Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

311–320 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#311
post #303
post #290

Earlier quoted context omitted.

Yeah I've been using yourcompany@mydomain.tld for ages to track who's sold or fumbled my data. Since haveibeenpwned I can even approximately separate the two groups. Surprisingly up to now nearly all incidents (that I know of) have been breaches. Not that it makes it any better.

Same here. Though people usually give me weird looks when I do this IRL and ask me "Is your email address really ourcompany@yourdomain.tld"?

I had these weird looks, and I even got engaged in a nice conversation with an employee at a t-mobile store, but some people don't even bat an eye.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#313

Earlier quoted context omitted.

Thanks for sharing this. I have similar feelings about the product, but am curious to hear your reasons in detail first if you'll share them.

The one thing that got me interested is them using a photo as the app icon. Intriguing. Maybe there's some fun to be had. The rest was of no real interest to me. Silly, but here we are. Trivialities aside, the content is not for me. It's either some self-help thing or a get rich fast scheme. And I don't care about either. Worse though is the content delivery. They talk so much and say so little. Horrible. It really i…

Thanks for that feedback.

I noticed the app icon as well. I wondered who it was, but didn’t look into it.

I’m in agreement about the content.

The “entrepreneurship” culture on Clubhouse seems to be either VC / media worship or this hustle thing.

I joined a "Real Estate Money" group that was pitching $500 investments in shared AirBnB properties. It had calling cards of a scammy “investment” group. A mix of cheerleading and leadership-enriching sales to suckers.

I spent some time last night in some social groups and while entertaining from a sort of shock value perspective they were not well moderated. They would not work with bigger audiences.

Andrew Sorkin interviewed Bill Gates on Clubhouse on Friday. My eyes widened when I saw that, I questioned my initial assessment of the product and it’s velocity. Then I realized I was thinking of Aaron Sorkin. Andrew is some mainstream media journalist. I doubt Gates gave a hoot about the medium.

I think VC, media and “influencers” all slept on TikTok and are now overcompensating with involvement on Clubhouse. It’s better suited to them anyway, and it matches the atmosphere of conferences.

It is the type of activity PG labeled “playing house” and is perhaps well suited as a stand in for puffery, fakery and “influence.”

Regarding content delivery, it is like you read my mind. I’d describe Clubhouse content, even purportedly serious stuff, as awash in loquaciousness word salad.

Clubhouse content forces listeners to be beholden to linear progression. So you lost the most valuable thing about audio content found in podcasts: editing and people who have developed the skills to be engaging.

Clubhouse lacks the crucial “trick play” of podcasts, where you can option out of minutes of content (and ads) at any time.

So anyhow, I regret sharing the address book with them and took my lumps ITT for admitting as much.

However, I don’t regret trying it. Critically evaluating nascent platforms and technology is what I do.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#314

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Bad data makes it less valuable for resale. It's an attack on the market that these things operate under. Can also be used as a canary trap.

> Can also be used as a canary trap.

Can you please explain how this can operate as a canary?

Edit: another post explains that the method is if the bogus data end up an a data leak, but that would require keeping track of bogus submissions and generating new data for each company where you create an account. Then you’d have to cross reference like crazy. Am I missing something simpler?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#316
Ever since ios 5 I think, there has been permission control behind a separate password. Why cant android replicate that? Nowadays, there seems to be one "permissions protection" but sadly all apps say "you seem to have contacts protection enabled. Please disable for best results". Whats the point?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#318

Earlier quoted context omitted.

Are you writing that to emphasize the urgency for the government to pass legislation to reign in unregulated online casinos as they continue refining their dark patterns? (I.e., without legislation, these companies will continue finding more and more sophisticated ways to get the user to act against their own interest.) Or do you mean imply that a practical approach to reign in unregulated online casinos is to spread…

Not the poster you are replying to, but I stopped feeling empathy for people who complaint about lack of privacy, yet willingly give up their data to non-essential services that ask for it with all the proper disclosures. If you agreed to sharing all your contacts to listen to “musical tweets”, I don’t see why you’ll be complaining. You willingly made a trade off.

I wish it were more clear what exact info we were giving to the app (not just generic "contacts" or "photos") and when the app is receiving that info.

I know more about coding than 95% of my friends and I still don't fully understand the depth of info that I transmit to an app when I agree to give it permissions on my iOS device.

E.g., if I give Whatsapp access to my photos on my iPhone, does that mean all of the photos that are stored on my iPhone, including screenshots and hidden photos, are uploaded to Whatsapp servers? Does it upload when I take a new photo or when I open the Whatsapp app?

So if, in this case, Whatsapp is indeed pulling all of a user's photos, including hidden photos, to their servers, I imagine many people would not want that to happen. So 1) I'd want to know ahead of time exactly what will be pulled and 2) ideally, I could have a way to use the app without giving it the keys to everything.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#319

Earlier quoted context omitted.

Clubhouse raised money at a billion dollar valuation. Hacker News specifically and Metafilter aren’t in the same stratosphere

What are you trying to say? That because they have a lot of VC money riding on it, they have to do "growth hacking" in order to justify the funds and grow quickly enough to satisfy the investors? Well, I guess I have to agree.

I assumed the OP saying successful social apps as in successful to the point of being known by at least some average people. Metafilter and Hacker News are both very niche and tiny.

Hacker News doesn’t have the same business model as others either. It’s to help the namesake incubator. It succeeds with that. Getting contacts etc wouldn’t benefit Hacker News. Hacker News could lose a decent amount of money yearly without any prospect of breaking even and still be run.

Most other apps of any kind can’t be run that way, including Reddit and Metafilter.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#320
post #232

Earlier quoted context omitted.

There's an asymmetry of information and power in the relationship between a business and a citizen. Governments, generally, attempt to mitigate this asymmetry. Hence, we have consumer protection laws, GDPR and the likes. While these solutions may be incomplete, or imperfect, having none is definitely worse. > If someone from the EU leaves the EU digitally to buy something in another country, it isn't up to the seller…

I am not sure what you are trying to argue here. I am not making any moral claim about whether a GDPR-type regulation is good or bad. I am simply saying that the EU saying the law applies outside their borders doesn’t make it so. If I am a US citizen living and working in the US, and break the GDPR by storing data illegally from visitors to my website from the EU, the EU can certainly try to fine me or issue a summon…

Yeah, this is the really frustrating thing about conversations about the GDPR: whatever you think about how companies should act, legislation doesn’t really matter unless there’s some way the government can take retributive action against those who ignore it. When someone asks about what this mechanism is, you inevitably get a whole host of people assuming you dislike the legislation.
Post reply on HN