Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

261–270 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#261
post #180

Earlier quoted context omitted.

It depends per bank; mine discontinued the paper OTP pad as well as the SMS codes, and gave me a separate 2FA device when I didn't want to use their app. I don't think banks can force you to have a smartphone yet.

> separate 2FA device FYI in New Zealand a few banks can provide a device (e.g. RSA SecurID) for proper non-bank 2 factor auth with consumer accounts. However some major banks only use phones for 2FA (app or SMS). The norms seem to vary considerably depending on country.

Which banks provide a device?

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#262
post #212

Earlier quoted context omitted.

Can I expect CalyxOS to support the Pixel 6 rather soon? Is e.g. camera performance dependent on closed source Google code/firmware? What are the limitations there? I was going for GrapheneOS, but tbh seeing that one main developer's personality issues turned me off big time. I don't care about technical advantages, if I have to trust in that guy's impulse control. Too small a project for that.

GrapheneOS’s main dev can come across as paranoid, but it is sort of understandable given the history of the project. Nonetheless, they are doing a spectacular job and I think using GCam with properly set permissions is the best of both words.

Paranoia is not the problem. The problem is general hostility and not being open to other viewpoints and ideas. Also I feel some kind of power hunger, which makes me feel really uncomfortable surrendering basically full control over my phone to these people.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#263
post #21

I'm wondering if Nokia phones with Android One are not snitching on their users like the others are.

Nokia licensed their mobile brand and now it's some Chinese producer slapping the logo on the devices. Probably on pair with Xiaomi and Huawei.

probably below Xiaomi even: they promised an open bootloader once, but broke that promise and every bootloader after that was fully locked up.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#264
post #95

Earlier quoted context omitted.

Do banking applications work? I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. "?

What kind of purchase/checkout system works like this? I have never seen one, but if I had, I would not complete the transaction.

Reading the comment I was confused as well - it sounds as if the user provides his banking login to the merchant as part of the checkout process. However they mean that the transaction has to be approved via banking app, not unlike a 2FA authenticator app.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#265

Earlier quoted context omitted.

> separate 2FA device FYI in New Zealand a few banks can provide a device (e.g. RSA SecurID) for proper non-bank 2 factor auth with consumer accounts. However some major banks only use phones for 2FA (app or SMS). The norms seem to vary considerably depending on country.

Which banks provide a device?

I have had SecurID tokens for ASB and SBS accounts. I have been told Westpac does not provide secure 2FA. I am not sure about other banks.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#266
post #262
post #212

Earlier quoted context omitted.

GrapheneOS’s main dev can come across as paranoid, but it is sort of understandable given the history of the project. Nonetheless, they are doing a spectacular job and I think using GCam with properly set permissions is the best of both words.

Paranoia is not the problem. The problem is general hostility and not being open to other viewpoints and ideas. Also I feel some kind of power hunger, which makes me feel really uncomfortable surrendering basically full control over my phone to these people.

From what I’ve seen, he gets summoned, and angry when things like “Calyx pays great attention to usability, while GrapheneOS gives more focus to security at the price of usability” gets mentioned, which is just false.

Also, do note that it is indeed a dangerous business — false sense of security is the worst. And there are plenty of companies taking advantage of people wanting something “privacy-oriented”.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#267
TL;DR: They track long-lived phone identifiers and some send usage data like:

> Xiaomi telemetry logs the user interaction with the dialer app when receiving a phone call, including the start and end times of the call

...and Microsoft SwiftKey logs the apps you open, how many characters you typed (with timestamps), and sends crash dumps that contain who-knows-what.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#268
post #95

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Do banking applications work? I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. "?

> I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. "

Huh? This is not a real thing.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#269
post #4
post #2

Last I checked the default keyboard samsung installs on their phones was collecting what you typed and sharing/selling that data with third parties. I try not to store or access any personal information on my cell phones when i can avoid it, but at a certain point, just having one is enough to seriously compromise your privacy. Strong regulation with real sharp teeth is the only thing that can fix this situation.

https://play.google.com/store/apps/details?id=org.dslul.open... OpenBoard is a 100% foss keyboard based on AOSP, with no dependency on Google binaries, that respects your privacy.

Alternatively, you can just disable internet access to any of the keyboards via 'Settings' > 'Apps and notifications'.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#270

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

OSMAnd is visually difficult to parse (especially at a glance) and fairly complicated to use. It is not a good map app.
Post reply on HN