Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

231–240 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#231

Earlier quoted context omitted.

What marketplaces do you use?

Im also curious about this. Is it just a website you place an order or do you have to go through some kind of agent?

If you're US based, there's tons of data broker sites, and you can glue together the information for free as various brokers leak various bits (E.g. Some leak the address, others leak emails, others leak phone numbers). And that's by design for SEO reasons, they want you to be able to google someone with the information you have, so they can sell you the information you don't have.

Some straight up list it all, and instead of selling people's information to other people, they sell removals to the informations owner. Presumably this is a loop hole to whatever legislation made most sites have a "Do Not Sell My Info" opt out.

What you do is look up a data broker opt out guide, and that gives you a handy list of data brokers to search. E.g.

https://inteltechniques.com/workbook.html

Re: Everyone knows your location: tracking myself down through in-app ads

#232

One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. And I buy this stuff. Every time I need customer service and I'm getting stonewalled I just go onto a marketp…

The thing is...contact details aren't really private information, basically by definition.

The distinction is contact details privacy is based on the desire not be interrupted by people you didn't agree to be interrupted by - i.e. it's a spam problem - and realistically to solve this requires a total revamp of our communications systems (long overdue).

The basic level of this would be forcing businesses to positively identify themselves to contact people - i.e. we need TLS certificates on voice calls, tied to government issued business identifiers. That would have the highest immediate impact, because we could retrain people not to talk to anyone claiming to be a business if there phone doesn't show a certificate - we already teach this for email, so the skill is becoming more widespread.

A more advanced version of this might be to get rid of the notion of fixed phone numbers entirely: i.e. sharing contacts is now just a cryptographic key exchange where I sign their public certificate which the cellphone infrastructure validates to agree to route a call to my device from their device (with some provisioning for chain of trust so a corporate entity can sign legally recognized bodies, but not say, transfer details around).

This would solve a pile of problems, including just business decommissioning - i.e. once a company shuts down, even if you scraped their database you wouldn't be able to use any of the contact information unless you had the hardware call origination gear + the telecom company still recognized the key.

Add an escrow system on top of this so "phone numbers" can still work - i.e. you can get a random number to give to people that will do a "trust on first use" thing, or "trust till revoked" thing (i.e. no one needs to give a fake number anymore, convention would be they're all fake numbers, but blocking the number would also not actually block anyone you still want to talk to).

EDIT: I've sort of inverted the technical vs practical details here I realize - i.e. if I were implementing this, the public marketing campaign would be "you can have as many phone numbers as you want" but your friends don't have to update if you change it. The UI ideally would be "block this contact and revoke this number?" on a phone which would be nice and unambiguous - possibly with a "send a new number to your friends?" option (in fact this could be 150 new numbers, one per friend since under the hood it would all be public key cryptography). I think people would understand this.

Re: Everyone knows your location: tracking myself down through in-app ads

#233

Earlier quoted context omitted.

True, while Google sees roughly 85% of all American cardholder swipes and doesn't need to sell it since they're making the ad market...

> while Google sees roughly 85% of all American cardholder swipe I'm probably not reading this properly, can you say that a different way?

For every 20 Americans with a credit card, 17 have all their purchases sent to Google.

Re: Everyone knows your location: tracking myself down through in-app ads

#235
post #42

May be Steve Jobs was right all along. We dont need Smartphone with App Store. Either 1st Party Apps and Everything else should be on Browser or Apps that uses Browser Engine.

Websites tend to have more ads and tracking than native apps, and they're still getting your ip address.

Re: Everyone knows your location: tracking myself down through in-app ads

#236
post #232

One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. And I buy this stuff. Every time I need customer service and I'm getting stonewalled I just go onto a marketp…

The thing is...contact details aren't really private information, basically by definition. The distinction is contact details privacy is based on the desire not be interrupted by people you didn't agree to be interrupted by - i.e. it's a spam problem - and realistically to solve this requires a total revamp of our communications systems (long overdue). The basic level of this would be forcing businesses to positively…

What definition of contact details makes them not private?

Contact details (your phone number, email or address) are definitively private information, you should be the one that decides who gets them and who doesn't.

Re: Everyone knows your location: tracking myself down through in-app ads

#237
I clicked the link at the beginning of your article, that led to the Google sheet with the list of apps. That list had 12,373 lines, not “over 2,000”, fyi. And while most of the apps looked like small time games that I have never downloaded and would probably not download, I saw included there “Microsoft Office 365”. Interesting.

Re: Everyone knows your location: tracking myself down through in-app ads

#238
post #225

Earlier quoted context omitted.

> Sounds like that'll push retailers to switch from a system where they give points/discounts to everyone, to one where points/discounts are "targeted", which of course requires opting into tracking. Like I said before, the whole premise of loyalty programs is that you're being tracked in exchange for rewards. You really can't expect to have your cake (discounts) and eat it too (not being tracked). As I said, in Germ…

>As I said, in Germany you can indeed have your cake and eat it too in this regard, if you’re okay with the offers you receive being less targeted and therefore less appealing. The "cake" in this case refers to the offers you had before GDPR came into effect and/or regulators started enforcing it. They might give opt-out people some token offers to appease regulators, but I doubt it'll be anywhere close to the offers…

> They might give opt-out people some token offers to appease regulators

It’s not an opt-out situation. As per GDPR requirements, these programs have a specific opt-in prompt for personalized targeting, separate from the one which is for generally collecting and redeeming points as a member, and it’s not pre-chosen by default.

I think one can assume that many people will decline to opt in, especially in a culturally privacy-focused country like modern Germany and since not opting in is far behaviorally common than explicitly opting out, but also that many others will knowingly consent in exchange for the benefits. So I think they would generally want to give decent offers to both categories of people, since the non-consent group is large enough to matter. Of course the personalized ones would be better, otherwise nobody would want to give that consent.

Myself, I’ve consented to some but not all of the personalized targeting and information sharing from the loyalty programs I participate in here, after reading the descriptions of the requested consents in detail and making a conscious choice. In at least one case I converted a no to a yes after thinking about it longer. It’s good to have that transparency and control, and not to have the legalese surreptitiously remove your right to sue the store should that become necessary as is common in the US (forced arbitration is generally illegal here in B2C agreements).

As for the rest of your most recent comment, I wouldn’t know; I didn’t ever live in Europe before the GDPR.

Re: Everyone knows your location: tracking myself down through in-app ads

#239
post #236
post #232

Earlier quoted context omitted.

The thing is...contact details aren't really private information, basically by definition. The distinction is contact details privacy is based on the desire not be interrupted by people you didn't agree to be interrupted by - i.e. it's a spam problem - and realistically to solve this requires a total revamp of our communications systems (long overdue). The basic level of this would be forcing businesses to positively…

What definition of contact details makes them not private? Contact details (your phone number, email or address) are definitively private information, you should be the one that decides who gets them and who doesn't.

Literally explained in the second paragraph there.

You can't have private information which is meant to also be shared widely. It is the distinction between Access and Authorization.

Re: Everyone knows your location: tracking myself down through in-app ads

#240

One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. And I buy this stuff. Every time I need customer service and I'm getting stonewalled I just go onto a marketp…

Honestly, kudos. The rules should apply to the ones foisting this system upon us as well. This is probably the only way to make anyone in power reconsider current setup. And people laughed at Red Reddington when he said he had no email.

Exactly this was tried by the likes of James Oliver and journalists/comedians of that caliber running ads and gathering data from politicians in Washington.

It was some years ago and resulted in nothing

Post reply on HN