Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

281–290 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#281
post #272

Earlier quoted context omitted.

Does nobody in the EU do computers ? How do they pass asinine laws like this ? I mean, from the outside, it always appears as though the EU is much better than the US when it comes to consumer rights, but it always feels like they don't have a very good grip on technology.

I don't think this was driven by law, but by an appropriate wish to increase transaction security (you really shouldn't use SMS for this anymore). There are some rules here that are nonsense, such as know-your-customer laws that force me to enter my home address even when the product or service (say, a concert or train ticket) is delivered to me entirely electronically. Most of the move to purely electronic payment i…

I agree that you shouldn't use SMS. My point was that unless the law (if there is one), requires that 2FA be enabled in an accessible way, the banks will do their own thing with the phone push notification system. The 2FA situation is quite bad in the US too, but a small no. of banks do offer TOTP.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#282
post #180

Earlier quoted context omitted.

It depends per bank; mine discontinued the paper OTP pad as well as the SMS codes, and gave me a separate 2FA device when I didn't want to use their app. I don't think banks can force you to have a smartphone yet.

> I don't think banks can force you They can and do. There are a number of banks where you have absolutely no choice.

you have a choice to not be their customer.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#283

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

OSMAnd is visually difficult to parse (especially at a glance) and fairly complicated to use. It is not a good map app.

Fun, I guess this is just a question of habit. Nowadays I use OSMAnd mostly, and when I have to use Google's Maps (OSMAnd's search isn't great, and public transportation isn't there), I'm lost, and the app never shows the information I want.

It's happened to me a lot of times with Google's Maps (with regard to how frequent I use Google's Maps) that I'm looking for something, I KNOW it's there, I'm searching for it (like "groceries" for a grocery store), and the only way Google's Maps would ever show it to me is by zooming it until the ONLY thing on screen is building, and then it does display it.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#284

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Almost all of these just need a browser, without any apps. I personally don't need any notifications, but I'm retired so it's easier.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#285
post #152

Earlier quoted context omitted.

Some will, however I have heard some of these apps have janky hooks into Android's trust system which will break them on non-google distros. Personally I wouldn't suggest having banking apps on a phone. You can always use the web browser if you absolutely must access those accounts.

Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…

[deleted]

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#286

How far are we from a phone that: ships fully formed - no flashing and stuff, has reliable supply chain and production, is open source only, usable on a daily basis (stable, normal battery life, all basic apps, easy upgrades) and ideally repairable / recyclable as much as possible? I would leave "high-end" specs and price constraints out of scope to make this a reality sooner than later. There are several contenders…

Nothing that appeals to general public, OpenMoko was released in 2006.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#287

Earlier quoted context omitted.

Why is there no money to be made? I would at least pay to buy the hardware and possibly for ongoing software support as well (depending on how they structure such support or any other "soft" features). E.g. I think its a jolly good idea if somebody really checked for a living all those open source apps. In any case if there is really no viable business model for private mainstream mobile computing we have been duped…

> Why is there no money to be made? Not enough people care to use cut rate hardware that actually conforms to the 'wholly open' philosophy. Even Stallman couldn't maintain using fully open hardware. He had to switch to a Thinkpad with Coreboot. People have expectations when using devices as complex as a phone or laptop to where, compared to even a desktop with Linux, having a smartphone that is fully open comes with…

well, "fully open" is just an ideal. I think I could live with proprietary bits that are not involved in the private data trade.

it doesn't have to be "cut rate". I left the specs/price point open for that reason. But indeed thinking of it as a tool, not as a trend-following gadget with 12 cameras and the screen size of a laptop.

Just interested to see whether this approach is viable.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#288
post #53

Earlier quoted context omitted.

I had a Pixel. That it took a screenshot when I switched apps makes sense. It allows the task switcher to open immediately and show the most recent state of all my apps. A screenshot of some sort is mandatory for the OCR functionality that allowed me to select text from these tiles in the task switcher (super handy!). I’m now on iOS 15 on an iPhone 12 Pro Max. I think I’ve seen movement on the tiles in its task switc…

As I understand it, each iOS application is sort of like its own 3D plane within a larger environment, hence why the launcher shows up without any lag. I hope someone can do the work of pasting the original Aqua framework overview that’s probably still hiding somewhere on the Apple website. The manner in which the combination of OpenGL (Metal?) and PDF work to render UI and elements on OS X and iOS is really quite re…

https://developer.apple.com/library/archive/documentation/Co... might be what you're after?

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#289

The issue with Android is it's extremely restrictive from a firewall perspective, I guess exactly as designed. I cannot dictate what apps chat over the internet or to what IP's (say, a setting to only allow EU-only addresses). Of course this means - rightfully or wrongly - you have to move this to another layer - probably PiHole or router level, but even then there could be gaps (can it use mobile data with you unawa…

Custom ROMs like LineageOS which is in this study does have an inbuilt firewall. Long press an app and you can deny internet access entirely, deny VPN access, etc.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#290

Earlier quoted context omitted.

Why is there no money to be made? I would at least pay to buy the hardware and possibly for ongoing software support as well (depending on how they structure such support or any other "soft" features). E.g. I think its a jolly good idea if somebody really checked for a living all those open source apps. In any case if there is really no viable business model for private mainstream mobile computing we have been duped…

> Why is there no money to be made? Because we don't really know how much hardware costs anymore. Most hardware you buy is subsidized in one way or another through data collection, from phones to TVs. Building stuff is very capital intensive, and the world changes very rapidly. And most people don't really care about data collection because they don't understand the consequences, or they don't care at all (which I fi…

this is plausible (and very worrisome if really true). We are not talking about an aspirational consumer device, it is already the case that you are being cutoff from regular life / the economy without one.

Incidentaly, I don't buy the "people don't care" argument. First of all, people do care. There is massive legislation in the EU (which represents half a billion people) towards data privacy. They are not freaks - well informed people obviously care about privacy. This touches also companies / commercial privacy and states (data sovereignty etc). But it is true that large numbers around the world are dazed and confused ("don't care") as nobody credible (and holding a large mouthpiece) is actually warning them.

But if you are right and its not viable (e.g why did blackberry not survive given companies at least should appreciate privacy) it is a baffling state to have degenerated into.

Post reply on HN