Live data from Hacker News

Betrayed by an app she had never heard of

privacyinternational.org

111–120 of 244 posts

Re: Betrayed by an app she had never heard of

#111
post #35

Earlier quoted context omitted.

This is why I don't use WhatsApp despite the fact I know many people who use it. To use the app, you have to give access to your entire contacts list. Even if I'm okay with them having my information, I don't feel comfortable consenting for those in my contacts list who don't use WhatsApp.

You don't have to give the app access to your contacts... at least on iOS. That's what I do. It would be impossible to communicate with friends and family otherwise. I just have to put a little more effort into figuring out who's texting or calling me. The app also still shows me people's (self assigned) nicknames in group-chats. My only gripe is that I still have to give the app access to my photos. I wish there was…

You don't need to give WhatsApp access to your photos.

If you want to share a photo you just have to leave the WhatsApp app and start the sharing from the Photos app and select WhatsApp as the target.

Re: Betrayed by an app she had never heard of

#112

Earlier quoted context omitted.

It’s quite different. A report spam function wouldn’t include (or shouldn’t include!) the identity of a person. If it does then it’s going over and above a spam filtering service. Reporting a number as spam should then just result in future recipients seeing a “Probably Spam” or “Spam” etc based on reported levels on Spam vs Non-Spam reports for the number. But I do agree that the journalist should have practiced bet…

But I do agree that the journalist should have practiced better opsec and advised her sources that they probably don’t want her name to show up on their phone if she calls them at an inopportune time such as when around the very people she is investigating. How do you secure against something that you're not even aware exists? Maybe outsourcing operational security? But how can a journalist aford that?

You quoted my example about the journalist calling the source while the source is around the people she is investigating. That’s a situation the journalist should be well aware of.

I would expect journalists to have some opsec training by their newspaper/publisher given maintaining confidentiality is a given in this line of work. Even if they didn’t have such formal training, I’d expect them to pick up a few things like this with experience.

Re: Betrayed by an app she had never heard of

#113
post #86

Earlier quoted context omitted.

> is it just me or is this a mountain-out-of-a-molehill situation? It's just you. The example of the journalist is a very good example of exactly why this is such an extreme issue, but it really starts with the small things. What if you want to call someone, and not tell them your name? well, f#$£ you then, the app already told them. Don't want everyone knowing where you work? well f$%& you again, maybe somebody adde…

Let's go back to the world where there is no internet. Imagine someone spreads a rumor about you. Or a praise. People might have heard this, before they even met you. It can be illegal, harmful, or beneficial, but it's under the control of the people you interact with. If you meet someone for the first time, and the person heard from someone that you're dealing drugs, and you tell her you don't, and ask them where th…

Sure, the mechanism is the same, but the scale and effectiveness are not.

In your scenario, if someone wants to spread rumors about you in bad faith, they have to spend a lot of time and resources to make sure everybody you might interact with knows about the rumors.

A service like TrueCaller makes this much easier, which I personally think is very problematic. And as others have noted, another issue is that people even might not do this in bad faith. Just as a little prank, without realizing the potential consequences.

Re: Betrayed by an app she had never heard of

#114
post #18

This reminds me once again that the weakest link in the privacy chain today is the mobile phone number, especially since governments in many countries have forced people to link their number to a real ID. It's essentially become a ID number by proxy. However, in the case of the article, the reporter should know to inform her sources not to enter _any_ information linking to her real-world identity into their electron…

I got a free loaner phone once a few years back ("Samsung Ultimate Test Drive") which came with pre-activated mobile phone service and was very clearly re-using a phone number that someone else had quite recently actively been using. While it was weird to get SMSes about SoCal drug deals, the strangest thing of all with that phone was opening the Lyft app and being automatically signed in to someone else's Lyft accou…

You could have signed into Whatsapp as well.

Re: Betrayed by an app she had never heard of

#115
post #102

Earlier quoted context omitted.

