Live data from Hacker News

Android launches yet another way to spy on users with “Privacy Sandbox” beta

arstechnica.com

121–130 of 156 posts

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#121

Earlier quoted context omitted.

> According to an analysis by StockApps.com, out of the five major digital firms (Google, Twitter, Apple, Amazon, and Facebook.) Google harvests the most data on its users. The corporation collects thirty-nine data points for each user. Apple is in a league above Amazon in protecting user privacy. It is the most privacy-conscious firm out there. Apple only stores the information that is necessary to maintain users’ a…

Apple stores data on who reads what articles in its News app to target ads. It stores data on who downloads which apps in the App Store to show ads. It will do more and more of this. Unlike Android, iPhone offers no other source for apps, and it does not let you uninstall the News app. User choice is required for real privacy. By that measure (for users who care about privacy and choose apps accordingly), Apple is th…

Basing the ad displayed on search terms entered or the page content is the opposite of a privacy violation.

The problem is companies like Google and Facebook, which track users across the web and relentlessly spy on everything they do.

Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.

>Of course, Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.

https://www.technologyreview.com/2017/05/25/242717/google-no...

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#122

Earlier quoted context omitted.

> the Google Play store doesn't work but that's no big loss It's the loss of an entire ecosystem worth of apps. If you want an inexpensive phone that will get five or six years of first party support with security updates after that, go with an iPhone SE. The original $399 version got six years of OS updates and just got another security update last month. That's $67 per year that got both an OS update and security u…

It's the loss of an entire ecosystem worth of apps. No, it's not. With very few exceptions, the Aurora store pulls apps from Google Play. About the only thing I have seen missing from Aurora store is a few super strict banking apps but you can usually just use their web site.

No paid apps though, right? That would be somewhat painful for me.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#123

Earlier quoted context omitted.

>With hardware remote attestation there will no longer be any point in even owning an android phone anyway. Android is obviously inferior to iOS in every way but the whole point was you could have control over the machine and do whatever you wanted. Now apps will be able to verify that you "tampered" with the phone and will refuse to run, and since it's hardware cryptography it cannot be faked without massive effort.…

Wait a minute, will something like this really come to Android phones? Google has been doing this for quite some time to prevent unlocked devices from accessing the Play Store. The solution is to avoid Google Play --- along with all other Googly things.

This is a security feature and the play store doesn't require it AFAIK. Apps can choose to use it as a signal on whether a client is secure. Unlocked devices are insecure because an attacker can flash a malicious image and steal all of your sensitive data such as an authentication token for your bank account.

If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you or treat you different since you are less secure than the other users.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#124

Earlier quoted context omitted.

Apple stores data on who reads what articles in its News app to target ads. It stores data on who downloads which apps in the App Store to show ads. It will do more and more of this. Unlike Android, iPhone offers no other source for apps, and it does not let you uninstall the News app. User choice is required for real privacy. By that measure (for users who care about privacy and choose apps accordingly), Apple is th…

Basing the ad displayed on search terms entered or the page content is the opposite of a privacy violation. The problem is companies like Google and Facebook, which track users across the web and relentlessly spy on everything they do. Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online. >Of course, Google has been able to…

> Basing the ad displayed on search terms entered or the page content is the opposite of a privacy violation

It doesn't just show ads based on current search terms. It uses your install and usage history to show personalized ads. https://www.macrumors.com/2022/10/22/apple-announces-more-ap...

The difference between Android and iOS is that with Android, you don't have to use spying services from Google or Apple. With iOS, you are required to use spying services from Apple.

> Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online.

Google gets your purchase history whether you use Android or iOS. iOS is strictly worse for privacy.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#125

Earlier quoted context omitted.

Wait a minute, will something like this really come to Android phones? Google has been doing this for quite some time to prevent unlocked devices from accessing the Play Store. The solution is to avoid Google Play --- along with all other Googly things.

This is a security feature and the play store doesn't require it AFAIK. Apps can choose to use it as a signal on whether a client is secure. Unlocked devices are insecure because an attacker can flash a malicious image and steal all of your sensitive data such as an authentication token for your bank account. If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you…

Yeah, sure. An "optional security feature".

> don't complain when services don't want to serve you or treat you different since you are less secure than the other users

Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different".

"Don't want to serve us" unless we let them invade and own our machines? Please. This should be illegal.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#126

Earlier quoted context omitted.

This is a security feature and the play store doesn't require it AFAIK. Apps can choose to use it as a signal on whether a client is secure. Unlocked devices are insecure because an attacker can flash a malicious image and steal all of your sensitive data such as an authentication token for your bank account. If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you…

Yeah, sure. An "optional security feature". > don't complain when services don't want to serve you or treat you different since you are less secure than the other users Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different". "Don't want to serve us" unless we l…

>They should not be allowed to discriminate against me just because I chose to own my system.

App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind.

>They should not even be able to figure out what software I'm running, to say nothing of "treating me different".

They just want to know that the client has not been tampered with so that they know you are not going to shall user's tokens, scrape people's information, or mondo automated actions as a bot. A signal that you are using the vanilla client makes you much more trust worthy to a service.

>"Don't want to serve us" unless we let them invade and own our machines?

Apps aren't invading your machine. They just want some guarantees about the environment they are operating in. The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#127
post #68

I have a bunch of issues with the "Privacy Sandbox", but my #1 issue is that it's called "Privacy Sandbox". That term implies that a sandbox is being used to preserve your privacy, when it is, in fact, a system designed for the opposite of that.

How I hate this war is peace "newspeech" . I don't even know what it's called. Anti speech? Lying ?

It is newspeak.

And what do you mean "lying" ? There are no lies anymore. Only "sources", CIA press releases and "insert your enemy here" propaganda. /s

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#128
post #23

I've been staunchly on the Android side of the Android / iOS question, but this carry-on with refusing to block tracking like Apple has done is really making me consider switching.

With hardware remote attestation there will no longer be any point in even owning an android phone anyway. Android is obviously inferior to iOS in every way but the whole point was you could have control over the machine and do whatever you wanted. Now apps will be able to verify that you "tampered" with the phone and will refuse to run, and since it's hardware cryptography it cannot be faked without massive effort.…

> Android is obviously inferior to iOS in every way

Damn how i hate to write that: At least on Android you can turn off WI-Fi and mobile data, unless iOS which keeps it enabled "for system services".

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#129
post #68

I have a bunch of issues with the "Privacy Sandbox", but my #1 issue is that it's called "Privacy Sandbox". That term implies that a sandbox is being used to preserve your privacy, when it is, in fact, a system designed for the opposite of that.

How I hate this war is peace "newspeech" . I don't even know what it's called. Anti speech? Lying ?

From "Yes Minister".

"Always dispose of the difficult bit in the title. Does less harm there than in the text." https://www.youtube.com/watch?v=40Br165MhLU

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#130
Anyone remember FLOC, which google attempted to push through on the web and then was forced to abandon? [1]. This just seems to be "floc, but for mobile apps".

[1] https://www.theverge.com/2022/1/25/22900567/google-floc-aban...

Post reply on HN