Live data from Hacker News

Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

eff.org

31–40 of 207 posts

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#33
post #14

If you have root you can still enable it with market apps.[0][1] However something like this needs to be integrated tightly like iOS and apps need to be aware they may not receive requested permissions. I still use App Ops in Kit Kat and it silently breaks apps all the time. Apps expect to be able request information (e.g. contact details) and crash or stall when they can't. In that respect, LBE Privacy Guard[2] was…

xprivacy does the same thing, and seems to be actively developed. The only problem is that it has an atrocious UX, but again, that seems to be on par for most android utils.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#34
post #19

The original intention (as explained by Dianne Hackborn among others) is that if the user sees the app requesting too many capabilities... the user should simply choose not to install the app. Having the user needing to understand all the different capabilities is too much. Having a bunch of pop-ups ( cough Vista) is also bad UI design. The current set of capabilities is too technical for end users to really understa…

> Have a single fake IMEI number, for example.

How would that work in countries where modifying the IMEI is illegal?

UK law (note prison sentence) http://www.legislation.gov.uk/ukpga/2002/31/section/1

I don't know if this is current US law or not. Here's one example http://thomas.loc.gov/cgi-bin/query/z?c112:S.3186.IS:

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#35

I'm probably going to turn in to that old guy with tin foil who can't play any games because nobody supports his choice of platform, but I really miss when computers were devices you could buy and then put your choice of OS on. Phones are pretty much just little ARM computers, why the hell don't I just install Ubuntu, Firefox OS, Android, WinPhone, Symbian, whatever? I could format a microSD card to boot from and go…

Why not? I installed Ubuntu the other day, it was trivial. Plus, there's a multitude of custom ROMs.

Yeah, but what you would call trivial might be insurmountable for lots of people. Cyanogenmod already has a lot of the privacy features missing in Android, but dicking around with clockworkmod recovery, etc. is pretty daunting.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#36
post #28

Earlier quoted context omitted.

They never had that ability (besides making their tweets private, but that's not what blocking is). Blocked users can just log out or log in under an alternate account in order to view the person's tweets.

You just used the term "making their tweets private". If we can't agree this constitutes a privacy feature - however small in scope - I think we'll just have to agree to disagree. :)

Huh? Using a phrase out of context doesn't mean you can insert it into his argument. He explicitly said, pretty much, "it's not about making their tweets private". Blocking wasn't a privacy feature.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#37

Earlier quoted context omitted.

Why not? I installed Ubuntu the other day, it was trivial. Plus, there's a multitude of custom ROMs.

Yeah, but what you would call trivial might be insurmountable for lots of people. Cyanogenmod already has a lot of the privacy features missing in Android, but dicking around with clockworkmod recovery, etc. is pretty daunting.

Fair point.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#38
post #34
post #19

The original intention (as explained by Dianne Hackborn among others) is that if the user sees the app requesting too many capabilities... the user should simply choose not to install the app. Having the user needing to understand all the different capabilities is too much. Having a bunch of pop-ups ( cough Vista) is also bad UI design. The current set of capabilities is too technical for end users to really understa…

> Have a single fake IMEI number, for example. How would that work in countries where modifying the IMEI is illegal? UK law (note prison sentence) http://www.legislation.gov.uk/ukpga/2002/31/section/1 I don't know if this is current US law or not. Here's one example http://thomas.loc.gov/cgi-bin/query/z?c112:S.3186.IS :

The suggestion was making a userspace call to retrieve the IMEI return a fake value, not modifying the IMEI itself. Perfectly legal, although I imagine a great legal battle could be fought over the interpretation of "interfere with the operation of".

I am, however, surprised that MAC spoofing is enough to get you a prison sentence if done on a "mobile wireless communications device".

EDIT: apparently as of a 2006 addendum in the "Violent Crime Reduction Act" even offering to do it for someone else will land you in the clink. Gotta keep those violent hackers off the streets I guess.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#39

I'm probably going to turn in to that old guy with tin foil who can't play any games because nobody supports his choice of platform, but I really miss when computers were devices you could buy and then put your choice of OS on. Phones are pretty much just little ARM computers, why the hell don't I just install Ubuntu, Firefox OS, Android, WinPhone, Symbian, whatever? I could format a microSD card to boot from and go…

Because while the ARM processor is probably supported, most of the other sensors, camera, cell radios, etc have proprietary binary drivers that are not.

Just read the problems Replicant, the true FOSS android, has had getting all components to work correctly.

Re: Google Removes Vital Privacy Feature From Android, Claims Release Was Accidental

#40
post #34
post #19

The original intention (as explained by Dianne Hackborn among others) is that if the user sees the app requesting too many capabilities... the user should simply choose not to install the app. Having the user needing to understand all the different capabilities is too much. Having a bunch of pop-ups ( cough Vista) is also bad UI design. The current set of capabilities is too technical for end users to really understa…

> Have a single fake IMEI number, for example. How would that work in countries where modifying the IMEI is illegal? UK law (note prison sentence) http://www.legislation.gov.uk/ukpga/2002/31/section/1 I don't know if this is current US law or not. Here's one example http://thomas.loc.gov/cgi-bin/query/z?c112:S.3186.IS :

That law seems particularly draconian. I assume it's an attempt to criminalise the changing of IMEIs on stolen phones? Reading that is slightly alarming, if only because I wouldn't have even considered that it could be illegal before today. I wonder how many other pieces of legislation I've naively violated?
Post reply on HN