Live data from Hacker News

More than 1k Android apps harvest data even after you deny permissions

cnet.com

101–110 of 146 posts

Re: More than 1k Android apps harvest data even after you deny permissions

#101
post #9

Earlier quoted context omitted.

According to Google Bluetooth requires location, because it van be used to find your location. So there is some reasoning behind this decisions, although I wwould be mutch happier with something like: Location (Bluetooth), location (GPS), location (WiFi) >A location permission is required because Bluetooth scans can be used to gather information about the location of the user. This information may come from the user'…

Please take a step back and look at this again. What is the cause and what is the effect here? Is Google's solution making it better or worse from a practical privacy point of view? (Also, don't buy Google's explanation that this is just to inform users of potential misuse - they actually log your location and even wait for a GPS lock when you pair a new device)

Why shouldn't I buy Google's explanation?

If an app that uses bluetooth can get my location via beacons or etc., then bluetooth should be wrapped in location privileges. An app that I do not want having my location should not be allowed to use bluetooth, and I have to accept that any app that does use bluetooth could get my location.

While it does mean that apps that use bluetooth now have a slightly easier way of getting location (i.e., via phone GPS, not just bluetooth), we shouldn't obfuscate that bluetooth is another way to get that information. In the end, you are trusting the app developer with the privilege of knowing your location. If you don't trust them with that, then they can't be allowed to use bluetooth, full stop.

Re: More than 1k Android apps harvest data even after you deny permissions

#102

Earlier quoted context omitted.

Ban. These. Apps. And. Devs. Permanently. It's hypocricy if they let these malicious devs keep publishing but keep harassing non-malicious developers with things like "How dare you have a Donate button in your app".

If the app can get around the permission system - it’s a vulnerability in Android itself that Google needs to correct.

To be fair, denying application knowledge of _device own_ MAC address is beyond absurd. If Google really wants that, they should buy their own MAC block, and regularly rotate the addresses within it when network is off.

A lot of Android own APIs (such as Wi-Fi P2P and Bluetooth) are built on implicit assumption, that application developer knows MAC address of device it is running on. Instead of fixing those APIs, Google now requires everyone using them to request Precise Location permission from user _and_ enable a Location Toggle in device settings. This is pure harassment.

Re: More than 1k Android apps harvest data even after you deny permissions

#103
post #21
post #10

Earlier quoted context omitted.

There's a paper linked from the article which contains details on the sidechannels: https://www.ftc.gov/system/files/documents/public_events/141... Example: if you have an SD card installed, one advertising SDK creates a file on it. When the SDK is running in an app with appropriate permissions, it writes the IMEI and advertising ID to that file. When it's running in an app without appropriate permissions, it retriev…

For this specific issue, I believe https://developer.android.com/preview/privacy/scoped-storage is the solution. Too bad many Android developers are opposing this feature (e.g. previous discussion: https://news.ycombinator.com/item?id=19521211 ).

Scoped storage does not prevent applications from sharing PII with each other. There are already advertising networks, using BroadcastReceivers and ContentProviders to share analytics data — it is simple and does not require individual apps to have external storage access.

Re: More than 1k Android apps harvest data even after you deny permissions

#104

Earlier quoted context omitted.

If Google's part of your threat model, it's probably time to ditch the Android phone entirely. No amount of permissions is really going to matter.

google should be part of everyone's threat model, but while we're forced to live with google and forced to hand over some data, it's best to limit what we send them voluntarily whenever we have any option.

Google and Apple are both part of my threat model. So I use an old dumbphone. It doesn't even text.

Re: More than 1k Android apps harvest data even after you deny permissions

#105

Earlier quoted context omitted.

Some might be using them without being aware of but the rest can be nicely permabanned.

How would you go about reliably and efficiently determining which category each falls into?

They aren't reliably determining violations of current absurd rules and people's apps get hit all the time for no good reason, so basically they could just continue doing what they've done so far.

Re: More than 1k Android apps harvest data even after you deny permissions

#107

Earlier quoted context omitted.

