Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

231–240 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#231

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

Technically, the Internet Connectivity Check on LineageOS also sends your position/IP to Google, and also avoids a VPN tunnel because it's lower down the stack. I can recommend LineageOS, however be aware that lots of malware infected builds have made it to xda dev in the past, so you should build it yourself if possible (or use the official downloads). Regarding the Connectivity Check: You can add all google related…

From GrapheneOS FAQ:

"Unlike AOSP or the stock OS on the supported devices, GrapheneOS stops making network time connections when using network time is disabled rather than just not setting the clock based on it."

"... rather than just not setting the clock based on it."

Wow, that is really sneaky and deceptive. The user thinks she has disabled the constant connections to the tech company time servers but in truth the connections persist.

The time checks are equally as annoying as the connectivity checks.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#232

Earlier quoted context omitted.

No budget restrictions although I’d like the ability for Bluetooth to run in the background and not go to sleep , and ideally ip67 or ip68 water protection.

All of the LineageOS phones I've ever used have been able to maintain a Bluetooth connection in the background. If you're fine with a used phone, the OnePlus 8 has a high-end Snapdragon 865 processor and 8 GB RAM.[1] The carrier models have IP68, and unlocked models are manufactured similarly but don't have an official IP rating.[2] If you're getting the T-Mobile carrier model (which may be carrier unlocked at sale),…

Appreciate it very much.

To check, do you know whether the bootloader can be unlocked without a SIM card with these phones?

I am thinking that the oneplus 8 has plenty of horsepower.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#233
post #229

Earlier quoted context omitted.

Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…

My pinephone has multiboot to several different Linux and Android varieties.

As well as NetBSD, and probably others, eventually.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#234

Earlier quoted context omitted.

All of the LineageOS phones I've ever used have been able to maintain a Bluetooth connection in the background. If you're fine with a used phone, the OnePlus 8 has a high-end Snapdragon 865 processor and 8 GB RAM.[1] The carrier models have IP68, and unlocked models are manufactured similarly but don't have an official IP rating.[2] If you're getting the T-Mobile carrier model (which may be carrier unlocked at sale),…

Appreciate it very much. To check, do you know whether the bootloader can be unlocked without a SIM card with these phones? I am thinking that the oneplus 8 has plenty of horsepower.

Unlocking a phone is a pain* (at least in the US), so I recommend buying one that is already unlocked. For example, a listing that says both "T-Mobile" and "unlocked" is for a phone that was originally locked by T-Mobile when it was sold as a new phone, but was then unlocked by T-Mobile before it was listed for sale as a used phone. For this type of phone (carrier unlocked), you'll just need to request a bootloader unlock code from OnePlus, which takes a week.

(Not all manufacturers require a bootloader unlock code, but having this option is still better than not being able to unlock the bootloader at all.)

And yes, the OnePlus 8 is faster than any Pixel phone released so far. It's only a year old after all.

* https://www.digitaltrends.com/mobile/how-to-unlock-a-phone-o...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#235

Earlier quoted context omitted.

Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…

Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled. The time service is enabled by default but can be disabled. "An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field." "Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."…

Yeah I agree, these settings should be disabled by default and require explicit opt-in. That said, I am impressed by how privacy/security-conscious the OS seems to be otherwise!

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#236

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Thanks for the list!

> You can buy a used Pixel 3a for around $80 on Ebay

It's worth noting that GrapheneOS recommend Pixel 4a or newer for best support: https://grapheneos.org/faq#recommended-devices

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#237
post #152

Earlier quoted context omitted.

Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…

My bank uses SMS. It's simple and platform agnostic: even a Nokia 3310 is compatible x)

also not very safe. Attacker can duplicate your sim. This way he can call the bank and use the mobile numer as to restore bank account details. At least in Poland

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#238

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

I'm using LineageOS with neither OpenGapps nor MicroG, and can confirm that Aurora works without. There are numerous apps available from Aurora that will not function, of course, and many other inconveniences of varying severity, but it's overall a good experience.

I am using Lineage without Gapps, and every app on my phone came from F-Droid.

I assume that my carrier sees location data on my device, but as I have learned to live within F-Droid on my daily driver, I assume that I am immune from this Google intrusion.

I do have an older stock phone that keeps my Google login for when I need access to Google services. If it is powered down for a month, I am assuming that I am free of Google for that month.

Google is a destructive force upon their customer base. Abandoning Google is always the correct action.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#239
post #214

Earlier quoted context omitted.

I have the FB app but rarely use it. Why would it be phoning home when I don't have it open?

To check for notifications? I’m fairly sure they haven’t implemented a complex AI model to determine that “you are using it rarely”, so the check it out each n minutes is a constant thing.

On Android, most notifications are handled by Google Cloud Messaging. The app/site developer pushes a notification to GCM, which then puts up the notification on your device.

The ugly white elephant in the room is that Google sees the text of the notification; it's not e2ee'd. Some more privacy-oriented apps implement GCM such that it just "pokes" the app on your phone to say "hey, check in with us" and the app then fetches the notification text etc. directly. But Google still knows that you got an event from what app.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#240

Earlier quoted context omitted.

Do you have any evidence the iOS operating system is better in any significant way? The article you linked focused on the apps available in the store, not the phone OS itself (which is what this article is about).

Apps draft off what the OS allows, iOS keeps adding features at the OS level (do not track, “app tracking health” metrics, advertising opt out, etc). At best Android grudgingly offers some of this after the fact, at worst does what this article offers.

Nevermind that iOS provides an extensive list of system-level data collection toggles. Don't want to contribute traffic data? Done. Don't want to contribute cellular/wifi location data? Done. Don't want your phone collecting data about what stores you visit and when? Done.

With Android, you don't have a choice for any of that. It just does it. Google Maps constantly slurps up every bit of location related information it can, whether you like it or not.

iOS even allows for forcing apps to only have access to coarse location data - it's off by a few miles - as well as only granting location data when the app is actually in use. Also options you don't get with Android.

The only thing I miss after switching: Android allowed for controlling not just cellular data but background data.

Post reply on HN