Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

261–270 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#261
post #137
post #95

Earlier quoted context omitted.

Here is implementation documentation from Mastercard about l3: https://na-gateway.mastercard.com/api/documentation/integrat... The cost reduction is very small, it’s applied to interchange fees. I’ve been directly responsible for implementing this functionality on payment gateways for multiple processors because it helps reduce fraud holds as well.

Separate question, what are your ethics around the surveillance of Americans' economic activities by private actors? What "rights" are relevant in this space and which do you subscribe to? I'm not going to debate you about anything, I just don't get the chance to ask insiders any of these questions.

My ethics are “this is unequivocally wrong without consent”.

Thankfully my work was on payment products that serviced businesses and government entities, so I did not really have to deal with that moral quandary.

However it gets muddier in other spaces as well. There are types of cards, like HSA/FSA that require something similar to level 3 data called IIAS that is used to determine what parts of your purchase are eligible. In the parts of the systems I have worked with, this is covered by HIPAA, but I have no idea if there are “clever” methods to sneak that data out of the chain elsewhere.

Re: Everyone knows your location: tracking myself down through in-app ads

#262
post #239
post #236

Earlier quoted context omitted.

What definition of contact details makes them not private? Contact details (your phone number, email or address) are definitively private information, you should be the one that decides who gets them and who doesn't.

Literally explained in the second paragraph there. You can't have private information which is meant to also be shared widely. It is the distinction between Access and Authorization.

But it's not meant to be shared widely, for most people it's meant to be shared with consideration and/or permission.

Also, it's not just about "a desire not be interrupted by people you didn't agree to be interrupted by", it's about not having the data in the first place, for any reason, including tracking of any sorts.

Re: Everyone knows your location: tracking myself down through in-app ads

#263
I paid for pcapdroid, it's a network monitoring app that use the vpn protocol on Android to monitor every packet sent, register which app made the request, to whom, dates and so on.

In it's paid feature, you can select app to block internet connection or you can select country, ip and host.

After browsing my internet logs, it shocked me to see some app I had absolutely no idea were spying so much.

Xiaomi home ? Yeah I knew Xiaomi app would be spyware. But Spotify for instance, how could I guess it sends every few hours data to remote server including Facebook ones.

Until I find replacement for Spotify, but most music streaming app do spy on its user (and I don't mean just learning what music you like), I can still block all the graph.facebook.com tracking.eu.miui.com Google ads.gdoubleclick.net and so on.

It's open source but firewall is paid feature, i highly recommend it if you're on Android.

https://f-droid.org/fr/packages/com.emanuelef.remote_capture...

There is even the possibility to decrypt packet and analyze them although it require root, i did it on another phone and yeah it's similar to what the author found. Every single bit of data, ip adress, since how long the phone is on, the wifi connections, when did I unlock the phone and so on.

Every data taken individually is not important to me but this stream of little data constantly going God knows where is creepy as fuck.

Re: Everyone knows your location: tracking myself down through in-app ads

#264

Earlier quoted context omitted.

It’s honestly crazy that we allow companies to sell our data — and even financially incentivize companies to share our data like this.

The problem is that to you it seems like your data but to Walgreens they see it as theirs. They generated it with their point of sale system. The data is about a transaction that you made, but they generated all of it. Until we have agreement as a society about what “my data” means, this kind of stuff is going to run rampant.

>to you it seems like your data but to Walgreens they see it as theirs

the value of this data comes from what did I buy, what else do I buy, where am I, who I am, etc.

to your point, Walgreens does not sell to their competitor CVS data about what they sell, when, and where.

so if that really is their argument, it's refutable.

Re: Everyone knows your location: tracking myself down through in-app ads

#265
post #229

Earlier quoted context omitted.

Corporations are people, too.

Or phrased less inflammatory manner: "Corporations can enter into contracts and engage in legal action just like people can". Even the much maligned Citizens United v. FEC basically boils down to "groups of people (corporations or labor unions) don't lose first amendment protections just because they decided to group up".

Except not everyone in a corporation has the right to speech. I'm prohibited by my employer to say anything on the company's behalf, but the C-suite and board are able to speak on my behalf. So, the company's leadership has a right to free speech, I don't.

Re: Everyone knows your location: tracking myself down through in-app ads

#266

Earlier quoted context omitted.

It would be amazing if you could build and send fake profiles of this information to create fake browser fingerprints and help track the trackers. Similarly, creating a lot of random noise here may help hide the true signal, or at least make their job a lot harder.

Unfortunately fingerprinting prevention/resistance tactics become a readily identifiable signal unto themselves. I.e., the 'random noise' becomes fingerprintable if not widely utilized. Everyone would need to be generating the same 'random noise' for any such tactics to be truly effective.

That's why it should be the browsers & OS's that enforce such privacy measures... it shouldn't be an option that my Grandma needs to enable...

Re: Everyone knows your location: tracking myself down through in-app ads

#267
I think one thing people are discussing a lot here about Privacy around contacts and sharing. Limiting access to contacts , completely or partially, is the wrong way to design such systems. There are two problems with this approach:

1. Having permission to contacts is NOT a capability. Running a function on it that is by design not leak PII is infinitely more valuable and a capability.

2. Asking users to grant permission is broken by design: You are giving a very bad multiple choice to the user: `(a)Creepy? (b). LessCreepy (c). Don't Use App`

Instead if we only granted operation rights and hid the actual information instead it would be so much better. We need a separation of data from the function to empower apps to give better choices to users.

Re: Everyone knows your location: tracking myself down through in-app ads

#268
post #109

wow @apokryptein thanks for posting my article here... I'm shocked it's #1 rn. if anyone has any questions regarding the post - I'm here to answer & talk!

how the MAID/IDfV gets into the PII-ID databases?

It seems that part is completely missing. (Or I missed it.)

So for example can/do airlines sell it? Or telecom/utility companies, when you use their app?

Re: Everyone knows your location: tracking myself down through in-app ads

#269
I find it fascinating reading hacker news, full of IT folk who simultaneously build software that enables and profits from the advertising and personal information selling & tracking industry - are also the same people who complain the loudest about it. Unbelievable.

Re: Everyone knows your location: tracking myself down through in-app ads

#270
post #188

Earlier quoted context omitted.

Actually this could prove very useful for a resistance movement. Take them down with with their own medicine.

Yeah, I wonder if it might help to create a little newsletter for politicians and regulators. Send emails telling them exactly where they are, what apps they use, and so on. And send them the same information about their children.

I’m relatively sure they would bring the hammer down on the sender.
Post reply on HN