Live data from Hacker News

Everyone going to World Cup must have this app, experts are sounding the alarm

nrk.no

341–350 of 354 posts

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#341

Earlier quoted context omitted.

The recipient of an abortion is the pregnant person who does not want to be pregnant.

There are two people involved. One is sometimes ignored, or dehumanized, but still there.

And nobody has the right to inhabit another persons body without their consent.

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#342

Earlier quoted context omitted.

The recipient of an abortion is the pregnant person who does not want to be pregnant.

There are two people involved. One is sometimes ignored, or dehumanized, but still there.

Unscientific nonsense!

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#344
post #324

The permissions mentioned sound like someone that doesn't understand the permissions systems used by Android and iPhone tried to translate them. So this part of the article is almost useless as it is hard to figure out what permissions the app actually has. I don't understand the Android permissions system well enough here, but I would be especially curious about which API version this is targeting as I don't know ho…

From my phone: I have Eteraz installed Read and Write to the file system - required to allow storage of a small encrypted file which holds a unique ID, QR code, infection status, configuration parameters, and proximity data of other devices using the Application. Not much more than a cookie.

You can't know what it is reading though. The app could theoretically be sending all your photos to the government. Would be interesting to see someone reverse engineering it.

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#345
post #324

The permissions mentioned sound like someone that doesn't understand the permissions systems used by Android and iPhone tried to translate them. So this part of the article is almost useless as it is hard to figure out what permissions the app actually has. I don't understand the Android permissions system well enough here, but I would be especially curious about which API version this is targeting as I don't know ho…

From my phone: I have Eteraz installed Read and Write to the file system - required to allow storage of a small encrypted file which holds a unique ID, QR code, infection status, configuration parameters, and proximity data of other devices using the Application. Not much more than a cookie.

Is there a reason this must be in the user's file location and not in the app's own internal files?

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#346

Earlier quoted context omitted.

Seriously? You're just gonna act like it's okay for them to have laws against being gay ?

It's for Quatar to decide what their laws are. They aren't telling other countries what their laws should be. Why this condescending tone and sense of moral superiority?

If a country makes Islam illegal, would you think some Muslim countries would try to tell to that country to change its laws or not?

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#347
post #247

Luckily my country is already so creepy this qatar thing is a fully non-issue for me. In fact, i wouldn't even have to know about the app before travelling to deal with this. ANY time I go through US airport security, I don't take my phone. I take a burner phone that doesn't have any of my accounts logged in or personal data on it. From my understanding, they can and will dd your whole phone image to some national se…

>From my understanding, they can and will dd your whole phone image to some national security database while holding you for 'enhanced screening.' this is not true, maybe at customs but not when traveling domestically. i had a dog sit down while walking through security and TSA had to swab everything i was traveling with. my phone was swabbed but nothing was ever connected to it.

It's the same TSA. You didn't have the appropriate database flag at the time. Those are explosives dogs, looking for explosives not selfies.

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#348
post #181
post #63

Earlier quoted context omitted.

Cut that by a factor of 10. If you need do be connected, but don't care about things like cameras or gaming specks, then I can get you an android phone for the equivalent of about $30. This is cheap enough to throw in the trash as you board for your flight home. Connectivity is a slightly larger problem. In some places you can get a prepaid SIM card for less than a dollar, other places need some form of registration.…

Good luck running even something as "simple" as slack on a $30 dollar Android phone. If new you usually want to throw in at least 150-250$ for an Android phone that doesn't run things with high latency, at least in my experience as a mid-range device user.

If I'm travelling for leisure, I would prefer things like Slack to stay as far away from me as possible. Preferably on my work machine that I left behind on my home continent.

If I travel for work, or if my employer requires me to have Slack (or similar) on my device and with me at all times, then they can provide me with a dedicated device for that purpose and that purpose alone. It's then their problem to worry about operational security associated with having work comms on a device that might have to be compromised by a foreign government.

Even the most basic android phone supports email and text (sms) out of the box. My country enjoys incredibly deep WhatsApp penetration, and subsequently it's become the default mode of communication for almost everyone. WhatsApp runs on almost anything. Back in the day they even had .jar files to download and install on your Symbian dumb phones.

I'm talking here about a "burner" device as it's sometimes called. The minimum viable communicator that you can take with you so that you can keep in touch with friends and family and be reachable in the case of an emergency.

But you make an interesting argument for not needing to go with a new device. A beat-up second-hand mid-ranger from a few years ago will probably work just as well. I have a drawer full of them, and if I don't have any, they can be had for very cheap.

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#349

Earlier quoted context omitted.

But dont these apps require network access to function?

Not at the venue, no. The relevant tokens are saved locally and the barcodes are rendered on-device once you’ve accessed the ticket, which you can do hours/days in advance. Some of TicketMaster’s API docs for this are publicly available so you can get an idea of how it works - https://developer.ticketmaster.com/products-and-docs/apis/pa...

I just used (against my will) the Axs app to go to a local show. It required location services to be enabled and didn't show the random qr code until it could verify I was at the venue.

I haven't seen a paper ticket in a long time.

Re: Everyone going to World Cup must have this app, experts are sounding the alarm

#350

Earlier quoted context omitted.

I did worry that my comment might incorrectly imply that, so I deliberately reworded it to say a particularly restrictive "Secure Boot" setup , but I guess that's still ambiguous. You're right, Debian "supports" such a set of restrictions, in the sense that a manufacturer could build devices that would comply with these hypothetical laws while only using vanilla Debian packages, but my point was that such a device wo…

No. Debian supports Secure Boot, and that means anybody can add their own signing key and sign and boot their own kernel, packages and everything else. As long as users can update the signing keys it's all good. If not, it's tivoization, and it breaches GPL.

> anybody can add their own signing key

That's assuming the hardware supports it. I'm imagining a (very likely) world where devices will either no longer support self-generated keys, or where using such keys makes your device unable to access the mobile network or the internet. (The latter sort of device might in theory be buildable, and run Debian just fine, but I don't think it would have enough buyers for a manufacturer to waste money on producing it).

> If not, it's tivoization, and it breaches GPL.

Contracts (and software licences) cannot override the law. If a government wants to ban self-generated keys (and/or make anti-Tivoization clauses unenforceable), then it can easily do so, and make all "Debian phones" either not feel like Debian, or not feel like phones.

Post reply on HN