Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

211–220 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#211

Earlier quoted context omitted.

> ...and have a better experience in every category than iOS, hardware and software. Really? I tried GrapheneOS on a Pixel 4A, and without exaggerating or trying to come off sensationalist the experience was really tepid compared to iOS, and even "normal" Android. Stuttering and jerky UI (which often also wanted to take a brief nap), very poor GPU hardware acceleration support, notably worse battery life, loads of th…

I run GrapheneOS on a 4A with TMobile and the frequent reports of people trying to call me telling me my line is out of service and days where calls won't initiate from my phone at all makes me want to run back to my iPhone. The tethering seems to be pretty flakey as well with me often having to reboot the phone.

I've been using GrapheneOS on a 4A with TMobile as my daily driver for over a year and have had none of these issues. Never had an out-of-service notice from someone calling me, never had a call not initiate, and tethering works great.

Maybe it's something to do with OpenGapps? I never installed it or microG, I'm perfectly happy with just Fdroid.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#212

Feeling quite smug about switching to CalyxOS earlier this week.

Can I expect CalyxOS to support the Pixel 6 rather soon? Is e.g. camera performance dependent on closed source Google code/firmware? What are the limitations there? I was going for GrapheneOS, but tbh seeing that one main developer's personality issues turned me off big time. I don't care about technical advantages, if I have to trust in that guy's impulse control. Too small a project for that.

GrapheneOS’s main dev can come across as paranoid, but it is sort of understandable given the history of the project. Nonetheless, they are doing a spectacular job and I think using GCam with properly set permissions is the best of both words.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#213

Earlier quoted context omitted.

I guess. You have to hit the screenshot combo and then tap the screenshot, versus hitting the app-switcher button. Are you doing this often enough for that 1 extra step to be a big deal?

I’m increasingly finding great value in reducing complexity of simple tasks. I thought the push button rear door closer on my minivan was silly, but it came with it, so (shrug). I’ve grown to like it! Reducing from a few steps plus a major context switch to just one step is valuable.

Where’s the context switch?

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#214

Earlier quoted context omitted.

> immediately it told me that Facebook attempted internet access. I am not sure how that information is useful to you or anyone else, not trying to be snarky, but an internet app wanting internet access...is the expected behavior? Most apps and operating systems communicate over the internet for any number of reasons, heck, apps can even check if you have internet access or not (and respond accordingly, such as cachi…

I have the FB app but rarely use it. Why would it be phoning home when I don't have it open?

To check for notifications? I’m fairly sure they haven’t implemented a complex AI model to determine that “you are using it rarely”, so the check it out each n minutes is a constant thing.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#215

Earlier quoted context omitted.

Some Android flavors, including /e/[1] and GrapheneOS,[2] don't use Google servers for the internet connectivity check by default. [1] https://gitlab.e.foundation/e/backlog/-/issues/268#note_1809... [2] https://grapheneos.org/faq#default-connections

Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…

Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled.

The time service is enabled by default but can be disabled.

"An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field."

"Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."

Connectivity checks are enabled by default but can be disabled.

"Connectivity checks designed to mimic a web browser user agent are performed by using HTTP and HTTPS to fetch standard URLs generating an HTTP 204 status code."

"You can change the connectivity check URLs via the Settings Network & internet Advanced Internet connectivity check setting. At the moment, it can be toggled between the GrapheneOS servers (default), the standard Google servers used by billions of other Android devices or disabled."

Why these are enabled by default, i.e., opt-out instead of opt-in, is strange considering this OS is aimed at technical, security and privacy-conscious users. Users who would surely know what services they want and be capable of enabling them.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#216

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

I've tried Osmand and found it way too slow/janky for everyday use (since it has to render the tiles locally and doesn't seem to pre-render for scrolling). Newpipe loads videos much slower than the official app and occasionally fails completely (likely because YouTube changed something). F-droid (regular, non-root install) shows me notifications to update apps, then when I tap them, I get a "there was a problem parsi…

If you don't like Newpipe you can use Youtube Vanced which is basically a pwned version of the native Youtube app. I've had some stutters with Newpipe but overall I like it.

