Live data from Hacker News

Android launches yet another way to spy on users with “Privacy Sandbox” beta

arstechnica.com

141–150 of 156 posts

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#141

Earlier quoted context omitted.

Basing the ad displayed on search terms entered or the page content is the opposite of a privacy violation. The problem is companies like Google and Facebook, which track users across the web and relentlessly spy on everything they do. Google literally spies on everyone's credit/debit card transaction data now, so they can spy on your offline life as much as they already do online. >Of course, Google has been able to…

> Basing the ad displayed on search terms entered or the page content is the opposite of a privacy violation It doesn't just show ads based on current search terms. It uses your install and usage history to show personalized ads. https://www.macrumors.com/2022/10/22/apple-announces-more-ap... The difference between Android and iOS is that with Android, you don't have to use spying services from Google or Apple. With…

> Google gets your purchase history whether you use Android or iOS.

> Apple only stores the information that is necessary to maintain users’ accounts.

The difference is clear.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#142
post #79
post #68

I have a bunch of issues with the "Privacy Sandbox", but my #1 issue is that it's called "Privacy Sandbox". That term implies that a sandbox is being used to preserve your privacy, when it is, in fact, a system designed for the opposite of that.

After all the crap that Google put in Android, I still don't understand why some other alternative ecosystems like Ubuntu Phone or GrapheneOS or Mankato (PinePhone) aren't attractive for users and developers. What's holding everyone back? I understand that without users there won't be apps, but also without apps there won't be users, since they offer just the basics. Imagine if TikTok or WhatsApp have had an app for…

Hardware support. Most of these distributions only work on very limited set of phone models

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#143
post #133

Earlier quoted context omitted.

>It's the loss of an entire ecosystem worth of apps. He literally just said that he used the Aurora store as an alternative. If you don't know what that is, it is basically an anonymous version of the Play Store. Highly recommended

Can you buy apps on the Aurora store?

Yes, see my post above.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#144
post #31
post #30

Earlier quoted context omitted.

Can any of these privacy-oriented forks support a device from within the last two years with a headphone jack?

I have the fairphone 4 with divestOS: https://shop.fairphone.com/ https://divestos.org/pages/devices#device-fp4 Super happy with it, but yeah no headphone jack, but i have it with the usb-c convertor.

I'm not happy with that compromise. I don't want to choose between charging and audio. And the dongles that can do both are actually really bulky. And Bluetooth headphones are a scam: too small to be repaired, must worry about batteries, Bluetooth likes to be flaky in general, almost all buds have terrible frequency response curves so the audio quality is not very good.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#145
post #120

Earlier quoted context omitted.

How does the Librem 5 support verified boot? What about user data encryption? Those are the first, most basic security features I am expecting from a smartphone. How about app sandboxes and strict MAC policies?

Beats me, I dunno if it does. But if it actually has no ad network tracking, that's more than any other platform, and could easily be worth the extra cost if you actually care about that. Lots and lots of people say they don't want to be tracked by ad companies. But how many are willing to open their wallets to make it happen? I'd say you can judge how sincere their commitment is by that.

What about AOSP or GrapheneOS? Those also lack all tracking. Not to mention the security, and can you really have privacy without security?

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#146

Earlier quoted context omitted.

How does the Librem 5 support verified boot? What about user data encryption? Those are the first, most basic security features I am expecting from a smartphone. How about app sandboxes and strict MAC policies?

Librem 5 has full disk encryption since PureOS 10 was released. See also: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque... .

Correct me if I'm wrong, but the way FDE is implemented in Librem 5 means that it is only effective when the phone is turned off? The disk is decrypted when you type in your LUKS passphrase and after that, it stays decrypted until you completely power it off or reboot. That makes it pretty much useless on a phone that you carry around.

The linked source has a lot of stuff that is done "in the future" and basically all of those "in the future" suggestions, are inferior to what AOSP has had for years.

The document lists some of the drawbacks of Librem 5, such as the use of memory-unsafe languages, and then blames Android for also relying on the same memory-unsafe languages and even some Android-specific components written in memory-unsafe languages. The fact is that Android has tons of mitigations specifically for this problem, which Librem 5 completely lacks. They're not comparable in that way. Librem 5 basically exposes the entire Linux kernel attack surface, whereas Android has multiple layers of protection between userspace and the Linux kernel. Apps written in memory safe language, proper app sandboxes, hardened memory allocator, extremely strict SELinux policies, CFI, PAC, ShadowCallStack, etc.

The only nice thing Librem 5 has, are the killswitches, but do those really matter at this point?

