Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

261–270 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#261
post #231

Earlier quoted context omitted.

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

And this tells me that there is a need for another step up for this app - to not only poison the contacts, but to temporarily 1) backup => 2) delete => 2a) share poisoned list => 3) restore contacts. So we can share the list, but they'll never get our real contacts, only trash data. Enough use it, maybe they'll stop

But wouldn't this company have to periodically review your contacts, to slurp up new ones?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#262
post #246

Earlier quoted context omitted.

If they don't do business there they don't have to comply. Making it available doesn't count Just like I don't have to comply if I have EU users on a service, I am in the united stated. europe cannot enforce their laws here. It's just the same as if saudia arabia tried to enforce their laws here. They carry no wait That is what makes the GDPR insignificant. It applies to Europe. Not the rest of the world. The cookie…

There's many EU things that take effect with vendors outside the EU. Like software sales: Try to buy a license for a software package from the EU (or with an EU payment card) and you will always be hit with VAT at the rate of your country :( Even if the company is US based only. With the exception of really small ones I guess. In the above case it's annoying for us :) But in the case of GDPR it's good IMO. Anyway the…

Most American companies don't though. They can safely ignore european laws

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#263

Earlier quoted context omitted.

A contact list often operates as a database of what number belongs to who, for guarding incoming calls. It can be a security tool.

You can generally block calls by number, without having them as a named contact.

I do see Waterluvian's point though. You might still have business with them yet you don't really want to deal with them otherwise. Knowing who this SMS or call was from can be helpful rather than blocking the number outright.

Then again, seeing their name when installing Signal and figuring "oh hey they have signal too" seems no less weird to me than seeing their name in my phone book and thinking "oh hey they have a phone too". If that really sets you off... that seems unlikely. So I don't really get this subthread, even if I see the general point that you might not want to be reminded of certain people on a regular basis (for me, installing a phone number-based social application is not a monthly occurrence).

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#264

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Does Signal share contacts the same way others like WhatsApp does? https://signal.org/blog/private-contact-discovery/ > Signal clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service.

Note that this SGX thing is broken seven ways from sunday, but in principle, yep they have some security measures here. We just have to trust them not to crack their SGX environment as well as (regardless of SGX' security) Intel not to generate an identical MRENCLAVE for anyone else but with additional logging code running inside.

This is the best system I know of anyone running, by the way. Threema, Wire, etc., nobody else has this (but then neither requires a phone number, so...). I also don't know of a better way to do phone number matching than having a trusted third party that bakes their private key into chips and verifies that you're really talking to the code you think you're talking to. The upsides of DRM technology!

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#265
post #232

Earlier quoted context omitted.

And any EU citizen is free to not do business with a company outside the EU. Do you think the EU laws should apply to people selling things to EU citizens while they are on vacation in other parts of the world? If someone from Germany travels to Brazil and buys something from a store, are they required to abide by EU rules? If someone from the EU leaves the EU digitally to buy something in another country, it isn't u…

There's an asymmetry of information and power in the relationship between a business and a citizen. Governments, generally, attempt to mitigate this asymmetry. Hence, we have consumer protection laws, GDPR and the likes. While these solutions may be incomplete, or imperfect, having none is definitely worse. > If someone from the EU leaves the EU digitally to buy something in another country, it isn't up to the seller…

I am not sure what you are trying to argue here. I am not making any moral claim about whether a GDPR-type regulation is good or bad. I am simply saying that the EU saying the law applies outside their borders doesn’t make it so.

If I am a US citizen living and working in the US, and break the GDPR by storing data illegally from visitors to my website from the EU, the EU can certainly try to fine me or issue a summons or whatever they want to do.

However, there exists no extradition treaty for this law, and there would be no way for the EU to enforce judgement.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#266
post #175

Earlier quoted context omitted.

This seems like the shady type of thing lawmakers should pass laws against

I see this as a key problem of our times. Social convention used to have a stronger impact on behavior. Now it isn't enough for behavior to be disdained, it must be flagrantly illegal.

Growth by any means necessary.. seems like there are a tens of thousands of apps that each act like their own data bureau, totalling dossiers on billions of people, just because it makes money. Maybe a few percentage points' value lost as a slap on the wrist every now and then. I feel, that in this scenario, rather than a better carrot, we need a better stick..

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#267
post #100

Earlier quoted context omitted.

Clubhouse can bite me. I refuse to use tooling from shitbags who try to exort me into compromising others' privacy for shiny toys. I know other shops do it, as if that makes it OK.

I remember signing up for Facebook back in the day. They tried to get me to share something about my email contacts list. That just made me not use Facebook instead. Unfortunately, everyone else didn't seem to have a problem with it.

Facebook literally had a box on their web site asking for your email address and email account password, so they could log in to your webmail and scrape your contacts.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#268

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

About that Signal thing: Did that other person actually get a conversation starter message of some sort?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#269
post #261
post #231

Earlier quoted context omitted.

And this tells me that there is a need for another step up for this app - to not only poison the contacts, but to temporarily 1) backup => 2) delete => 2a) share poisoned list => 3) restore contacts. So we can share the list, but they'll never get our real contacts, only trash data. Enough use it, maybe they'll stop

But wouldn't this company have to periodically review your contacts, to slurp up new ones?

Yup, probably their next move would be to require constant access to contacts list and check whenever the app runs.

The next move on this side would be to keep contacts in a separate app from the std Android/Apple app, and then have to make calls, texts, etc. from there.

If only there weren't so many sociopaths running these companies... sorry, wrong planet

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#270

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

The problem I have with Whatsapp is even more than Signal: Not only they engage me to start a conversation with that customer to whom I only wanted to appear super-stern and rigorous, but they also send them my profile photo and my name!

My business name is not my private name! At least let me remain under my name in their address book, don’t give them information.

Post reply on HN