Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

351–360 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#351

Earlier quoted context omitted.

Yeah, I wonder if it might help to create a little newsletter for politicians and regulators. Send emails telling them exactly where they are, what apps they use, and so on. And send them the same information about their children.

They would make adjustments so that their details are protected, but the regular user is not.

Eh, California protects politicians from having their real estate holdings posted online by government, and afaik, most county recorders have decided it's easier to not let any of it be online than to figure out who is a politician and only restrict their information.

Of course, much of it is public information so businesses can go in person, get all the info and then list it.

Re: Everyone knows your location: tracking myself down through in-app ads

#352
post #345

Earlier quoted context omitted.

> (this is usually successful, but can backfire badly -- CashApp terminated my account for this shenanigans) When I was at a medium-sized consumer-facing company whose name you’d recognize if you’re in the tech space (intentionally vague) we had some customers try this. They’d find product managers or directors on LinkedIn then start trying to contact them with phone numbers found on the internet, personal email addr…

> So I can see why companies are quick to lock out customers who try these games. Most of the companies who customers try these "games" against are places like Google and Meta that literally do not provide a way for the average customer to reach a human. None. Those have got it coming for them, the megacorps' stance on this is despicable and far worse than the customers directly reaching execs who could instantly cha…

> but that's not generalizable.

You only referenced two companies...

Re: Everyone knows your location: tracking myself down through in-app ads

#353
post #127

I'm surprised people think they have any kind of privacy - especially when using free services. They are not free. You pay with whatever data can be extracted from your devices and behavior. Also, there's a looong list of companies who know the location of your mobile device, starting from the cell phone tower operator to Apple/Google and many in between.

True. But even paid apps have access to these data and can collect it without our knowledge. A genius called Stallman proposed solution decades ago. Free software aka. open source software. But outside of tech community, open source is not a known term. Maybe we should market it wherever possible, if we want true privacy and freedom.

Re: Everyone knows your location: tracking myself down through in-app ads

#354
post #253
post #177

Earlier quoted context omitted.

>One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. >As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. Fortunately this is changing with iOS 18 with "limited contacts" sharing. https://mobiledevmemo.com/wp-cont…

How about a no/limited internet setting? So many apps spy on you and they don’t need network at all to function.

Grapheneos lets you pick this for apps before they even launch. You can revoke their network access, as well as define storage scopes for apps at a folder level, so if an app needs access to photos, you can define a folder, and that is the only folder it can scan for photos.

I used that when submitting parental leave at work. I didn't want to provide full access to all my photos and files for work, so all they got was a folder with a pic of a birth certificate.

Re: Everyone knows your location: tracking myself down through in-app ads

#355
post #50

Earlier quoted context omitted.

The browser has less access to your system, and usually only if you give a specific website permission to use these features. Mobile operating systems are slowly changing that though.

Have you looked at the latest JS standards?

(and if you haven't... check out the APIs available to the developers/owners of all the websites you browse: https://developer.mozilla.org/en-US/docs/Web/API )

Re: Everyone knows your location: tracking myself down through in-app ads

#356
post #6

There are quite a few interesting tracking flows out there. My rent is paid through a company called Bilt. I discovered that when I shop at Walgreens now, Bilt sends me an email containing the full receipt of what I bought like so: > Hey [inahga], > > You shopped at Walgreens on 12/1/24 and earned Bilt Points with your > Neighborhood Pharmacy benefit. > > Items eligible for rewards > TOSTITOS HINT OF LIME RSTC 11OZ >…

I believe that's opt-in. At least it seemed to be when my landlord switched to Bilt. There's a section of your Bilt profile that shows your other credit cards and whether you want them linked. It's pretty freaky to see them listed in the first place. I definitely keep them off. Bilt is ultimately a big points/reward program though, so you might get points for having them connected. I still haven't figured out exactly…

It was initially opt in for me, then they made it mandatory.

(Sure, I could pay by check but consumer banking technology/US in the US already feels like is is lagging a decade behind other countries without voluntarily going further back. Paying by check every month would be quite inconvenient.)

