Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

311–320 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#311
post #238

Earlier quoted context omitted.

I am using Lineage without Gapps, and every app on my phone came from F-Droid. I assume that my carrier sees location data on my device, but as I have learned to live within F-Droid on my daily driver, I assume that I am immune from this Google intrusion. I do have an older stock phone that keeps my Google login for when I need access to Google services. If it is powered down for a month, I am assuming that I am free…

> I am using Lineage without Gapps, and every app on my phone came from F-Droid. Did you transition or quit cold turkey? I switched to Lineage OS with micog. Actually, now that I look through what I installed via Aurora, I'm surprised how few apps there are. 3 required for work. I guess I could reduce that to one with some effort. A few financial / shopping apps that are nice to have vs using their website. Google ma…

> Google maps (not sure the replacement to that is).

OsmAnd~ is great :-)

https://f-droid.org/en/packages/net.osmand.plus

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#312
post #272

Earlier quoted context omitted.

I don't think this was driven by law, but by an appropriate wish to increase transaction security (you really shouldn't use SMS for this anymore). There are some rules here that are nonsense, such as know-your-customer laws that force me to enter my home address even when the product or service (say, a concert or train ticket) is delivered to me entirely electronically. Most of the move to purely electronic payment i…

I agree that you shouldn't use SMS. My point was that unless the law (if there is one), requires that 2FA be enabled in an accessible way, the banks will do their own thing with the phone push notification system. The 2FA situation is quite bad in the US too, but a small no. of banks do offer TOTP.

This whole situation caused me to throw up my hands in Thailand and now I pay for most everything in cash since it's still a cash-friendly nation.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#313
post #311

Earlier quoted context omitted.

> I am using Lineage without Gapps, and every app on my phone came from F-Droid. Did you transition or quit cold turkey? I switched to Lineage OS with micog. Actually, now that I look through what I installed via Aurora, I'm surprised how few apps there are. 3 required for work. I guess I could reduce that to one with some effort. A few financial / shopping apps that are nice to have vs using their website. Google ma…

> Google maps (not sure the replacement to that is). OsmAnd~ is great :-) https://f-droid.org/en/packages/net.osmand.plus

OsmAnd has been real hit or miss for me. It definitely has a lot more friction than Google Maps, and sometimes I'm not able to find a destination even with the full address. I want to use it, and I want to support the ecosystem, but damn if it doesn't make it difficult.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#314
post #306

Earlier quoted context omitted.

Yeah I agree, these settings should be disabled by default and require explicit opt-in. That said, I am impressed by how privacy/security-conscious the OS seems to be otherwise!

Network time is pretty important for things like HMACs.

Maybe, but couldn't they let me set my own server and not hit a predefined time server without asking me?

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#315

It seems worth talking about the fact that it appears to be the vendor of the phone putting this kind of snooping in place. Blaming Android is missing the real culprit. Like they say in the article, we need stronger controls on people's data for whoever happens to make the phone's OS.

For practical purposes Android is not just the open source codebase but also the economic institution, where various middlemen get to do sketchy and low-rent stuff in between the trusted brand and the consumer. That is the “openness” that sets it apart from its competitor.

And at the end of the day that's the reason I don't use it anymore. It's just the wild-west.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#316

Earlier quoted context omitted.

Yeah I agree, these settings should be disabled by default and require explicit opt-in. That said, I am impressed by how privacy/security-conscious the OS seems to be otherwise!

You can't really get rid of connectivity check, because it is a part of public API. Applications use it to check whether a network has internet access. Android itself uses it to detect captive portals and prompt user to authenticate when network requires authentication/payment via a web page.

I'm not suggesting they get rid of connectivity check. They already provide the option to disable it. All I'm suggesting is that it's not enabled until the user indicates they want it to be. This could be asked during a "first time" setup flow like most smartphones have.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#317
post #26

Android takes snapshots (screenshots) of apps as soon as you switch to another app. When you view the app list, it already has the last view of each app. But the Xiaomi/MIUI Android sends over those screenshots back to the company is new information.

> Android takes snapshots (screenshots) of apps as soon as you switch to another app.

For the interested, here's info on where those are stored: https://android.stackexchange.com/questions/172913/where-doe...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#318

Earlier quoted context omitted.

If you think Google is adversarial then don't use Gmail; It seems strange to avoid using their 'apps' but continuing to use their products? I think you just handed them that information when you logged into their website.

>I think you just handed them that information when you logged into their website. Obviously and that's my point. You are not going to avoid Google if you use the web. The best you can do is limit exposure. >Google is adversarial then don't use Gmail This is ignorant and unhelpful. Do you think I just decided not to consider that option? I don't have an option. I have to use it for work. This is the problem with the…

I don't think it's fair to say I was ignorant when you only now mention need it for work. You could use a second handset, or try asking your employer to move away from Google products, or even find a new employer. There's plenty of options here.

If you say that the best you can do is limit exposure, then do that!

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#319

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

For the average end user however, this is a distinction without a difference. A Galaxy S21 you buy from the store has Google Play and will be sending info of 99.99% of users to Google

A Galaxy S21 comes without Lineage pre-installed.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#320
post #152

Earlier quoted context omitted.

Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…

Didn't know this was driven by PDS2. As much as I appreciate the convenience, I still find the whole drive fucking annoying - especially that, with all the talk about data portability, I still can't get a simple API endpoint I could point a script at to fetch me my account's balance. Yes, I'm bitter. If there's ever a bank that puts end-user automation first, I'll switch in a second.

If you are in the UK, Starling offers a relatively simple API.
Post reply on HN