Live data from Hacker News

Android wallpaper images can threaten privacy

fingerprintjs.com

51–60 of 81 posts

Re: Android wallpaper images can threaten privacy

#51
post #35
post #12

Interesting article but its rich as fuck coming from a company whose sole product is weaponizing the ever increasing scope of browsers against users

Yeah I don't know how to interpret this article. Is it a warning to users about a new threat to privacy, or is it an announcement to customers about improved tracking capabilities in Android 12/a potential product update? Even if it's just some inbound marketing blog spam bullshit, why would a company whose business it is to violate and exploit privacy want to post an article that will attract people who are concerne…

Hey there, I work at FingerprintJS.

We don't believe in third party tracking and only focus on first party anti-fraud use cases. We publicly reveal any methods that we detect as being pure third party tracking privacy violations so that they get patched.

Re: Android wallpaper images can threaten privacy

#52
post #7

Although this is an interesting, novel method, there are so many fingerprinting capable APIs in native code that I don't think this matters much. Many apps I use daily require internal storage permissions and a bunch of them drop random dotfiles with magical IDs in there. Xiaomi even dumps a world readable unique device ID on the emulated SD card. Not all apps require external storage permissions, but even then there…

Chasing this dragon is exhausting, and seems to be requiring more user-hostile measures that prevent end users from using their device fully. Can there be a legal frame work where Google and Apple just take your source code and builds it on their farm, and app review is a source-code level review? And Developers that refuse to do these things are just blocked from developing on these platforms?

I don't believe there is any company willing to leak their closed source production source code to anyone. And even they do, it is highly likely there are some dependency they use did not come with source at first place. That wouldn't work in any means.

Re: Android wallpaper images can threaten privacy

#53

Earlier quoted context omitted.

> Most of their apps ("gapps") are pre-installed with backdoor privileges that can bypass sandbox restrictions in-place for every other (non-OEM) app Hadn't heard about this. Like what?

See: https://grapheneos.org/usage#sandboxed-play-services

Ah, I see, thanks. I thought you meant like gmail, not play services.

Re: Android wallpaper images can threaten privacy

#54
I'm beginning to feel as if after I'd put my Android phone though a metal shredder that the individual remaining atoms will somehow still have my ID on them à la QM's conservation of information.

It's been clear to me for quite some while that the whole notion of trying to achieve privacy on the internet is broken - the paradigm we're now using (and have always been using) to achieve privacy is wrong. As no matter what steps we take - such as making browsers more private and less fingerprint prone to, say, sandboxing apps etc., etc. - someone sooner or later will always find ways around our best defenses. As it stands, it's an ongoing incremental battle over privacy that we citizens can never have any long-term certainty about.

Somehow our ID and personal data have to be separated from the hardware, software, means of transmission and IP addresses, etc. in ways that any chance of ever linking them are not just difficult but are also logically impossible. It's only then that we'd be in a situation where no matter the amount of hacking the 'system' would ever reveal or encroach upon users' privacy.

This wallpaper example may still be somewhat of a stretch to implement in practice but chances are it won't be so in the future; its existence only goes to illustrate my point.

If anyone ever manages to solve the problem in an easy implementable way then he/she will either be deemed a hero genius or a pariah. Which of these views one has will depend on which side of the political fence one's sitting.

Re: Android wallpaper images can threaten privacy

#56
post #45

Earlier quoted context omitted.

I would assume the opposite. Why a company which makes money from tracking users for many reasons develops an OS which prevents tracking? My guess is that it'd be an OS which would perform tasks Google needs to stay as Google better than Android, and Google may sell these capabilities to devs to further enhance their bottom line.

Google cannot change the Linux kernel like they control Chromium or the most of the Android, so with Fuchia (or its kernel) they are more in control once again.

Again What has google done to make Chrome more privacy friendly when they have every control? I guess the answer is 0. So even with Fuchia I think it will be worse than Linux.

Re: Android wallpaper images can threaten privacy

#57
post #28

Earlier quoted context omitted.

It's been more than a year since I last changed my wallpaper.

I've used the same wallpaper on every computing device I've owned, for the last 26 years.

With the downside of fingerprinting yourself it seems, would you be willing to share the wallpaper?

Re: Android wallpaper images can threaten privacy

#58
post #10

Earlier quoted context omitted.

>Many apps I use daily require internal storage permissions and a bunch of them drop random dotfiles with magical IDs in there. Xiaomi even dumps a world readable unique device ID on the emulated SD card. They're fixing this with soon with scoped storage api.

A decade later and they're implementing folder permissions...?

Better late than never! But.. yikes!

Re: Android wallpaper images can threaten privacy

#59
post #35

Earlier quoted context omitted.

Yeah I don't know how to interpret this article. Is it a warning to users about a new threat to privacy, or is it an announcement to customers about improved tracking capabilities in Android 12/a potential product update? Even if it's just some inbound marketing blog spam bullshit, why would a company whose business it is to violate and exploit privacy want to post an article that will attract people who are concerne…

Hey there, I work at FingerprintJS. We don't believe in third party tracking and only focus on first party anti-fraud use cases. We publicly reveal any methods that we detect as being pure third party tracking privacy violations so that they get patched.

I suspect first party anti-fraud tracking methods and third party tracking methods have a lot of overlap. What are meaningful differences?

Re: Android wallpaper images can threaten privacy

#60
post #28

Earlier quoted context omitted.

I've used the same wallpaper on every computing device I've owned, for the last 26 years.

With the downside of fingerprinting yourself it seems, would you be willing to share the wallpaper?

It isn't special, merely a blue/green colour with mild dithering.

It is a little like looking at the morning sky.

It's on all phones, desktops, etc. And if I were to give it to you? Well. Maybe you're the NSA, maybe I'll be pulled off the street, thrown into a chair, and in a NDA-drugged, mildly confused state, be told "look, it is your desktop, see your familiar backgroud? You should enter your password."

No sir, I will not disclose my background image!! Sneaky! Good try though.

Post reply on HN