Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

301–310 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#301

Recently Apple added a feature to iOS that allows you only to allow selected photos to be accessible by an app. This allows the user to respond positively to an access request, but allow the app to see only a subset (or zero) actual photos. It would be a very useful feature for Apple to do the same for contacts: the app would think it's getting access to your contacts, but would only actually receive a subset of them…

Under Android, if apps want to be respectful, they can. For example, the Discord Android will fall back to system file-pickers if you block storage permissions. Since there's no incentive to be privacy respecting, very few other apps I've used let you do this.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#302

Can someone please explain to me how the collection of contact data is in any way legal under the GDPR and why Microsoft (Windows), Apple/Google haven't been required to make changes to prevent abuse of this permission (such as selecting specific contacts). I'd also like to not know why if my contact data is shared, I am not informed of this. If my data is uploaded by Google to their servers, I should know. If somebo…

The data protection agencies who are given the power to enforce the GDPR are completely incompetent at doing so, or are corrupt and silently benefit from the status-quo.

The web is filled with various dark patterns (and even companies whose entire business is to provide such dark patterns as a service) that would fall afoul of the GDPR, and yet nothing is being done.

Google and Facebook - part of the most popular websites worldwide, and with business presence in all the major EU countries - have had a non-compliant cookie/tracking consent flow for over a year now and nothing is being done.

If even blatantly obvious breaches (which would be trivial to litigate) are ignored, something more murky like Apple (a neutral third-party) merely providing a tool that can be used to violate the GDPR (but also can be used legitimately) has no chance of making any progress.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#303
post #290

Earlier quoted context omitted.

*@myname.name

Yeah I've been using yourcompany@mydomain.tld for ages to track who's sold or fumbled my data. Since haveibeenpwned I can even approximately separate the two groups. Surprisingly up to now nearly all incidents (that I know of) have been breaches. Not that it makes it any better.

Same here. Though people usually give me weird looks when I do this IRL and ask me "Is your email address really ourcompany@yourdomain.tld"?

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#304
post #252

Earlier quoted context omitted.

Not the poster you are replying to, but I stopped feeling empathy for people who complaint about lack of privacy, yet willingly give up their data to non-essential services that ask for it with all the proper disclosures. If you agreed to sharing all your contacts to listen to “musical tweets”, I don’t see why you’ll be complaining. You willingly made a trade off.

... willingly give up other peoples‘ data.

Exactly. What a jerk right?

“Oh noes I had to give up all of my contact’s personal information... but I got into that beta!!”

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#305
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

Or a feature implementation which would essentially means - "select fake/random data instead".

Fake/mock GPS (w/o telling the app that it's fake unlike what Android does), fake contacts etc.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#306
post #63

Earlier quoted context omitted.

All these permission choices should be invisible to the app. If I say no contacts the call should succeed but with a zero Len response. It shouldn’t be possible for apps to say you have to agree to this or I won’t run. I can run the software and as the root user control what data the software can use.

> It shouldn’t be possible for apps to say you have to agree to this or I won’t run. It's not - that's a violation of the App Store TOS. That's also not what's happening here - you can use clubhouse without allowing contacts access, but you can't invite someone to the closed beta without allowing it.

> that's a violation of the App Store TOS.

not if the app still functions with deliberately reduced functionality. What i want to have is for the app to be unable to tell the difference between being denied permission, and having no data (or be sent fake data).

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#307
Just reading the headline and thinking: Providers (like google) may still be able to filter out fake profiles if those fake contacts don't have relations to each other. Meaning that if only you have a contact with a random number, and nobody else has, it's most likely fake.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#309

Apps using contacts is a $#%$ing anxiety attack for me. The scum companies don't care. They just want more leads. But for me, it's this fear that they're going to spam my exes and old roommates and bosses and professors and landlords and everyone who ends up added to my contacts. Signal did that to me last week. This person I'm not on speaking terms with got Signal and it added us and announced to each other we were…

Not to be unkind but I suppose most people are not really traumatised by merely seeing someone's name, even if they're not on speaking terms with that person. It probably falls on the side of convenience for the vast majority. For the Signal org, it's possibly even an existential issue, since it helps them counter network effects in the incumbents. It's hard to expect them not to do it, then. Having said that, I thin…

Signal shows contacts (and just bare phone numbers as well) inside the app which have not been in my contact list for years (but once were).

And this is how Signal suggests doing it https://support.signal.org/hc/en-us/articles/360007319011#io...:

> Remove someone from your Signal contact list

> Contacts must be blocked in order to be removed from your Signal Contact List. To learn how to block someone, click here.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#310
post #9

Clubhouse requires contact list in order to get invites, which are required to sign up right now. I get why they are doing this, and it caused me to share my contacts with them. However, I resented it and it put me immediately in a defensive posture with the product and company. There is no possible way to trust a company with your contact list and Apple should make it how Photos works now--where you can select which…

OpsecLeaksHouse
Post reply on HN