Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

241–250 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#241
post #209

Earlier quoted context omitted.

0. Don't use Clubhouse because it adds no value?

When you run a business, you have to go where the people are. If my customers are there, I have to be there.

I’d think that depends on the business. What is the engagement like on clubhouse? Do you participate or just have a presence?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#242
post #211

Earlier quoted context omitted.

I have an old iPhone with an empty address book for testing dodgy apps that require contacts access, I use that for sending Clubhouse invites. OTOH, Clubhouse seem work fine on my primary phone, where I haven't given it contacts access.

If your invitees don't also have a spare iPhone, what's the point of inviting them? They'll have the same problem with no workaround?

You don't need to grant the Clubhouse app access to your contacts to use it. ATM, that's only needed to invite people.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#243
post #149

All the shady data schemes and dark patterns in todays idea of software business motivated me to look to my phone as an enemy and using the web cautiously all the time. Actually the idea of hyperconnected future in which 24/7 monitoring of the individuals will be normalised and mandatory makes me cringe. The Internet from force of good is turning to dystopian toolchain by the hour. And all is because we as society ca…

Because some [ˈklʌbhaʊs], a shitty app promoted and used by hype-flex-and-chill type of “people”? Just let them be and move on, what do you think you miss there? If you see them as a source of income, a second job-only phone is a must anyway.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#244
post #240

Earlier quoted context omitted.

They are in california. They can give the finger to the gpdr. It's irrelevant to most people in the world People tend to forget that it is not applicable. For instance nothing I build will ever comply to it regardless of users that might be in europe Clubhouse has no duty to obey european law The question is: why do you think the need to be compliant?

This is not how it works. If you make it available to EU users, you have to comply with GDPR (at least when it comes to those user's data). For the same reason WhatsApp's new T&Cs don't really change anything for EU users. However I don't think the collection of contacts is actually illegal under GDPR, considering WhatsApp does exactly this too. And it's huge in Europe, much bigger than in the US. if they haven't gon…

If they don't do business there they don't have to comply. Making it available doesn't count

Just like I don't have to comply if I have EU users on a service, I am in the united stated. europe cannot enforce their laws here. It's just the same as if saudia arabia tried to enforce their laws here. They carry no wait

That is what makes the GDPR insignificant. It applies to Europe. Not the rest of the world. The cookie warnings for the vast majority of the internet are stupid an unnecessary

So call it illegal in europe but who cares?

It honestly is maddening how many people care about the GDPR that don't need to

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#245

Earlier quoted context omitted.

I did the same and I’m still annoyed at myself. Clubhouse is pretty shit, really. So I sold my soul and got nothing in return.

Thanks for sharing this. I have similar feelings about the product, but am curious to hear your reasons in detail first if you'll share them.

The one thing that got me interested is them using a photo as the app icon. Intriguing. Maybe there's some fun to be had. The rest was of no real interest to me. Silly, but here we are.

Trivialities aside, the content is not for me. It's either some self-help thing or a get rich fast scheme. And I don't care about either.

Worse though is the content delivery. They talk so much and say so little. Horrible.

It really is this:

> Clubhouse is C tier people listening to B tier people talk about A tier people

And here I am, a D tier person not wanting to be part of this circlejerk.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#246
post #240

Earlier quoted context omitted.

This is not how it works. If you make it available to EU users, you have to comply with GDPR (at least when it comes to those user's data). For the same reason WhatsApp's new T&Cs don't really change anything for EU users. However I don't think the collection of contacts is actually illegal under GDPR, considering WhatsApp does exactly this too. And it's huge in Europe, much bigger than in the US. if they haven't gon…

If they don't do business there they don't have to comply. Making it available doesn't count Just like I don't have to comply if I have EU users on a service, I am in the united stated. europe cannot enforce their laws here. It's just the same as if saudia arabia tried to enforce their laws here. They carry no wait That is what makes the GDPR insignificant. It applies to Europe. Not the rest of the world. The cookie…

There's many EU things that take effect with vendors outside the EU. Like software sales: Try to buy a license for a software package from the EU (or with an EU payment card) and you will always be hit with VAT at the rate of your country :( Even if the company is US based only. With the exception of really small ones I guess. In the above case it's annoying for us :) But in the case of GDPR it's good IMO.

Anyway the EU says it applies but I agree they don't really have much in the way of enforcement capability with companies that have no presence here. Though they could ask Apple/Google to remove it from the store I suppose.

And of course most companies do have a presence here. All multinationals do, and even the smaller ones. Even if it's just a sales office.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#247
I seem to remember CyanogenMod having a per-app sandbox feature around 2013 that returned blank info from a virtual root.

Like many point out, this isn't data poisoning, especially if there aren't metric-breaking honeypots around the web seeding these services with enough noise to make these collection practices useless, which there are not.

A more effective alternative might be hashing real contacts to generate seeds of complete but false profile information. Apps thinking they got the mother lode wouldn't be able to assign confidence to any results they didn't have duplicates of, and slowly over time, groups who used this would become worthless.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#248
The problem with this approach is twofold:

a) At the margin, a few people doing this does _nothing_ to mess with big companies' data collection & analysis. But opting out also has the same problem, obviously, so at least it's not doing worse.

b) In the absence of sandbox / selective sharing features like other commenters have mentioned, or you going so far as to _only_ keep fake contacts in your phone, using this approach requires you to also share your actual contacts with the app, thus giving away PII of unconsenting third parties. Yes, I'd rather blame the app developers for collecting this data in the first place, but I'd still prefer not to give my contacts away whenever I can reasonably withhold them.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#250

Earlier quoted context omitted.

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

Are you writing that to emphasize the urgency for the government to pass legislation to reign in unregulated online casinos as they continue refining their dark patterns? (I.e., without legislation, these companies will continue finding more and more sophisticated ways to get the user to act against their own interest.) Or do you mean imply that a practical approach to reign in unregulated online casinos is to spread…

Not the poster you are replying to, but I stopped feeling empathy for people who complaint about lack of privacy, yet willingly give up their data to non-essential services that ask for it with all the proper disclosures.

If you agreed to sharing all your contacts to listen to “musical tweets”, I don’t see why you’ll be complaining. You willingly made a trade off.

Post reply on HN