Osmand really isn't bad, sure it's a little bit slower to render but we're talking maybe 500-1000ms on a Pixel 3a.

Regarding F-Droid you're right it is quite buggy, but thankfully once you've got the apps you want you don't really need to use it except to update.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#217

Earlier quoted context omitted.

Signal is specifically designed to work without Google Play Services, so expect a 1:1 experience when using it with these privacy conscious distros. I'm confident Whatsapp will work, but I have not tried. Push notifications will not work without Google Play Services.

According to Plexus, WhatsApp works perfectly on Android without Google Play Services, whether or not you have microG installed.[1] I think they implement their own push notification system if you download directly from them,[2] though I haven't confirmed this. Discord works perfectly with microG, and has a 3/4 rating without it since notifications will only work if you have microG. [1] https://plexus.techlore.tech/a…

IME, the notifications do work. I downloaded .apk directly from WhatsApp.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#218
post #2

Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. I try not to store or access any personal information on my cell phones when i can avoid it, but at a certain point, just having one is enough to seriously compromise your privacy. Strong regulation with real sharp teeth is the only thing that can fix this situation.

Hi! I have a Samsung and I looked around online and couldn't find any real info on this topic. I don't doubt it's quite possible, but where is your source from? It's been hard for me to confirm. A good point, though, I'll look at the open source options....

Samsung's own privacy policy and those of the 3rd parties they use. It's been over a year and checking now some things have already changed, but if you click on the gear icon from within the keyboard you can select "about sumsung keyboard" which should give you a list of policies including gify and tenor (both used for gifs I guess) but i didn't even check those. The one you want is the legal info which tells you that in addition to samsung's privacy policy (which outright says it's collecting and selling everything it can get their hands on (see https://www.computerworld.com/article/3514999/samsung-sellin...) you also have to accept the policy of a 3rd party called Nuance which they use for "language data".

The wall of legal text there eventually links to their privacy privacy which opens in the browser. They collect and store things like "your choice of words, speech and writing patters, how you use your keyboard, custom words you add, the number of charters you type, your typing speed, etc. and they share (read sell) that data to affiliates, subsidiaries, vendors, subcontractors, etc (pretty much anyone they feel like). They specifically state they use this data to draw inferences reflecting your characteristics, behavior, abilities, preferences and aptitudes all of which they can sell to anyone at any time without even telling you about it because what they learn about you by going over all your data is their data and they don't have to tell you anything at all about what they do with their data.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#219

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

I just reinstalled my FP2 with LineageOS and microG after reading your post.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#220
post #2

Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. I try not to store or access any personal information on my cell phones when i can avoid it, but at a certain point, just having one is enough to seriously compromise your privacy. Strong regulation with real sharp teeth is the only thing that can fix this situation.

> Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. How did you check? Do you have a source/link?

as stated elsewhere:

Samsung's own privacy policy and those of the 3rd parties they use. It's been over a year and checking now some things have already changed, but if you click on the gear icon from within the keyboard you can select "about sumsung keyboard" which should give you a list of policies including gify and tenor (both used for gifs I guess) but i didn't even check those. The one you want is the legal info which tells you that in addition to samsung's privacy policy (which outright says it's collecting and selling everything it can get their hands on (see https://www.computerworld.com/article/3514999/samsung-sellin...) you also have to accept the policy of a 3rd party called Nuance which they use for "language data".

The wall of legal text there eventually links to their privacy privacy which opens in the browser. They collect and store things like "your choice of words, speech and writing patters, how you use your keyboard, custom words you add, the number of charters you type, your typing speed, etc. and they share (read sell) that data to affiliates, subsidiaries, vendors, subcontractors, etc (pretty much anyone they feel like). They specifically state they use this data to draw inferences reflecting your characteristics, behavior, abilities, preferences and aptitudes all of which they can sell to anyone at any time without even telling you about it because what they learn about you by going over all your data is their data and they don't have to tell you anything at all about what they do with their data.

Post reply on HN