Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

371–380 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#371
post #296

Earlier quoted context omitted.

>Its not. Apple still owns your stuff. There is no difference between Apple and other 3p retailers. That could be taken to mean anywhere between "Apple controls the software on your iPhone, therefore they control your contacts" and "Apple gives out your data like the data brokers mentioned in the OP". The former wouldn't be surprising at all, and most people would be happy with, and the latter would be scandalous if…

Why do you inherently trust Apple? Remember, the big celebrity photo leak happened because of a vulnerability within Apple Software.

The "vulnerability" part doesn't seem to be substantiated. From wikipedia:

>The images were initially believed to have been obtained via a breach of Apple's cloud services suite iCloud,[1][2] or a security issue in the iCloud API which allowed them to make unlimited attempts at guessing victims' passwords.[3][4] Apple claimed in a press release that access was gained via spear phishing attacks.[5][6]

Regardless of their security practices, it's a stretch to equate getting hacked with knowingly making available data. Moreover you can opt out of icloud backup, unlike with whatever is happening with apps mentioned in the OP.

Re: Everyone knows your location: tracking myself down through in-app ads

#372

Earlier quoted context omitted.

The problem is that to you it seems like your data but to Walgreens they see it as theirs. They generated it with their point of sale system. The data is about a transaction that you made, but they generated all of it. Until we have agreement as a society about what “my data” means, this kind of stuff is going to run rampant.

>what “my data” means It makes me wonder, if everyone 'owned' their own data, I wonder if it could be used as a form of UBI. Everyone has data from using services, everyone owns it, everyone can sell it to make a living just doing whatever they are doing everyday. This is only just a shower thought I had the other day though, there are probably many pitfalls when it comes to such an idea.

Connecting information to that kind of personal gains sounds dangerous. There is probably non-negligible abuse potential, like college kids legally printing money at weird scale.

Re: Everyone knows your location: tracking myself down through in-app ads

#373
post #352
post #345

Earlier quoted context omitted.

> So I can see why companies are quick to lock out customers who try these games. Most of the companies who customers try these "games" against are places like Google and Meta that literally do not provide a way for the average customer to reach a human. None. Those have got it coming for them, the megacorps' stance on this is despicable and far worse than the customers directly reaching execs who could instantly cha…

> but that's not generalizable. You only referenced two companies...

Two companies that are so gigantic they combine to a great percentage of number of "company interactions" the average Westerner has on a daily basis.

Anyway, I don't think it contradicts my point? Your company exist, mom and pops exist and there's a whole spectrum between them, so it's not generalizable.

Re: Everyone knows your location: tracking myself down through in-app ads

#374
post #343

Earlier quoted context omitted.

This holds for every app and every permission? Because I'm quite sure I recently used an app that closed for not allowing a permission. May be misremembering..

5.1.1 (iv) Access: Apps must respect the user’s permission settings and not attempt to manipulate, trick, or force people to consent to unnecessary data access. For example, apps that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos. Where possible, provide alternative solutions for users who don’t grant consent. For example, if a…

Yeah, "unnecessary" is the word that may as well render the whole section moot unless it's actually properly enforced. If I can remember I'll test it today and see how it goes.

Re: Everyone knows your location: tracking myself down through in-app ads

#375
post #123

I wonder: to which extent are purchased/brokered app real-time location data feeds used by various intelligence services to target missile strikes in war zones? In e.g. Ukraine/Russia.

https://taskandpurpose.com/news/russia-ukraine-cell-phones-t...

Not riding off ad geolocation but hijacking a UA app: https://www.crowdstrike.com/wp-content/brochures/FancyBearTr...

Re: Everyone knows your location: tracking myself down through in-app ads

#378
post #343

Earlier quoted context omitted.

This holds for every app and every permission? Because I'm quite sure I recently used an app that closed for not allowing a permission. May be misremembering..

5.1.1 (iv) Access: Apps must respect the user’s permission settings and not attempt to manipulate, trick, or force people to consent to unnecessary data access. For example, apps that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos. Where possible, provide alternative solutions for users who don’t grant consent. For example, if a…

I agree with these guidelines (although they could be improved), although I think that some things could be done by the implementation in the system, too.

> For example, if a user declines to share Location, offer the ability to manually enter an address.

This is a reasonable ability, but I think that the operating system should handle it anyways. When it asks for permission for your location, in addition to "allow" and "deny", you can select "manually enter location" and "custom" (the "custom" option would allow the user to specify their own program for handling access to that specific permission (or to simulate error conditions such as no signal); possibly the setting menu can have an option for "show advanced options" before "custom" will be displayed, if you think it would otherwise make it too complicated).

> that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos

This is reasonable, that apps should not be allowed to require microphone access for such a thing.

However, sometimes a warning message makes sense but then to allow it anyways even if permission is not granted; e.g. for a video recording program, it might display a message about "Warning: microphone permission is not allowed for this app; if you proceed without enabling the microphone permission, the audio will not be recorded." Something similar would also apply if you denied camera permission but allowed microphone permission; in that case, only audio will be recorded. It might refuse to work if both permissions are denied, though.

Re: Everyone knows your location: tracking myself down through in-app ads

#379
post #350

Earlier quoted context omitted.

Honestly, kudos. The rules should apply to the ones foisting this system upon us as well. This is probably the only way to make anyone in power reconsider current setup. And people laughed at Red Reddington when he said he had no email.

It's odd that of the two replies referencing people, both got their names obviously wrong. Is that a new phishing tactic?

New AI tactic.

Re: Everyone knows your location: tracking myself down through in-app ads

#380

I'm really happy to see this level of detail and research. So many privacy-related articles either wholly lack in technical skill, or hysterically cannot differentiate between different levels of privacy concerns and risks. People commonly point to Mozilla's research regarding vehicle's privacy policies. ( https://foundation.mozilla.org/en/blog/privacy-nightmare-on-... ) But that research only states what the car com…

> Lastly, does your insurance shoot up if you have a car without one of these systems? This question I can answer with a reasonable degree of certainty; no, it does not. Insurance companies increase rates for automobile coverage for many reasons, real or illusionary. But "does your insurance shoot up" strictly for not having a recording device in a vehicle is not one of them. Do some insurance companies charge less w…

> Do some insurance companies charge less when provided access to policy owner driving patterns which the companies infer reduce their risk? Sure.

> But that is a different question.

In what way? A discount for allowing surveillance is identical to an extra charge for disallowing it. They're identical, unless the "base" rate is set externally somehow.

$5 for lemonade, $3 off if you skip the lemon == $2 for sugar water, $3 extra to add lemon.

Post reply on HN