I'd already decided to avoid bilt as much as possible, but reading this thread prompted me to try going a little further.

Looking through their privacy policy it talks about what California residents can do under CCPA: https://legal.biltrewards.com/policies

> Request to Know... The specific pieces of Personal Information we collected about you.

> You have the right to opt-out from having your Personal Information and Sensitive Personal Information sold to third parties. You also have the right to opt-out from having your Personal Information and Sensitive Personal Information shared with third parties for purposes of cross-contextual advertising

Might as well give this a go.

Re: Everyone knows your location: tracking myself down through in-app ads

#357
post #296

Earlier quoted context omitted.

>Fortunately this is changing with iOS 18 with "limited contacts" sharing. Its not. Apple still owns your stuff. There is no difference between Apple and other 3p retailers. Apple just wants more of your money.

>Its not. Apple still owns your stuff. There is no difference between Apple and other 3p retailers. That could be taken to mean anywhere between "Apple controls the software on your iPhone, therefore they control your contacts" and "Apple gives out your data like the data brokers mentioned in the OP". The former wouldn't be surprising at all, and most people would be happy with, and the latter would be scandalous if…

Why do you inherently trust Apple?

Remember, the big celebrity photo leak happened because of a vulnerability within Apple Software.

Re: Everyone knows your location: tracking myself down through in-app ads

#358

Earlier quoted context omitted.

How? Most of the services I use, from Walgreens to banks to retirement accounts, require a phone number either for 2FA or just to verify that you’re you when signing up. After changing my phone number this year and having to go through the rigamarole for each service, I decided never again.

Yeah, companies are not dumb, and they know when you have VoIP number vs a full account with an "accepted" company. I can kind of see why not allowing 2FA to a number that could be easier to loose, but that's weak argument. Of course they don't want someone from .ru to get a US number with all of the baggage that would entail

There are flaws to their methodology. For half the companies, to change your number from A to B, you first must verify a NONCE with A, then verify a NONCE with B. This just means you have to possess two phone numbers for a period of time — Weeks, or in reality, months — while you change the long list of services over to the new phone number.

There is a simpler/better way and that is to verify you have your email address before allowing you to do a NONCE with B.

Re: Everyone knows your location: tracking myself down through in-app ads

#359

Earlier quoted context omitted.

I'm referring to devices and apps that are 'hard-coded' to query specific DoH servers/providers, therefore bypassing and regardless of any user-configured DNS server/s. And because DoH operates on outbound TCP/443, the lookups are indistinguishable from any other 'web' traffic. Even some of the most popular desktop web browsers are configured to utilize DoH by default nowadays. The most that a network administrator c…

> The most that a network administrator can do to prevent this is configure firewall IP blocklists of known DoH servers ... A firewall (which must also host a resolver) can choose to block requests to IPs it hasn't resolved domain names for. This is something I implemented for an Android firewall app I co-develop; it works nicely enough.

  A firewall (which must also host a resolver)
Is that true? Per what spec are you referring to?

Re: Everyone knows your location: tracking myself down through in-app ads

#360
post #343

Earlier quoted context omitted.

Such "go away" screens are in violation of Apple's AppStore rules. You cannot make a permission a condition of using the app, and stop the user from using it if they don't grant that permission. The app should gracefully do as much as it possibly can without the permission.

This holds for every app and every permission? Because I'm quite sure I recently used an app that closed for not allowing a permission. May be misremembering..

5.1.1 (iv) Access: Apps must respect the user’s permission settings and not attempt to manipulate, trick, or force people to consent to unnecessary data access. For example, apps that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos. Where possible, provide alternative solutions for users who don’t grant consent. For example, if a user declines to share Location, offer the ability to manually enter an address.

https://developer.apple.com/app-store/review/guidelines/

This wording is actually a lot weaker than I remember it back when I wrote iOS apps. The developer also was not allowed to exit the app or close it against the user’s intent, however I can’t find that rule anymore.

Post reply on HN