Live data from Hacker News

Everyone knows your location: tracking myself down through in-app ads

timsh.org

501–510 of 628 posts

Re: Everyone knows your location: tracking myself down through in-app ads

#501
post #484

Earlier quoted context omitted.

Pretty much all companies are doing the privacy violations. You think your doctors office doesn't sell their contact list?

In my country (and I suspect most Western Countries) my doctor would lose his medical licence for selling my contact information.

Your poor oppressed doctor! And I’ll bet they rarely even get to treat bullet wounds. It’s different here in the Land of the Free ™.

Re: Everyone knows your location: tracking myself down through in-app ads

#502

One big privacy issue is that there is no sane way to protect your contact details from being sold, regardless of what you do. As soon as your cousin clicks "Yes, I would like to share the entire contents of my contacts with you" when they launch TikTok your name, phone number, email etc are all in the crowd. And I buy this stuff. Every time I need customer service and I'm getting stonewalled I just go onto a marketp…

I just block all unscheduled calls and calls from unknown numbers. If there isn't a calendar event and it isn't coming from a known family member or close friend, the call doesn't go through.

I also have multiple cell and virtual numbers and give different ones out to businesses, banks, friends, and family. Businesses that don't need to ship me stuff also get a different address than ones that do.

I don't register to vote anymore because they leak my residential info. When they can agree to stop leaking it, I will participate again.

Re: Everyone knows your location: tracking myself down through in-app ads

#504
post #410

Earlier quoted context omitted.

They were evil before. Previously they’d take your LinkedIn password and try using that to log in to your email account to grab your contacts.

Wasn't this also how some services would connect e.g. your bank accounts? They'd ask for your credentials and log into your bank to scrape its contents. And I kinda get it, some services external to your bank can help you manage your finances etc. But it's why banks should offer APIs where the user can set limited and timed access to these services. In Europe this is PSD2 (Revised Payment Services Directive).

I think the key point is that they would take your Linkedin password and try to use that on your email without asking you, in case you reused passwords.

Re: Everyone knows your location: tracking myself down through in-app ads

#505

Earlier quoted context omitted.

I stopped keeping a mobile number many years ago. Phone is wifi only. In particular, I do not use the contacts functionality built into the phone. (This is /e/OS, which helps, but I'll be moving to Mobian as soon as it is viable.)

How do you do online banking?

Given the rampant privacy abuse on phones, I use a laptop.

Re: Everyone knows your location: tracking myself down through in-app ads

#506

Very interesting and disturbing research, definitely a wake up call for me. Does anyone know/can anyone recommend me software that can block these sorts of requests from going through? I know of pihole which blocks adds but does it also filter out these sorts of things?

"no-root firewalls" to control data flows on devices (sorry for not publicly naming my preferred one).

Re: Everyone knows your location: tracking myself down through in-app ads

#507

Earlier quoted context omitted.

I stopped keeping a mobile number many years ago. Phone is wifi only. In particular, I do not use the contacts functionality built into the phone. (This is /e/OS, which helps, but I'll be moving to Mobian as soon as it is viable.)

What do you do when the car repairman wants to call/text you when the car is finished? Or any other similar situations?

I use VOIP numbers for that. One per business.

Re: Everyone knows your location: tracking myself down through in-app ads

#508

I find it fascinating reading hacker news, full of IT folk who simultaneously build software that enables and profits from the advertising and personal information selling & tracking industry - are also the same people who complain the loudest about it. Unbelievable.

Brother, I work on internal software at a non-tech company and have never generated a single revenue.

Re: Everyone knows your location: tracking myself down through in-app ads

#509
post #403

> Advertising Tracking ID was actually set to 000000-0000... because I "Asked app not to track". > I checked this by manually disabling and enabling tracking option for the Stack app and comparing requests in both cases. > And that's the only difference between allowing and disallowing tracking This is revealing! I'd wondered about Apple's curious wording " Ask App not to track" leaves suspicious wriggle room - apps…

Apple sets Advertising Tracking ID to 00000-0000 because it's the only technical control they have. However, apps are also supposed to respect the signal with regards to other methods of cross-site/app tracking and disable fingerprinting mechanisms. See https://developer.apple.com/app-store/user-privacy-and-data-... for details

It's not the only technical control they have - every single datapoint an app can gather is ultimately provided from the OS. They could let you disable access to metrics that have proven to be useful for fingerprinting. They could also attempt block known tracking code - all games with IronSource ads will run the same tracker binary, byte for byte. There's a lot of things they could do, but don't, since in the mainstream they have a pretty good reputation when it comes to privacy.

Re: Everyone knows your location: tracking myself down through in-app ads

#510
post #444

Earlier quoted context omitted.

There’s no code of conduct or rule book that anyone should follow so ethics is determined at the individual level. That quickly turns to, either I build it for them or the next guy will. Resistance is futile type thing. Most other types of engineering have published rules and standards and industry credentialing including ethics tied into it and loss of credentials for an ethics violation would be career ending in ma…

Can you give a few examples where that helped? (I can only think of straw-man examples. Does the private prison industry have problems getting architects, civil engineers, electrical engineers? Does the pharma industry have problems getting chemical engineers for manufacturing addictive painkillers?)

Architects have to build to codes and have their plans signed off by an engineer that is very much liable for the basic safety of the structure.

I’m a CFO and the CPA credential helps a whole industry of accountants avoid outright shenanigans that would take place if we could report financials the way sales, marketing and some others would prefer. We also have a whole layer of audits to help make sure what we say is true, is true.

It’s obviously not perfect and There’s always going to be bad actors but having industry guardrails does help a lot more than is obvious. This is one of those things we’re the absence of data is the data. The fact it’s pretty rare for a skyscraper to structurally fail and Enron type financial fraud situations are relatively rare. It’s hard to imagine how much things around us would be worse without checks and balances.

As for pharma example, I think it’s a good point but also a bit of a case study in where this should have worked but didn’t. Those sometimes are necessary things. Just like how originally technologists thought social media was beneficial to society, it could perhaps be revisited with a different opinion with a different perspective with benefit of hindsight. It’s pretty subjective and opinionated but I personally think R&D should be pretty loose. In pharma, you have to be pretty open minded as it seems sometimes things are discovered while in search of something else. The business of pharma, the sales people pushing those addictive pain meds, should be able to push them (with an expectation of presenting accurate data of research/side effects/etc). Prescribing physicians are ultimately the best check. Even when lied to about addiction stats, they didn’t seem to perform the appropriate check/balance as their profession would normally have done and sound alarms / stop prescribing. Instead, as a whole, they leaned into the idea that pain should be more aggressively managed than it has been in the past. They were all very slow to act even when addiction had been identified as a problem. The confluence of all these things has caused the industry to become introspective and change some things in hopes to avoid a similar repeat. Just like Enron did for finance and household accident data drives improving building guidelines. Software remains the Wild West without something similar in place.

To circle back to the CPA example as that’s what I’m most familiar with, it doesn’t tell me not to work in a particular industry. Like, private prisons need accountants. But it tells me what type of accounting practices are acceptable. I’d imagine a similar example for the context of this topic, is you wouldn’t be told not to work for an adtech company but in that employment you would be able to say certain types of data sharing is decidedly inappropriate according to your industry standards and you would be putting your career in jeopardy by building a feature sales requested. Furthermore you have things like whistleblowing hotlines and eventually other companies that couldn’t work with your adtech company because doing so would be considered an ethics violation on their part. Etc etc.

Post reply on HN