The problem I see is that politicians don't seem to have any good days.

You are living in a complex, mostly functioning nation state where the majority of conflicts is resolved in a civil manner. Not in a small tribal society where you might be murdered by someone physically stronger than you simply because he lusts after your partner. That simple fact proves how hyperbolic and naive your statement is.

wut? are we really comparing 21st century society with a tribal one?

by that measure we've solved pretty much everything.

when in reality the contrary is true: politicians are mostly career based opportunists and the inertial nature of our society pushes us to peace and prosperity.

Re: Betrayed by an app she had never heard of

#116
Rather than disabling the Caller ID, what if the journalist spoofed her Caller ID each time she called. In that way, it prevents 'Private Number' showing up on the receiving end which is the thing preventing those on the receiving end picking up her calls.

Re: Betrayed by an app she had never heard of

#117

This article focuses on the problems that truecaller poses for 'non-users". As a non-user of truecaller in India myself, I find myself in the minority. It seems I get none of the benefits (improved spam filtering, the chance to see who is calling me), and in the 'prisoners dilemma' sense, it appears I would loose nothing by installing it, because they already have my contact information. However, this is only half th…

> If you install truecaller on Android, you're handing over ALL your personal information to them.

That's what I remember too but the article said Truecaller only gets non-user's information when a user tags them so. Maybe the app behavior varies with the country the user is in.

Re: Betrayed by an app she had never heard of

#118
post #23

I find TrueCaller very usefull. I used to get sooo many sales and robo-calls a day that I seriously considered just getting rid of my phone. Now they get automatically blocked or I can just put them on a profile that they ring silently and hang up immediately. I get that this can be dangerous for journalists, but shouldn't they maybe investigate alternative ways of contacting sources privately? Mobile numbers are not…

It's also worth noting that - as with almost any privacy-violating technology - journalists apparently sometimes use TrueCaller for research themselves.

Re: Betrayed by an app she had never heard of

#119

Earlier quoted context omitted.

But I do agree that the journalist should have practiced better opsec and advised her sources that they probably don’t want her name to show up on their phone if she calls them at an inopportune time such as when around the very people she is investigating. How do you secure against something that you're not even aware exists? Maybe outsourcing operational security? But how can a journalist aford that?

You quoted my example about the journalist calling the source while the source is around the people she is investigating. That’s a situation the journalist should be well aware of. I would expect journalists to have some opsec training by their newspaper/publisher given maintaining confidentiality is a given in this line of work. Even if they didn’t have such formal training, I’d expect them to pick up a few things l…

I would expect journalists to have some opsec training by their newspaper/publisher given maintaining confidentiality is a given in this line of work.

I agree. But I still think it's a tall order to expect a journalist to know every service and every app, which may violate their privacy and protect against such entities.

And then there are things, which you just can't control, even being aware of them.

As a for example: How do you, as a journalist, prevent that your pictures are tagged by others on Facebook?

Edit: Slight clarification

Re: Betrayed by an app she had never heard of

#120

Earlier quoted context omitted.

GDPR is 100% necessary and fundamentally a good idea. It has a lot of problems that just show how incompetent politicians can get on a bad day, but that doesn't invalidate the core idea.

It has a lot of problems that just show how incompetent politicians can get on a bad day Mind elaborating on them? The only potential issue, which I see, is some ambigiouty. However, I don't see how you could craft a legal frame work without some ambiguity, which needs to be resolved by the courts at one point. Unless your business model is dreck, I really don't see any issues with the GDPR as such.

Maybe I'm just naively applying my programmers sense of beauty to legal stuff, but the main problem I have is complexity. I'm OK with google having to spend some money on lawyers to work out what they can and cannot get away with, but smaller busynesses seem to be pretty lost right now. This is partly because it's a new thing and we need to wait and see how judges ultimately interpret things, which will give people some more security.

A simpler, more elegant solution would have been better in my opinion.

Post reply on HN