing I build will ever comply to it regardless of users that might be in europe Clubhouse has no duty to obey european law The question is: why do you think the need to be compliant?

This is not how it works. If you make it available to EU users, you have to comply with GDPR (at least when it comes to those user's data).

For the same reason WhatsApp's new T&Cs don't really change anything for EU users.

However I don't think the collection of contacts is actually illegal under GDPR, considering WhatsApp does exactly this too. And it's huge in Europe, much bigger than in the US. if they haven't gone after WhatsApp for this, they will probably not do so for Clubhouse.

Post reply on HN