Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

131–140 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#132
post #65
post #63

Earlier quoted context omitted.

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

Or even as a a service fake data - feed fake location data and fake contact list. Full of 202-555-1234 type numbers. I always put fake data into web forms and it is a sign that I don’t truly own the phone that I can’t do the same for local software.

Like I want a pop up: this application is requesting your location data. Shall we give the real data, no data, or simulated data. Same for contacts, photos, apps installed, etc.? Not saying that would solve all the problems but it would be user centric in a way the privacy conversation just isn’t.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#133
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

please reconsider doing this next time if you’re able to

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#134
post #47

Earlier quoted context omitted.

If you’re not subject to the EU (I.e. don’t have any offices, servers, etc. in the EU) I don’t see how the GDPR is relevant: non-EU citizens generally aren’t subject to the laws of the EU.

"The GDPR also applies to data controllers and processors outside of the European Economic Area (EEA) if they are engaged in the "offering of goods or services" (regardless of whether a payment is required) to data subjects within the EEA, or are monitoring the behaviour of data subjects within the EEA (Article 3(2)). The regulation applies regardless of where the processing takes place. This has been interpreted as…

Countries or groups of countries don't get to impose their law on other countries.

That's called colonialism, and Europe is supposed to have given it up.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#135
post #53

Earlier quoted context omitted.

"Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app." What we really need to see from Apple is a permissions index in the app store that allows me to inspect, and consider, the permissions that an app will request before installing that app . I shouldn't have to install the app (or do laborious research online) to discover what permissions it will attempt to…

I'm not sure the permission index would be very useful. Most iPhone chat apps for example work perfectly fine with zero permissions granted yet provide the option to send pictures, invite contacts, use mic/camera, send gps location, etc if a user is so inclined. With a permissions index, you would likely end up with the majority of apps listing all permissions and users would simply ignore it.

So? Just give me the possibility to see it.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#136
I was looking through my contacts the other day, deleting some people I don't speak to any more. Its interesting that with 5 or so unique enough contacts I could be identified. If they were sufficiently unique, no one in the world could possible know those 5 people. Scary thought.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#137
That is why we should have a custom app for contacts with custom encryption (like keepass) to store our real contact. So not any app or apple or google has access them.

For some ppl like political of activist fundraisers, contact info privacy are utter most important. In fact some of them still store it on rolodex, and will not put any of that into digital form. And as a software developer I actually support that tremendously.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#138

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

I've got a dead friend that I'm reminded about every time I open signal. "DeceasedFriend is on signal!". No, no he is not.

I'm sure I could clear it, but I don't really want to yet.

On the whole, I still like the feature.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#140
post #120

Earlier quoted context omitted.

Is there some service where I can easily create unlimited custom email addresses for a flat monthly fee? I want to use a unique email for each new website/service. That would go a long way to solving some data leak/privacy problems. The problem with custom domain is I have to maintain it right? I want a service which I don't have to maintain. I used to use new Yahoo accounts but they are a hassle and recently they di…

Protonmail allows wildcard emails from 1 custom domain if you pay for the ~$5/mo plan. No maintaining a mail server, just point your MX records to their servers.

Catch-all support starts at €8 at ProtonMail.

https://protonmail.com/pricing

Post reply on HN