Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

321–330 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#321
post #206

Earlier quoted context omitted.

Clubhouse raised money at a billion dollar valuation. Hacker News specifically and Metafilter aren’t in the same stratosphere

But still, why do they need to steal your addressbook? They can offer you to spam your contacts without demanding. Is the profit contingent on selling the address book data? To the point where they won't let you invite more people (help them grow!) without it?

The pushback is minimal. A lot of the pushback possibly includes people that are going to be upset by many things. Specific Reddit communities and Hacker News are good examples of that. If these demographics are unlikely to be happy with your social product’s privacy and dark or non dark patterns, catering to them makes no sense.

I don’t know any one outside some geeky sites and only one person personally who cares about any of this. Some do say lame casually. But it’s not going to be a deciding factor for using the app.

To add on to the whims of the geeky communities. Some companies escape it more than others. Airbnb doesn’t get much shit for spamming Craigslist people in early days. Compared to the negative talk of Uber, Facebook, etc, they also get no where near any criticism for the way they incentivize negative aspects of their platform.

All of this to say - there’s no real downside if money and power is the primary goal.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#322

Earlier quoted context omitted.

That means that more than likely clubhouse have our details even if we have no desire to be part of it.

It’d be fun once they’ll have EU presence.

I think they had a wave of people join from Germany either earlier this month or last month, so I imagine there are already plenty of Europeans on the app. Plus, doesn't GDPR apply even if there's just one user who resides in the EU?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#323

Earlier quoted context omitted.

>> some apps check for what apps are installed on the device I can't believe that's allowed by the OS - seems like a horrible policy.

Probably should be removed but I have seen it used legitimately sometimes. Some apps for things like contact syncing will tell you there are other apps for caldav and stuff and check if you already have them installed to not show the message.

Nextcloud and DAVx5 by chance?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#325
post #65

Earlier quoted context omitted.

Or even as a a service fake data - feed fake location data and fake contact list. Full of 202-555-1234 type numbers. I always put fake data into web forms and it is a sign that I don’t truly own the phone that I can’t do the same for local software.

Like I want a pop up: this application is requesting your location data. Shall we give the real data, no data, or simulated data. Same for contacts, photos, apps installed, etc.? Not saying that would solve all the problems but it would be user centric in a way the privacy conversation just isn’t.

Giving fake location data could create real problems. Suppose you do this then forget. If it’s a safety or navigation app, you tell the phone to give it fake data, then you forget and maybe use the app much later. Now you’re using a service that thinks you’re in a different location.

One of the examples given here was an app that gives you safety alerts. A navigation app might give you useless directions. There are a thousand ways this could go horribly wrong.

I suppose iOS could present some warning, but that might interfere with the UI, or be misunderstood.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#326
post #53

Earlier quoted context omitted.

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

They have added that, but it's written by the app developers so you still can't trust what they claim they're gathering from you.

I think Apples app reviewers have tools to analyse what APIs and permissions an app tries to access to check this.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#327

Earlier quoted context omitted.

I mean this is why they do it. You knew it was wrong, you knew they were going to take that data and mine it, and you still said sure.

They do it because all the successful social apps need to make contact discovery easy. The ones that don't use this trick - ethical - we don't hear so much about, maybe they don't succeed.

They do it because all the successful social apps need to make contact discovery easy.

Signal does it with hashes which it doesn’t store anyway

https://support.signal.org/hc/en-us/articles/360007061452-Do...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#328

I seem to remember CyanogenMod having a per-app sandbox feature around 2013 that returned blank info from a virtual root. Like many point out, this isn't data poisoning, especially if there aren't metric-breaking honeypots around the web seeding these services with enough noise to make these collection practices useless, which there are not. A more effective alternative might be hashing real contacts to generate seed…

I remember that too; it was great. That feature disappeared at some point though - it's not in Lineage OS these days as far as I've found. I recall it made some apps crash, but only as far as I could tell those that weren't robust enough to handle being fed junk data. I'm not sure why that feature disappeared. EDIT: my guess is that a later Android update broke the existing Cyanogenmod code and no one was maintaining…

There's XPrivacy framework that runs on top of Magisk or XPosed (not sure how it works now). I remember it allowed you to give very fine-grained permissions to apps and poison the data as well, with fake contacts, location, etc.

Back in the day it required a lot of tinkering to set it up, and would likely make your OS pretty unstable.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#329

Earlier quoted context omitted.

The one thing that got me interested is them using a photo as the app icon. Intriguing. Maybe there's some fun to be had. The rest was of no real interest to me. Silly, but here we are. Trivialities aside, the content is not for me. It's either some self-help thing or a get rich fast scheme. And I don't care about either. Worse though is the content delivery. They talk so much and say so little. Horrible. It really i…

Thanks for that feedback. I noticed the app icon as well. I wondered who it was, but didn’t look into it. I’m in agreement about the content. The “entrepreneurship” culture on Clubhouse seems to be either VC / media worship or this hustle thing. I joined a "Real Estate Money" group that was pitching $500 investments in shared AirBnB properties. It had calling cards of a scammy “investment” group. A mix of cheerleadin…

> Andrew Sorkin interviewed Bill Gates on Clubhouse on Friday. My eyes widened when I saw that, I questioned my initial assessment of the product and it’s velocity. Then I realized I was thinking of Aaron Sorkin. Andrew is some mainstream media journalist. I doubt Gates gave a hoot about the medium.

Funny, when I read that, my eyes equally widened, until your next sentence corrected the interviewer’s name in my head.

I believe Andrew runs DealBook on the NY Times, but I’m curious how the interview was conducted?

Bill Gates is on record some years ago, saying that “no iPhone for me” when asked if he used an iPhone. This was around the time Windows Phone lost the mobile market to iOS and Android, and since ClubHouse is iOS-only, I’m wondering how Gates was able to take part, unless he’s changed his mind since he was asked that question.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#330
post #284

Earlier quoted context omitted.

> and which of them are required to function. On the iOS App Store, none of the optional permissions can be required for an app to perform it's basic functions - that's a store policy, and it's generally well enforced. Obviously if your app's function is mapping, GPS can be required to use those features (but only at the user's discretion - ie while running or all the time, granular or coarse), but the app can't just…

Tell that to Citizen which refuses to operate without location enabled, and even worse, refuses to operate with coarse location. And being a free app there's no place on Apple's site to report this bad behavior.

Yes, they are extremely aggressive. Also, their payment screen about "start for free" leads to a $199 payment after a short two-week trial.
Post reply on HN