Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

271–280 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#271
post #246

Earlier quoted context omitted.

There's many EU things that take effect with vendors outside the EU. Like software sales: Try to buy a license for a software package from the EU (or with an EU payment card) and you will always be hit with VAT at the rate of your country :( Even if the company is US based only. With the exception of really small ones I guess. In the above case it's annoying for us :) But in the case of GDPR it's good IMO. Anyway the…

Most American companies don't though. They can safely ignore european laws

And also choose not operate in the nations whose laws they are flouting in most cases; EDIT: a few weeks ago EU posters here were describing how ERCOT was preventing access to the company's public facing website, citing not wanting to comply with GDPR

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#272
post #142

Earlier quoted context omitted.

Even if you make your contact list 99% bounces and 1% real (and every user of the app does the same), I don't see how this becomes a problem for the app's operator. Remove a contact after 1-2 bounces and you're golden.

Fair. Still golden if this needs to be done for all contacts of all users?

If they bounce they are extremely fast to cull.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#273
post #232

Earlier quoted context omitted.

And any EU citizen is free to not do business with a company outside the EU. Do you think the EU laws should apply to people selling things to EU citizens while they are on vacation in other parts of the world? If someone from Germany travels to Brazil and buys something from a store, are they required to abide by EU rules? If someone from the EU leaves the EU digitally to buy something in another country, it isn't u…

There's an asymmetry of information and power in the relationship between a business and a citizen. Governments, generally, attempt to mitigate this asymmetry. Hence, we have consumer protection laws, GDPR and the likes. While these solutions may be incomplete, or imperfect, having none is definitely worse. > If someone from the EU leaves the EU digitally to buy something in another country, it isn't up to the seller…

This article basically confirms my suspicion that this provision is basically unenforceable:

http://slawsonandslawson.com/article-32-the-hole-in-the-gdpr...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#274
post #63
post #53

Earlier quoted context omitted.

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

> If I say no contacts the call should succeed but with a zero Len response.

Actually I would take it further and say that I should be able to define its response or have it render a random but plausible template response. Otherwise a zero len response is too obvious that you didn't give it permissions.

I once had an app yell at me for not giving my GPS permission, but then yell at me again when I enabled a mock GPS on Android. It really shouldn't have been able to know I was mocking location.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#275
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Should you not tell your contacts that you gave their details to Clubhouse?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#276

I seem to remember CyanogenMod having a per-app sandbox feature around 2013 that returned blank info from a virtual root. Like many point out, this isn't data poisoning, especially if there aren't metric-breaking honeypots around the web seeding these services with enough noise to make these collection practices useless, which there are not. A more effective alternative might be hashing real contacts to generate seed…

I remember that too; it was great. That feature disappeared at some point though - it's not in Lineage OS these days as far as I've found. I recall it made some apps crash, but only as far as I could tell those that weren't robust enough to handle being fed junk data. I'm not sure why that feature disappeared.

EDIT: my guess is that a later Android update broke the existing Cyanogenmod code and no one was maintaining it.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#277

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

I wish telegram had a setting for "Block everyone in my contacts list" Unfortunately it only seems to have the reverse

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#278

Remember: some apps check for what apps are installed on the device, and if they see this installed they can deduce you're poisoning the well. Also if you want to research obfuscation and how it thwarts surveillance, check these: https://www.schneier.com/blog/archives/2019/11/obfuscation_a... https://www.science20.com/news_articles/obfuscation_how_to_h... https://www.theguardian.com/technology/2015/oct/24/obfuscati..…

>> some apps check for what apps are installed on the device I can't believe that's allowed by the OS - seems like a horrible policy.

Probably should be removed but I have seen it used legitimately sometimes. Some apps for things like contact syncing will tell you there are other apps for caldav and stuff and check if you already have them installed to not show the message.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#279
post #113

This is a common technique in the mailing list industry. It's called "salting". You add fake names, but real email addresses, street addresses, or post office boxes. You then monitor what shows up in these places addressed to "Mr. Fake Name". It's how mailing list companies monitor who is using their lists and helps control misuse.

A general term for this is a "copyright trap" [1]. Map makers for example often add small, fake features to be able to tell if another map was copied from theirs.

[1] https://en.wikipedia.org/wiki/Fictitious_entry

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#280
post #142

Earlier quoted context omitted.

Not an expert on guerilla cyber-warfare, but isn't it the whole point of this sort of poisoning? If enough people do this the cost of those bouncing emails would become prohibitive. That's my speculation. Would be great to know more from someone who knows the domain better.

Even if you make your contact list 99% bounces and 1% real (and every user of the app does the same), I don't see how this becomes a problem for the app's operator. Remove a contact after 1-2 bounces and you're golden.

[deleted]
Post reply on HN