Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

251–260 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#251

Earlier quoted context omitted.

Far in never. There's no (real) money to be made, manufacturers don't care. I use GrapheneOS. It's rough but at least it gives me peace of mind.

Why is there no money to be made? I would at least pay to buy the hardware and possibly for ongoing software support as well (depending on how they structure such support or any other "soft" features). E.g. I think its a jolly good idea if somebody really checked for a living all those open source apps. In any case if there is really no viable business model for private mainstream mobile computing we have been duped…

> Why is there no money to be made?

Not enough people care to use cut rate hardware that actually conforms to the 'wholly open' philosophy. Even Stallman couldn't maintain using fully open hardware. He had to switch to a Thinkpad with Coreboot.

People have expectations when using devices as complex as a phone or laptop to where, compared to even a desktop with Linux, having a smartphone that is fully open comes with serious drawbacks.

You could always get a LibrePhone or a Pinephone but you probably won't enjoy the experience.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#252
post #238

Earlier quoted context omitted.

I am using Lineage without Gapps, and every app on my phone came from F-Droid. I assume that my carrier sees location data on my device, but as I have learned to live within F-Droid on my daily driver, I assume that I am immune from this Google intrusion. I do have an older stock phone that keeps my Google login for when I need access to Google services. If it is powered down for a month, I am assuming that I am free…

> I am using Lineage without Gapps, and every app on my phone came from F-Droid. Did you transition or quit cold turkey? I switched to Lineage OS with micog. Actually, now that I look through what I installed via Aurora, I'm surprised how few apps there are. 3 required for work. I guess I could reduce that to one with some effort. A few financial / shopping apps that are nice to have vs using their website. Google ma…

> Google maps (not sure the replacement to that is).

Try HERE WeGo: https://play.google.com/store/apps/details?id=com.here.app.m...

It’s not quite as polished as Google Maps, but I use it as my primary maps app and have mostly not been disappointed.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#253
post #238

Earlier quoted context omitted.

I am using Lineage without Gapps, and every app on my phone came from F-Droid. I assume that my carrier sees location data on my device, but as I have learned to live within F-Droid on my daily driver, I assume that I am immune from this Google intrusion. I do have an older stock phone that keeps my Google login for when I need access to Google services. If it is powered down for a month, I am assuming that I am free…

> I am using Lineage without Gapps, and every app on my phone came from F-Droid. Did you transition or quit cold turkey? I switched to Lineage OS with micog. Actually, now that I look through what I installed via Aurora, I'm surprised how few apps there are. 3 required for work. I guess I could reduce that to one with some effort. A few financial / shopping apps that are nice to have vs using their website. Google ma…

RE Google maps, /e/OS ships with this: https://www.magicearth.com/

I've found it to be more than good enough. There's also various OSM based apps:

https://wiki.openstreetmap.org/wiki/Comparison_of_Android_ap...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#254
post #95

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Do banking applications work? I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. "?

On /e/OS with microG, I successfully use the apps for Starling Bank and Hargreaves Lansdowne. Nationwide and Nivo also both work. (these are all UK services, not sure how far they are known elsewhere)

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#255

Earlier quoted context omitted.

I've tried Osmand and found it way too slow/janky for everyday use (since it has to render the tiles locally and doesn't seem to pre-render for scrolling). Newpipe loads videos much slower than the official app and occasionally fails completely (likely because YouTube changed something). F-droid (regular, non-root install) shows me notifications to update apps, then when I tap them, I get a "there was a problem parsi…

If you don't like Newpipe you can use Youtube Vanced which is basically a pwned version of the native Youtube app. I've had some stutters with Newpipe but overall I like it. Osmand really isn't bad, sure it's a little bit slower to render but we're talking maybe 500-1000ms on a Pixel 3a. Regarding F-Droid you're right it is quite buggy, but thankfully once you've got the apps you want you don't really need to use it…

Skytube is also a good YT client available on F-Droid

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#256
post #38

Please, technical people of HN, install NetGuard on your Android phone. You will be shocked where your data goes. GDPR? Ha!

I was wondering if you could expand on your comment because I am confused. How is seeing what IP addresses an app communicates with a violation of GDPR? If I can't see the content of the data it's sending but just where it's going, that is not exactly a violation. It's not illegal to communicate with an IP address, there could be many reasons $app sends a request via a US server. Like a postman with an address and an…

Install the app. You'll see that it sends personally identifiable information (your ip address) to facebook, before you have opted in.

99% of apps also send usage stats and/or crash information to mixpanel, etc. also without opt-in.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#257
post #184

Earlier quoted context omitted.

Looking through the GrapheneOS source, the servers may not be Google servers but the system is still designed to phone home. As such, have they solved the problem or is this just another case of "Dont' trust them, trust us instead." Has anyone succeeded in running multiboot on "smartphone" hardware, i.e., where the user can boot into a choice of kernel/userland. One choice might be Android, another might be GrapheneO…

Did you actually find any examples of GrapheneOS phoning home? GrapheneOS doesn't rely on any third-parties I'm aware of. The only service provided is over-the-air security updates. It doesn't even come with an app store (although you can install F-Droid). For that reason, GrapheneOS alone fits all three categories you mentioned: It is Android, it is GrapheneOS, and it is fully controllable / doesn't ship bloatware.

It is not controllable at all: It still enforces any app author's will against the user's. Root is not offered, and the grapheneos maintainer seems to be personally offended by the thought that root could be helpful.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#258

Earlier quoted context omitted.

> I think I’ve seen movement on the tiles in its task switcher, so I’m not clear if it takes screenshots. In my experience, it seems like only the app you were in when you brought up the task switcher continues to update the screen. If you go somewhere else, like just back to the home screen, it goes static like all the rest.

This is correct. iOS snapshots the app as soon as it's moved into the background, and that snapshot is what you see. When you bring up the switcher, the foreground app isn't backgrounded yet — that only happens if you go to the home screen or actually switch apps.

If the app is using the Background App Refresh entitlements [1] (Background fetch / background processing) then it is possible for iOS to update the screenshot for the app switcher periodically even when the app is in the background

Messages does this, as you will notice that an active conversation tends to be up-to-date in the app switcher

[1] https://developer.apple.com/documentation/uikit/app_and_envi...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#259

Earlier quoted context omitted.

Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled. The time service is enabled by default but can be disabled. "An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field." "Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."…

A couple thoughts: * Usability: An OS without network connectivity checks and time sync might not be usable by non-geeks * Obscurity: The threat from these pings is low. The threat of having a phone that behaves differently than "billions of other Android devices", indicating that it's GrapheneOS or some other security-oriented OS, is arguably higher.

[deleted]

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#260

Earlier quoted context omitted.

Far in never. There's no (real) money to be made, manufacturers don't care. I use GrapheneOS. It's rough but at least it gives me peace of mind.

Why is there no money to be made? I would at least pay to buy the hardware and possibly for ongoing software support as well (depending on how they structure such support or any other "soft" features). E.g. I think its a jolly good idea if somebody really checked for a living all those open source apps. In any case if there is really no viable business model for private mainstream mobile computing we have been duped…

> Why is there no money to be made?

Because we don't really know how much hardware costs anymore. Most hardware you buy is subsidized in one way or another through data collection, from phones to TVs. Building stuff is very capital intensive, and the world changes very rapidly. And most people don't really care about data collection because they don't understand the consequences, or they don't care at all (which I find baffling). This means you'll be always facing cheaper competition. It's very hard to keep a company like that afloat.

Post reply on HN