A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…
Android phones are sending significant amount of user data with no opt-out [pdf]
241–250 of 377 posts
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#242Earlier quoted context omitted.
I'm using LineageOS with neither OpenGapps nor MicroG, and can confirm that Aurora works without. There are numerous apps available from Aurora that will not function, of course, and many other inconveniences of varying severity, but it's overall a good experience.
I am using Lineage without Gapps, and every app on my phone came from F-Droid. I assume that my carrier sees location data on my device, but as I have learned to live within F-Droid on my daily driver, I assume that I am immune from this Google intrusion. I do have an older stock phone that keeps my Google login for when I need access to Google services. If it is powered down for a month, I am assuming that I am free…
Did you transition or quit cold turkey? I switched to Lineage OS with micog. Actually, now that I look through what I installed via Aurora, I'm surprised how few apps there are. 3 required for work. I guess I could reduce that to one with some effort. A few financial / shopping apps that are nice to have vs using their website. Google maps (not sure the replacement to that is).
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#243Earlier quoted context omitted.
> Obviously and that's my point. You are not going to avoid Google if you use the web. The best you can do is limit exposure. That couldn't have been your point. It's very easy to avoid having a gmail account. > This is ignorant and unhelpful. People here don't know you personally, or your needs. Most people don't need gmail for work. If your job requires you to use google products, it's going to be difficult for you…
>That couldn't have been your point. It's very easy to avoid having a gmail account. Did you miss the part where I told you we have Google Workspace (GSuite) and I have to use it for work? What part of getting rid of that is easy? I cannot stop using it end of story. >People here don't know you personally, or your needs. Most people don't need gmail for work. I feel like you're not aware of the fact that Gmail is use…
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#244Earlier quoted context omitted.
Technically, the Internet Connectivity Check on LineageOS also sends your position/IP to Google, and also avoids a VPN tunnel because it's lower down the stack. I can recommend LineageOS, however be aware that lots of malware infected builds have made it to xda dev in the past, so you should build it yourself if possible (or use the official downloads). Regarding the Connectivity Check: You can add all google related…
> however be aware that lots of malware infected builds have made it to xda dev in the past, Can you point me to some? How were they caught? I knew this was a possibility, but I hadn't seen it actually happen before.
I only found out by coincidence of another dev asking me to verify the build. The nature of how Android is built (with all its hundreds of repositories) isn't made for verifiable builds, so it's really hard to prove or audit.
From what I've found usually the builds with custom UIs or skins on top are infected with stuff either the person packaging it doesn't know about (benefit of the doubt) or do, but it comes out a year later when someone skeptical checks for it.
Verification is especially hard because everybody on xda dev is using some paid adfly links or some google storage or dropbox links that will change in intervals (depending on how much traffic they produce they'll get blocked quickly).
So yeah, I think the need for a hash based end to end verification tool is kind of there.
But honestly I have no idea how to build it because even the partition setup of old flash storage using devices is so messed up that there can be side effects when an apk is put in /emulated storage folders.
I think the only future proof way to do this is going mainline like the postmarketOS devs try to do. But until we're there I'm probably dead of old age already. I don't believe in the Android ecosystem anymore, because this is a governance coordination problem that's not easily fixable. Hosting all outdated kernels alone with all the custom drivers is way too much traffic for any open source project to pay for.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#245I don't think this is news to anyone (in general), but it is increasingly becoming the differentiating factor between Android and iOS. Apple is all-in on customer privacy and Google hasn't really been able to respond on that front since their business model depends on targeted advertising based on data collected about their users. The question is whether regular people really care about privacy more than they do abou…
Apple is just better at pretending being all in. They were part of PRISM. They recently added a systematic scan, compare and report routine to all your pictures. They forces you to tie your phone to an Apple account just to use it. My android phone doesn't have an account, or even an email linked to it. Apple now has an entire mesh network of BT devices constantly looking up each others, even if some of them are not…
Isn't that still a thing?
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#246Earlier quoted context omitted.
Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled. The time service is enabled by default but can be disabled. "An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field." "Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."…
Yeah I agree, these settings should be disabled by default and require explicit opt-in. That said, I am impressed by how privacy/security-conscious the OS seems to be otherwise!
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#247Earlier quoted context omitted.
Thanks for this, just installed it and when I click to enable in my settings, I get an Attention message: "OpenBoard may be able to collect all the text you type, including personal data such as passwords and credit card numbers" This appears to be from Samsung, trying to deter users from using keyboards other than their own.
I'm glad they let people know it's possible, a keyboard isn't something you should install without some careful consideration because they can be used as keyloggers. I just wish they'd been as clear about that with the keyboard already installed on the phones when they ship. Anyone seeing that warning might easily think it's safer not to replace their stock keyboard even though it's already doing the very thing they…
To be frank, Android should not allow input methods access to internet/filesystem in the first place. But that would have hindered Google's own keylogger, so...
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#248Earlier quoted context omitted.
It depends per bank; mine discontinued the paper OTP pad as well as the SMS codes, and gave me a separate 2FA device when I didn't want to use their app. I don't think banks can force you to have a smartphone yet.
Does nobody in the EU do computers ? How do they pass asinine laws like this ? I mean, from the outside, it always appears as though the EU is much better than the US when it comes to consumer rights, but it always feels like they don't have a very good grip on technology.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#249Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. I try not to store or access any personal information on my cell phones when i can avoid it, but at a certain point, just having one is enough to seriously compromise your privacy. Strong regulation with real sharp teeth is the only thing that can fix this situation.
https://play.google.com/store/apps/details?id=org.dslul.open... OpenBoard is a 100% foss keyboard based on AOSP, with no dependency on Google binaries, that respects your privacy.
Re: Android phones are sending significant amount of user data with no opt-out [pdf]
#250Earlier quoted context omitted.
Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…
Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled. The time service is enabled by default but can be disabled. "An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field." "Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."…
* Usability: An OS without network connectivity checks and time sync might not be usable by non-geeks
* Obscurity: The threat from these pings is low. The threat of having a phone that behaves differently than "billions of other Android devices", indicating that it's GrapheneOS or some other security-oriented OS, is arguably higher.