Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

121–130 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#122
post #107

Earlier quoted context omitted.

amazon paysend many others do too. bank is Boursorama

Is this something more popular outside of the US where credit/debit cards are not as ubiquitous?

It usually happens when someone pays with a credit or debit card. If the confirmation is not given in the app within a certain time limit, the bank rejects the card transaction.

Edit: to clarify, my comment is about the UK, and it does not happen with most card transactions; "usually" here refers instead to card transactions being the usual trigger (in my experience) for this app-based authentication flow.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#123

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

Technically, the Internet Connectivity Check on LineageOS also sends your position/IP to Google, and also avoids a VPN tunnel because it's lower down the stack.

I can recommend LineageOS, however be aware that lots of malware infected builds have made it to xda dev in the past, so you should build it yourself if possible (or use the official downloads).

Regarding the Connectivity Check: You can add all google related domains to /system/etc/hosts if you have root/sudo access.

Additionally I'd recommend everyone to use RethinkDNS as a DNS adblocker and app firewall - and AppWarden to patch out the Analytics parts of proprietary Apps.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#124

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

[deleted]

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#125

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

> ...and have a better experience in every category than iOS, hardware and software.

Really? I tried GrapheneOS on a Pixel 4A, and without exaggerating or trying to come off sensationalist the experience was really tepid compared to iOS, and even "normal" Android. Stuttering and jerky UI (which often also wanted to take a brief nap), very poor GPU hardware acceleration support, notably worse battery life, loads of things that just didn't work well (or at all) without Gapps, and trying to get Play Services shoe-horned into GrapheneOS was still quite the bug-ridden hassle. Additionally, the Open Camera app produced rubbish results compared to Google's native Android camera app, which matters a lot to me.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#126

It seems worth talking about the fact that it appears to be the vendor of the phone putting this kind of snooping in place. Blaming Android is missing the real culprit. Like they say in the article, we need stronger controls on people's data for whoever happens to make the phone's OS.

For practical purposes Android is not just the open source codebase but also the economic institution, where various middlemen get to do sketchy and low-rent stuff in between the trusted brand and the consumer. That is the “openness” that sets it apart from its competitor.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#127

Earlier quoted context omitted.

Is this something more popular outside of the US where credit/debit cards are not as ubiquitous?

It usually happens when someone pays with a credit or debit card. If the confirmation is not given in the app within a certain time limit, the bank rejects the card transaction. Edit: to clarify, my comment is about the UK, and it does not happen with most card transactions; "usually" here refers instead to card transactions being the usual trigger (in my experience) for this app-based authentication flow.

"Usually" is a bit of sticky word here. Your usual is not my usual, hence my questioning of it. My experience is US centric, so I'm assuming non-US but non-US is a really big place.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#128

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

I'm using LineageOS with neither OpenGapps nor MicroG, and can confirm that Aurora works without. There are numerous apps available from Aurora that will not function, of course, and many other inconveniences of varying severity, but it's overall a good experience.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#129

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

I use the exact same setup, works like a charm. I can definitely recommend it for anyone concerned with the privacy issues of current mobile OSes. Furthermore, it never feels limited after getting used to this suit of apps, which may take up to a week at most.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#130
post #39

Earlier quoted context omitted.

Based on your comment I have installed it and enabled notifications.. immediately it told me that Facebook attempted internet access. I have 432 other apps so it will be interesting to see what else is phoning home.

> immediately it told me that Facebook attempted internet access. I am not sure how that information is useful to you or anyone else, not trying to be snarky, but an internet app wanting internet access...is the expected behavior? Most apps and operating systems communicate over the internet for any number of reasons, heck, apps can even check if you have internet access or not (and respond accordingly, such as cachi…

Doesn't sound like he was in the Facebook app at the time, though.
Post reply on HN