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#147
post #79
post #68

I have a bunch of issues with the "Privacy Sandbox", but my #1 issue is that it's called "Privacy Sandbox". That term implies that a sandbox is being used to preserve your privacy, when it is, in fact, a system designed for the opposite of that.

After all the crap that Google put in Android, I still don't understand why some other alternative ecosystems like Ubuntu Phone or GrapheneOS or Mankato (PinePhone) aren't attractive for users and developers. What's holding everyone back? I understand that without users there won't be apps, but also without apps there won't be users, since they offer just the basics. Imagine if TikTok or WhatsApp have had an app for…

Banking apps (not all but many), android auto, tap to pay. Those are three huge sacrifices for most people.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#148

Earlier quoted context omitted.

Librem 5 has full disk encryption since PureOS 10 was released. See also: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque... .

Correct me if I'm wrong, but the way FDE is implemented in Librem 5 means that it is only effective when the phone is turned off? The disk is decrypted when you type in your LUKS passphrase and after that, it stays decrypted until you completely power it off or reboot. That makes it pretty much useless on a phone that you carry around. The linked source has a lot of stuff that is done "in the future" and basically al…

Yes, desktop GNU/Linux has a long way to go to get to the security model of Android. Yes, FDE only works for the turned off device (at the current stage). But, depending on your threat model, the phone can already be more secure nevertheless.

For example, if you do not trust the manufacturers in China, you can verify the schematics, or order Librem 5 USA. Or, if you suspect your device is compromised, you can rely on the kill switches to make sure you are not tracked or listened to. Can you do these on Android? I'm sure there are known vulnerabilities for the latter on the black market.

Another example: If you use the smart card to read or sign your emails, you can be sure that even a hacked or stolen unlocked phone would not allow the attackers to manage your email identity.

People who say that Librem 5 is less secure than Android do not take into consideration that threat models can affect it a lot. You cannot simply declare "it's insecure" without considering the threat models. Also, I guess if you are fine with the security of your GNU/Linux laptop, which you take with you, you should be also more or less fine with the Librem 5 security.

I am not even speaking about the freedom benefits. Also, there is no security and privacy without freedom (https://puri.sm/posts/why-freedom-is-essential-to-security-a...). In the long term, Google is heading toward the walled garden on Android, just like Apple does. I would not bet on it for the future. If you care about security more than freedom and need Android-style security now, then Librem 5 is not for you.

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#149

Earlier quoted context omitted.

No paid apps though, right? That would be somewhat painful for me.

You can do paid apps. You just have to login to Aurora using a Google account instead of anonymously. This isn't so bad if you use a privacy focused ROM and create a special, single purpose Google login that is only used for app purchases. I also suggest keeping a Google gift card for the occasional purchase. Privacy invasion doesn't really kick in until you start re-using your Google login and your phone/apps are re…

Ah, with paid apps I also mean in-app purchases. I guess it might be possible by running sandboxed Play Services on GrapheneOS?

Re: Android launches yet another way to spy on users with “Privacy Sandbox” beta

#150
post #71

Earlier quoted context omitted.

I run Lineage Even without GApps, Lineage still includes links to Google. e/OS had a list of some of these at one time. They remove these links and include MicroG in the default install. Others may disagree but in my opinion, it is a pretty good compromise between security, privacy and usability.

I think the links are very few, the main one being captive portal detection for wifi logins. In exchange for this, Lineage delivers the monthly security patches first, mostly guaranteed to be in place by the 15th of every month (load the first nightly published after that date, and it will be bundled).

...and that captive portal link can be replaced by the user if so desired (which it is by me, I don't see why Google needs to know when I try to connect to any network):

   settings put global captive_portal_http_url http://captive.example.org/generate_204
   settings put global captive_portal_https_url https://captive.example.org/generate_204
   settings put global captive_portal_fallback_url http://another.example.org/generate_204
Or, for Android
   settings put global captive_portal_server captive.example.org
No Google, no cry. Of course you need to replace those domains with some of your own choice, I use my own server with a bit of nginx configuration to provide this functionality:

   server {
     listen 80;
     listen [::]:80 ipv6only=on;
   
     server_name captive.example.org;
   
     # Apple CNA
     location /hotspot-detect.html {
       return 200 'SuccessSuccess';
       add_header Content-Type text/html;
     }
   
     # Apple CNA
     location /library/test/success.html {
       return 200 'SuccessSuccess';
       add_header Content-Type text/html;
     }
   
     # ChromeOS, Android
     location /generate_204 {
       return 204;
     }
   
     # Windows
     location /ncsi.txt {
       return 200 'Microsoft NCSI';
     }
   
     location / {
       return 302 http://www.example.org/;
     }
   }
Post reply on HN