Earlier quoted context omitted.
Have you ever logged into messages.google.com?
No, never. HN is pretty much the only social media I use, the rest of it is not really my thing.
What happens when your phone is spying on you
101–110 of 169 posts
Re: What happens when your phone is spying on you
#102Earlier quoted context omitted.
Most privacy advocates probably do plenty of things I would be perfectly happy to see made illegal, but we don't just ban them because we don't want a complete dictatorship of one segment of the population over everyone else, and because it seems the people realize it would cause problems for some people, and we need to be careful to find suitable replacements before we ban things. A lot of the tech I imagine you are…
Most privacy advocates I know revolve around the concept of "informed consent". The idea isn't to ban technologies because they can be abused, it's to stop the abuse. The guiding principle for when that line is crossed is whether or not the affected person was completely and accurately informed about what is going to happen, and that they have affirmatively given their consent for it to happen.
Re: What happens when your phone is spying on you
#103Earlier quoted context omitted.
Weird. The small places here (I'm thinking chinese take-out, for example) take cash only, order tickets are on paper, they don't deliver, and seem to be thriving. Have the Uber Eats and other tech middlemen started taking such a big slice of the profit that it's not worth it? Having worked in a restaurant, if someone took 30% of my gross it certainly would have been all of my profit and then some.
I just said the opposite. Restaurants apps do not pay 30% even when going through the App Store. It’s a physical good and even if they do accept Apple Pay, they get charged standard credit card processing fees - $0.25 + 2-3% of the amount. I said they do not use GrubHub. They have their own system run as SaaS. The company they use takes care of the POS system, merchant accounts, and a white labeled app just for their…
Does the SaaS/POS company let customers use one app and "install/subscribe" to each restaurant as needed?
Re: What happens when your phone is spying on you
#104Earlier quoted context omitted.
Is it because the phone is very intimate to you, or because of the implications?
because they could be viewing all their private communication/media on their device and that causes a lot of anxiety cause they won't confirm or deny if they have access.
Re: What happens when your phone is spying on you
#105Earlier quoted context omitted.
Yeah, I sort of feel that way too but maybe also is a good lesson learned.
What’s the lesson here? That software is insecure? Or that you shouldn’t trust your friends? Sad.
Re: What happens when your phone is spying on you
#106Earlier quoted context omitted.
No, never. HN is pretty much the only social media I use, the rest of it is not really my thing.
Maybe this isn’t what happened. But I was specifically referring to the ability to pair a computer with your Android device to send/receive messages without your phone: https://messages.google.com/web/authentication It’s actually quite handy.
Re: What happens when your phone is spying on you
#107Earlier quoted context omitted.
Most privacy advocates I know revolve around the concept of "informed consent". The idea isn't to ban technologies because they can be abused, it's to stop the abuse. The guiding principle for when that line is crossed is whether or not the affected person was completely and accurately informed about what is going to happen, and that they have affirmatively given their consent for it to happen.
The GDPR goes a little farther than that though, because it makes consent revokable even after the fact, and disallows consent as a requirement to access a service, and some privacy advocates seem to think that's still not enough.
> some privacy advocates seem to think that's still not enough.
I am one of them. I think the GDPR is inadequate in many ways, but it's certainly a huge improvement over the nothing that existed prior, and it's much better than anything we have here in the US.
But the things I think are inadequate about the GDPR still revolve around consent. I will admit that "consent" is a very broad term, though, and includes a whole lot of intricacies and nuances. It's a bit like "freedom" in that sense.
Re: What happens when your phone is spying on you
#108A week ago I purchased a bluetooth device that takes some measurements. You require an Android or iOS application. The first thing the iOS app did was request permission for your location. Immediate fired up MITMproxy [1] running in transparent `--mode wireguard` and installed it's certificate in the iOS trust store. It was sending a whole bunch of data to China and HK. Since I don't have a jailbroken iPhone, it's off to Android.
For BLE scanning, Android does require permissions for location, but this application is using a Chinese branded tracking SDK and sending encrypted blobs (within already encrypted TLS). So it's time to start reversing and instrumenting the runtime.
Well - not so easy, they used a commercial packer that encrypts their compiled bytecode and decrypts and I think executes it within C++ library that might be an actual interpreter. I managed to pull the Dalvik bytecode out of memory using Frida[2] after the packer had decrypted the base application and converted it to java bytecode with dex2jar[3] then into decompiled java with jadx [4].
Since the developer relied on the packer to hide/obfuscate their software, it's quite easy to follow the deobsfucated code. The libraries that do the location tracking on the otherhand are obfuscated so now I'm at the stage of identifying where to hook before the encrypted blobs are sent to servers in China.
Here it would be nice to have a call flow graph generated based on the static decompiled java code - can anyone recommend anything?
I've sunk about 8 hours into this so far. The message here is that to understand what some applications on your phone does you need to really invest time and effort. The developers increase the cost to the consumer to know what their application is doing by obfuscation, encryption and packing. It's asymmetric. Also note: the play store and apple store state the app does not send data, which is demonstrably false.
I can also see that the tracking SDK has what looks like functionality to dynamically invoke code - which would break the terms and conditions of the app stores.
At some point I will reimplement it's primary BLE functionality and release it as opensource to the public and perhaps write a blog post.
[1] https://mitmproxy.org/posts/wireguard-mode/
[2] https://frida.re/docs/android/
Re: What happens when your phone is spying on you
#109Earlier quoted context omitted.
I have a Galaxy S21 5G with Android 13 I also changed my pin because I suspect he saw me entering it, but when this occurred he was at the other end of town so it would have had to have been some sort of remote access. I am thinking maybe phone link, which I had been using with my laptop, I disabled that. It was definitely not autocomplete because he said something that only he would have know regarding the message I…
You should not buy him anything. You should cut him out of your life entirely. This is an egregious trust violation. I’d forgive a teenager of such thoughtlessness but if they’re an adult then they’re going to abuse you in other ways. They don’t care about you.
Re: What happens when your phone is spying on you
#110Earlier quoted context omitted.
Flip phones are available. SBF has been issued with one under his latest conditions of release. Remember though, privacy comes at a cost. Thousands of parasitic "startups" that live off of VC, produce nothing for sale, have no profits and rely on surveillance to demonstrate speculative "value" might suffer or even "go out of business", "Big Tech" might not rake in billions per quarter for selling ad services, "tech j…
Your quoting of certain words seem odd. https://prestersperspective.blogspot.com/p/schizophrenia-ran...