Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

241–250 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#241
post #177

Earlier quoted context omitted.

>One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. >As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. Fortunately this is changing with iOS 18 with "limited contacts" sharing. https://mobiledevmemo.com/wp-cont…

People will share their whole list because it’s simpler

Or because they were tricked. eg. LinkedIn’s “Connect with your contacts” onboarding step which sounds like it’ll check your contacts against existing LinkedIn users but actually spam invites anyone on your contact list that doesn’t have an account.

Re: Everyone knows your location: tracking myself down through in-app ads

#242

Earlier quoted context omitted.

Those aren't questions that have fixed answers. The data available is pretty far beyond what I'm personally comfortable with though. One OEM I'm familiar with had such a policy. My org determined that we needed a statistical reference to compare against within a certain area. Some calls were made to the right people and shortly after we had a (mildly) anonymized map of high precision tracks for every vehicle of that…

That’s pretty interesting. What was the purpose of the statistical sample? What did your company want to know precisely?

I’m assuming insurance or commercial trucking? Or both?

Re: Everyone knows your location: tracking myself down through in-app ads

#243
post #133

I'm a very happy paying customer of NextDNS ( https://nextdns.io ) which blocks known adware and tracking hosts across all mobile and desktop platforms.

Which does absolutely nothing if your device or the app in question is permitted or otherwise not prevented from making DNS-over-HTTPS (or, less commonly because of its discrete port, DNS-over-TLS) queries.

Don't all the ad-blocking DNS providers also support DNS-over-HTTPS now as well? I use it with AdGuard Home, and I saw PiHole supports it as well.

Re: Everyone knows your location: tracking myself down through in-app ads

#245
post #223
post #206

Earlier quoted context omitted.

I think it's not properly appreciated that Apple fully endorses all of this. For two reasons: (1) the provision of the output of billions of dollars of developer time to their users for no up front cost (made back via ads) is super valuable to their platform; and (2) they uniquely could stop this (at the price of devastating their app store), but choose not to. In light of that, perhaps reevaluate their ATT efforts a…

>I think it's not properly appreciated that Apple fully endorses all of this. [...] they uniquely could stop this (at the price of devastating their app store), but choose not to. A perfectly privacy respecting app store isn't going to do any good if it doesn't have any apps. Just look at f-droid. Most (all?) of the apps there might be privacy respecting, but good luck getting any of the popular apps (eg. facebook, t…

> good luck getting any of the popular apps (eg. facebook, tiktok, google maps) on there

That makes sense, considering they’re not privacy respecting.

Re: Everyone knows your location: tracking myself down through in-app ads

#246

Earlier quoted context omitted.

Which does absolutely nothing if your device or the app in question is permitted or otherwise not prevented from making DNS-over-HTTPS (or, less commonly because of its discrete port, DNS-over-TLS) queries.

Don't all the ad-blocking DNS providers also support DNS-over-HTTPS now as well? I use it with AdGuard Home, and I saw PiHole supports it as well.

I'm referring to devices and apps that are 'hard-coded' to query specific DoH servers/providers, therefore bypassing and regardless of any user-configured DNS server/s. And because DoH operates on outbound TCP/443, the lookups are indistinguishable from any other 'web' traffic.

Even some of the most popular desktop web browsers are configured to utilize DoH by default nowadays.

The most that a network administrator can do to prevent this is configure firewall IP blocklists of known DoH servers and NAT all outbound 53 (and 853) traffic to a desired resolver (like a local Pi-hole instance, for example).

Re: Everyone knows your location: tracking myself down through in-app ads

#248

Earlier quoted context omitted.

Honestly, kudos. The rules should apply to the ones foisting this system upon us as well. This is probably the only way to make anyone in power reconsider current setup. And people laughed at Red Reddington when he said he had no email.

Exactly this was tried by the likes of James Oliver and journalists/comedians of that caliber running ads and gathering data from politicians in Washington. It was some years ago and resulted in nothing

Do you mean John Oliver?

Re: Everyone knows your location: tracking myself down through in-app ads

#250

One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. And I buy this stuff. Every time I need customer service and I'm getting stonewalled I just go onto a marketp…

> find an exec and buy their details for pennies and call them up on their cellphone

There is a vendor for this very thing in relation to business and government position called “zoominfo”

Post reply on HN