Live data from Hacker News

Google collects cell tower info even if location services are disabled

qz.com

131–140 of 422 posts

Re: Google collects cell tower info even if location services are disabled

#131
post #63

It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. That's the advice of pretty much everyone in the infosec field and I'm sure some of them will attest to that in this thread.

Apple provides a black box with iOS, they have full control. Maybe the next iOS update comes with privacy intrusion because it's more lucrative. A more sensible way of dealing wirh the issue would be to use an open source Android version like AOSP or LineageOS, not run proprietary gapps, and replace its functionality with F-Droid, MicroG and Yalp-store. Your location will stay out of Apple's/Google's hands and you ca…

Agree.

Another sensible way (if you are prepared to 'phone' a bit more frugal) is a Sony Xperia X with Sailfish. (But check together first.)

Re: Google collects cell tower info even if location services are disabled

#132
post #124

Earlier quoted context omitted.

It's really humbling to see what people in different living circumstances take for granted. Apparently privacy is the fundamental right only for the people who can afford a $700+ device.

I take your point, but I think it’s important to note that the iPhone SE is half that price. In India, it’s about $309 today.

> In India, it’s about $309 today.

So about three times the average monthly wage if the numbers I find are right.

(Sneak edit) Just to write it down another way, that means 25% of the average yearly income. For a phone.

Re: Google collects cell tower info even if location services are disabled

#133
post #63

It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. That's the advice of pretty much everyone in the infosec field and I'm sure some of them will attest to that in this thread.

I don't disagree with your first point, but I disagree with the second. Encouraging everyone to "just buy an iPhone" is a false dilemma of its own.

No. The "obvious" solution here is to regulate companies and give huge fines for doing stuff like this, without explicit user permission. Google went through hell in Germany over its "error" in collecting user data from their Wi-Fi hotspots. Why can't the U.S. do the same in this case?

It's not just an absolute privacy outrage, but also an outrage because Google will drain my phone's battery life without permission, just to serve its own interests.

Re: Google collects cell tower info even if location services are disabled

#134
post #25

Earlier quoted context omitted.

Of course, this is meaningless without context. Privacy from who? Security from what? What's the perceived threat we're trying to protect against? Everything is a tradeoff. To absolutely protect your privacy, you must never be seen in public or interact with any other party in any way.

This is sophistry, privacy in the sense that a private company is not continuously compiling a list of every location you visit throughout your life.

[deleted]

Re: Google collects cell tower info even if location services are disabled

#135
post #63

It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. That's the advice of pretty much everyone in the infosec field and I'm sure some of them will attest to that in this thread.

Apple provides a black box with iOS, they have full control. Maybe the next iOS update comes with privacy intrusion because it's more lucrative. A more sensible way of dealing wirh the issue would be to use an open source Android version like AOSP or LineageOS, not run proprietary gapps, and replace its functionality with F-Droid, MicroG and Yalp-store. Your location will stay out of Apple's/Google's hands and you ca…

"Apple provides a black box with iOS, they have full control. Maybe the next iOS update comes with privacy intrusion because it's more lucrative."

This is true, but it's also potentially worthwhile to consider that Apple has positioned themselves as a hardware company (i.e. the majority of their money is based on selling units of hardware), whereas their main competitor here (Google) is an ad company (i.e. the majority of their money comes from selling their users' data). Apple has chosen to highlight their commitment to privacy partially because they feel it helps their market position, whereas for Google, it would hurt it.

Certainly it doesn't mean that Apple is infallible, just that I think it makes it easier to accept that Apple is more likely to protect privacy more than Google.

I'm pretty biased towards Apple, so obviously this may not work for everyone; if you need source code to feel secure, then by all means, go for it. For people who are looking for less work but some of the benefits, I think that Apple is a decent way to go.

Re: Google collects cell tower info even if location services are disabled

#137
post #63

It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. That's the advice of pretty much everyone in the infosec field and I'm sure some of them will attest to that in this thread.

> It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. Smartphone or not, carrying any phone means providing this information to your carrier at all times. I don't like the idea of sending this information to anybody, but to be honest, Google is the entity that I'm the las…

If you don't believe him just google it!

Re: Google collects cell tower info even if location services are disabled

#138
post #63

It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. That's the advice of pretty much everyone in the infosec field and I'm sure some of them will attest to that in this thread.

> It's amazing to me how many comments here excuse Google's behavior by offering the impractical "solution" of just not using a smartphone (a false dilemma) when the obvious answer is to get an iPhone. Smartphone or not, carrying any phone means providing this information to your carrier at all times. I don't like the idea of sending this information to anybody, but to be honest, Google is the entity that I'm the las…

You can also set your phone to airplane mode with WiFi and Bluetooth enabled most of the time unless you need 4g for something like driving directions.

Google has much better security than the phone companies anyway, so letting the phone companies know where you are is bad enough.

I had the idea to "red team" myself and find out if there's a way of finding out my location history from shady online data broker and then take countermeasures.

Re: Google collects cell tower info even if location services are disabled

#139

Earlier quoted context omitted.

Android is bad for pretty much all threat models. - Worried about Google? Android is bad. Google collects your data. - Worried about the government? Since Google must obey warrants for your data, Android is bad. - Worried about malicious third parties? Since Google has failed to patch even the Pixel line for KRACK until the December update... yeah, Android is bad. And malware through the Play Store that hits large nu…

You should be assuming that all networks are pwned anyway. KRACK was exciting, but really isn't a major threat to people.

This is true and false. It is good to assume your Wi-Fi networks are insecure, and I've done so for a long time. But the fact that WPA2 is not the lynchpin of your entire security plan doesn't mean that WPA2 being effectively nullified isn't a massive layer of security being ripped off.

WPA2 working correctly does not guarantee that you are secure, but WPA2 working correctly means it is much harder for someone to do something malicious. The fanboy crowd has leaned heavily on Google's push to get sites to use HTTPS everywhere as a reason to suggest KRACK isn't a big deal, but the reality is a massive amount of Internet traffic still isn't HTTPS, and more than likely, never will be.

Post reply on HN