Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

291–300 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#291

Earlier quoted context omitted.

Yeah I agree, these settings should be disabled by default and require explicit opt-in. That said, I am impressed by how privacy/security-conscious the OS seems to be otherwise!

You can't really get rid of connectivity check, because it is a part of public API. Applications use it to check whether a network has internet access. Android itself uses it to detect captive portals and prompt user to authenticate when network requires authentication/payment via a web page.

Not an awful lot of stuff breaks if you just patch the api to always return true.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#292
post #80

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

I hope you have recurring donations setup for all these FOSS apps. FOSS still means that developers need to eat.

I'm going to setup a librapay account exactly for this purpose

https://en.m.wikipedia.org/wiki/Liberapay

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#293

Earlier quoted context omitted.

Why is there no money to be made? I would at least pay to buy the hardware and possibly for ongoing software support as well (depending on how they structure such support or any other "soft" features). E.g. I think its a jolly good idea if somebody really checked for a living all those open source apps. In any case if there is really no viable business model for private mainstream mobile computing we have been duped…

In order to have a reasonable, stable supply chain at all, you need quite large scale; and even then your phone would have much smaller scale than the mainstream competitors and so would be be significantly more expensive than their models with similar hardware, both because it's targeting a niche and also because all this tracking&targeting does result in some revenue stream for the manufacturers. It indeed is a jol…

you sketch a good frame to help think about this challenge holistically. the list of failed initiatives is by now so large it almost gives you a statistical sample of factors to take into account (I contributed a data point once - one of the but somehow the numbers could/should add up at some point. If you think (ballpark) a billion devices in circulation and assume that 1-in-1000 people has a combination of awareness and ability to afford a private / open source device, that is your 1M right there.

this should be a very conservative estimate. it assumes that people (more precisely those who claim to represent their best interests) will continue with the inexcusable practice of governments "not interfering" with the "market" (in quotes because it not a real market when you have two options). While some governments slowly take legislative steps in the data privacy space, I have never seen any actual warning from official lips about privacy (the way they warn about assuming financial risk, being overweight, drunk driving, not getting vaccinated etc).

maybe the current business model only stands due to the "subsidy through silence"?

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#294

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

OSMAnd is visually difficult to parse (especially at a glance) and fairly complicated to use. It is not a good map app.

I had the same feeling. I now use Organic Maps which I find much better.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#295

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Same here. I can also recommend :

- Organic Maps which is cleaner than Osmand

- KeepassDX for password management

- AntennaPod for podcasts

- I have a Tutanota email address. Their app is fully open source, downloadable on FDroid's main repos.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#297

Earlier quoted context omitted.

I'm glad they let people know it's possible, a keyboard isn't something you should install without some careful consideration because they can be used as keyloggers. I just wish they'd been as clear about that with the keyboard already installed on the phones when they ship. Anyone seeing that warning might easily think it's safer not to replace their stock keyboard even though it's already doing the very thing they…

> a keyboard isn't something you should install without some careful consideration because they can be used as keyloggers To be frank, Android should not allow input methods access to internet/filesystem in the first place. But that would have hindered Google's own keylogger, so...

I use Google Pinyin Input. (Which seems to have been deprioritized or something, but still...)

The general shape of input methods that let you produce 汉字 is that you provide some type of input that hints at the character(s) you want, the input method displays a menu of options that match your input, and you select the correct option from the menu. For example, if I'm using pinyin entry and I type `shi`, I can choose from 是, 时, 事, 使, 试, 世, 市, 十, 式, 师, 石, 室, ......, which are all pronounced shi. (And heck, those are just the top 12 suggestions. They mean things like "ten", "be", or "stone". The `shi`s go on for several pages.)

You can enter more than one character at once. If I type `bhys`, I'll see the suggestion 不好意思 ("sorry").

The presented options are chosen based on what the input method predicts I'm most likely to want. They are context-sensitive -- the order of suggestions will change depending on what I typed just beforehand -- and the likelihoods and the phrases are collected from what people elsewhere in the world type. Suggestions can be quite current! Without an internet connection, this would be a much worse experience; the predictions would be wrong or useless much, much more often.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#298
post #95

Earlier quoted context omitted.

Do banking applications work? I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. "?

> I mean as in "I buy X online. It requires me to login to my bank application and press 'confirm'. I perform this sequence, and online purchase is completed. " Huh? This is not a real thing.

Bog standard in Germany

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#299

Earlier quoted context omitted.

Hi! I have a Samsung and I looked around online and couldn't find any real info on this topic. I don't doubt it's quite possible, but where is your source from? It's been hard for me to confirm. A good point, though, I'll look at the open source options....

Samsung's own privacy policy and those of the 3rd parties they use. It's been over a year and checking now some things have already changed, but if you click on the gear icon from within the keyboard you can select "about sumsung keyboard" which should give you a list of policies including gify and tenor (both used for gifs I guess) but i didn't even check those. The one you want is the legal info which tells you tha…

They specifically ask you when something like that is being used.

And I don't think giffy or others are receiving your emails. This is probably just usage stats, but someone needs to check that.

Windows 10 start menu on the other hand send every keystroke to bing. You cannot turn it off either

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#300

Earlier quoted context omitted.

Looking at the FAQ provides more details on various ways GrapheneOS phones home by default. Thankfully, some of these "services" can be disabled. The time service is enabled by default but can be disabled. "An HTTPS connection is made to https://time.grapheneos.org/ to update the time from the date header field." "Network time can be disabled with the toggle at Settings System Date & time Use network-provided time."…

A couple thoughts: * Usability: An OS without network connectivity checks and time sync might not be usable by non-geeks * Obscurity: The threat from these pings is low. The threat of having a phone that behaves differently than "billions of other Android devices", indicating that it's GrapheneOS or some other security-oriented OS, is arguably higher.

Connectivity checks can't possibly be useful, because the network can go down after the check. Then what, the phone explodes?
Post reply on HN