Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

351–360 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#351
post #234
post #227

Earlier quoted context omitted.

> If you want to do business with EU citizens you must abide by EU regulations. No, no more than if I want to do business with Saudis I'm liable for punishment if I drink a beer.

But that's not really a good analogy (not that analogies are proof). A better analogy would be you selling beers in Saudi Arabia. I urge you to read this, it should clarify things: Applicability outside of the European Union: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...

They claim it applies. That doesn't make it so:

http://slawsonandslawson.com/article-32-the-hole-in-the-gdpr...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#352
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

What about dividing your contacts into circles and only give permission to a specific set?

Google+ anyone?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#353

Earlier quoted context omitted.

Bad data makes it less valuable for resale. It's an attack on the market that these things operate under. Can also be used as a canary trap.

> Can also be used as a canary trap. Can you please explain how this can operate as a canary? Edit: another post explains that the method is if the bogus data end up an a data leak, but that would require keeping track of bogus submissions and generating new data for each company where you create an account. Then you’d have to cross reference like crazy. Am I missing something simpler?

This is basically a mechanism that would allow for a honeytrap on steroids. https://blog.finjan.com/honeytokens-used-to-track-cybercrimi...

> that would require keeping track of bogus submissions

You don't have to keep track of the submissions because you can generate them with a reversible algorithm. Basically use a word list method https://github.com/bitcoin/bips/blob/master/bip-0039.mediawi... but have the list be entirely people's names (or generated from a corpus of known accounts and something like https://github.com/minimaxir/textgenrnn to make them harder to spot)

> generating new data for each company where you create an account.

yes https://arxiv.org/abs/2006.15794

Basically treating the data from various email honeypots as a "Numbers station" but instead of using it to prime encryption keys, you use it as a form of steganography. To do this entirely anonymously, the next step would be to publish on a public blockchain or anonymous service so that the owner's device (that generated the emails originally) can uploaded a signed statement that proves they were the phone pwned and who the offending app was.

A similar idea seems baked into a couple of crypto initiatives https://coincentral.com/sentinel-protocol/ but fundamentally we're talking about an anonymous reputation system modeled after how swarms operate to gossip risk.

It would be necessarily stochastic in nature because you'd be depending on the 3rd parties to send emails a bit at a time, but if you get a deluge of phones all reporting the same app, you can assume fairly confidently that app has been compromised. Punishment (Brand reputation, sanctions by app store) for being compromised would encourage better security.

This could (and would need to be) operated at the hardware level and orchestrated by the OS, and OS provider. This is the kind of thing apple and google could do as part of their privacy initiatives around "differential privacy" https://venturebeat.com/2019/12/21/ai-has-a-privacy-problem-...

What, you think that deep learning chip on your phone is there to make cute avatars?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#355
post #63
post #53

Earlier quoted context omitted.

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

This works fine for contacts, but what should happen when I deny the microphone permission? Should I be able to send Shazam a monotone beep or even worse a sample of random sounds that can't even be filtered out?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#356

Earlier quoted context omitted.

It’d be fun once they’ll have EU presence.

I think they had a wave of people join from Germany either earlier this month or last month, so I imagine there are already plenty of Europeans on the app. Plus, doesn't GDPR apply even if there's just one user who resides in the EU?

Having European data subjects is enough ground to ask them to abide by the GDPR. But assume they won't, then you'll have to go to a European court, which could rule whatever, but it can't do much to a company that has no money or persons in the EU to collect from.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#357
post #55

Earlier quoted context omitted.

If you control your own email routing, by using your own mail server, Google Workspace, Microsoft 365, etc, you can choose whatever convention you want. How would you know to strip everything after my first name?

I wouldn't care about the people using their own mail server I would just strip everything after a + sign

Can't strip it if it's not there. Everything after my name is the comment, and you have no way to know.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#358

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Bad data makes it less valuable for resale. It's an attack on the market that these things operate under. Can also be used as a canary trap.

Well since it uses names (last and first) that all start with Z most of these crooked outfits could survive losing 0.5% of the "real" names off their list by filtering the Z. Z. names.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#359

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

The vast majority of phone calls I receive are spam calls by people/robocallers which I did not give my phone number to, but apparently someone else did. I don't want people sharing my phone number with random other people

I thought that the new challenge-response systems between providers (shaken-stir?) was supposed to take 99.9% of this. I guess I'm off to see if they have actually fully implemented it between providers.

Edit: looks like summer is the mandated time. From: wikipedia article on Stir/Shaken As of 2019, SHAKEN/STIR is a major ongoing effort in the United States, which is suffering an "epidemic" of robocalls.[1] Both the Canadian Radio-television and Telecommunications Commission and the Federal Communications Commission are requiring use of the protocols by June 30, 2021.[2][3]

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#360
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

It's not really understandable. It should be an opt in with and OR "I would like these 10 people who are important to me to be on the list you look at, not these other 400 people who I've taken the phone number of at some point"
Post reply on HN