VPNService is an API ( https://developer.android.com/reference/android/net/VpnServi... ). Your own link points tp this documentation. It does not require sending your data to a VPN, and in this case, it obviously doesn't. The weird thing is that you went out of your way to research to find a misleading quote when the page itself points out why the quote is misleading and that the app is open source (negating your ads…

It has to route traffic through a local VPN to drop the traffic. Doesn't play well with other VPNs for this reason. Real firewalls need root. The VPN trick is a hack to get around that while still providing some of that functionality. Yes, you could edit the source code and compile it yourself every time it updates to remove the ads, but I think that's a little much to expect. Ultimately this is functionality users s…

> Doesn't play well with other VPNs for this reason. Real firewalls need root.

"Real firewalls" also don't play well with other VPNs. I don't see what functionality you think you're missing here.

> Yes, you could edit the source code and compile it yourself every time it updates to remove the ads, but I think that's a little much to expect.

Nobody's suggesting that. Just install another build (like the one I posted on F-droid) or any number of other apps that do the same thing.

> Ultimately this is functionality users should have access to by default

No OS comes with this functionality by default, only the APIs to implement it, exactly like Android.

Re: More than 1k Android apps harvest data even after you deny permissions

#108
post #38
post #32

Earlier quoted context omitted.

What exactly is the blame of Android? That it allows the app to read photos when user allows it to read photo files? Because this criminal behaviour is also present in Linux, Windows and macOS. Or the fact that an app can write a file to disk? And then another app can open the file? Also criminal behaviour present in other operating systems. Some users might even call it a feature and do the unthinkable - share files…

I expect my devices to uphold the security model they advertise. My desktop OS (macOS, for what it matters) doesn't ask me to approve permissions for apps, so I assume that anything I install has whatever privileges I have (or root privileges, given the broken must-install-as-root behaviour of many of them). On the other hand, for example, Firefox asks my permission before allowing sites to use the microphone or came…

Here's a simple experiment. On a Linux box, open your GUI text editor. Try to open /var/log/syslog. You will see "Permission denied". That's because only apps with root can access /var/*.

Re: More than 1k Android apps harvest data even after you deny permissions

#109

Earlier quoted context omitted.

Please take a step back and look at this again. What is the cause and what is the effect here? Is Google's solution making it better or worse from a practical privacy point of view? (Also, don't buy Google's explanation that this is just to inform users of potential misuse - they actually log your location and even wait for a GPS lock when you pair a new device)

Why shouldn't I buy Google's explanation? If an app that uses bluetooth can get my location via beacons or etc., then bluetooth should be wrapped in location privileges. An app that I do not want having my location should not be allowed to use bluetooth, and I have to accept that any app that does use bluetooth could get my location. While it does mean that apps that use bluetooth now have a slightly easier way of ge…

> Why shouldn't I buy Google's explanation?

Because Google is notorious for coming up with bogus explanations whenever they get caught red-handed. Every month there is a bunch of news articles, where high-ranked Google employee claims to spy on everyone to "protect people from electric pigs", "lower the danger of Confucian Jihad", "enrich e-mail UX with hefty data-harvesting" or something along those lines.

> If an app that uses bluetooth can get my location via beacons or etc., then bluetooth should be wrapped in location privileges.

There is no reason why apps have to be able to "get location from beacons" in order to connect with another phone over Bluetooth. Same for P2P Wi-Fi API — pairing with another device already requires exchanging tokens via graphical dialog with explicit user approval on both devices. Removing ability to read scan results from API would be enough to fix the underlying data leak. Once two devices are paired, they should be able to exchange data without need for any permissions or user actions.

Instead Google forces users to keep Location enabled long after initial connection is made. Even if there is no underlying bad intention, they should be ashamed of forcing such garbage UX upon people.

Re: More than 1k Android apps harvest data even after you deny permissions

#110
post #5

> The update will address the issue by hiding location information in photos from apps and requiring any apps that access Wi-Fi to also have permission for location data, according to Google. The great minds at Google have done it again!! This craziness (Bluetooth requires location) was the reason I never bought a smartwatch. I guess now I should stop using internet too.

The fun doesn't stop at your phone, you're usually leaking location data to third party passive scanners too just by turning on bluetooth. It will broadcast a mac address that is usually poorly and/or infrequently randomized, if it's randomized at all. Some phones will somewhat mitigate this, but random bluetooth devices rarely will.

Ramble is a simple bluetooth scanner app on android, check how often your friends and coworkers mac addresses are updating.

Post reply on HN