Live data from Hacker News

Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

github.com

331–340 of 363 posts

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#331

Earlier quoted context omitted.

What are you trying to say? That because they have a lot of VC money riding on it, they have to do "growth hacking" in order to justify the funds and grow quickly enough to satisfy the investors? Well, I guess I have to agree.

I assumed the OP saying successful social apps as in successful to the point of being known by at least some average people. Metafilter and Hacker News are both very niche and tiny. Hacker News doesn’t have the same business model as others either. It’s to help the namesake incubator. It succeeds with that. Getting contacts etc wouldn’t benefit Hacker News. Hacker News could lose a decent amount of money yearly witho…

Perhaps it is just a fact that we have to accept that large (1M+? 10M+? 100M+?) social networks cannot remain sustainable without abusing their users. That would mean we can benefit from building smaller, sustainable communities for ourselves and those we care about. I'm surprised it's not happening already, to be honest.

With today's technology, you can spin up a community website for, e.g. your family or your organization for the price of basic Web hosting and have all the perks of connecting without the downsides of e.g. your data being harvested and reviewed by anyone at CompanyX.

Sure, you have to do your own security, but the big social networks aren't impervious either. And you gain the advantage of not having your account randomly disabled or spamfiltered or shadowbanned.

It won't protect you from NSA or FBI, but I don't think most people care about that. On the other hand, people I've spoken with are aware and do care about snooping by CompanyX employees.

The more I think about it, even as writing this comment, the more I can see that we are very close to rapid disruption in the social network space.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#333

It's pretty sad that we get to this point. Creating fake contact in our phones to create "data-poisoning". Where the hell are we going?

Going by the canary email addresses I put into my devices from time to time... nowhere good. Those email addresses receive spam despite never sending or being signed up to anything. Apps are actively uploading and selling email addresses. I'd not be surprised if some Big Data company has a massive graph of mobile numbers / email addresses sourced purely from app uploads, let alone reasonable signups. Then its all correlated with other sources like linkedin. Yay! Profit!

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#334

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

Better to use canary email addresses that actually go somewhere you can detect incoming emails. Then it would be useful.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#335

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

I'm surprised it has such a harsh name. Years ago I was wondering what would happen if people just came up with random data, e.g. derived from the own personal data, thinking about crawlers, automatized personal data processing. But I'd just call it creating garbage data because that's what it is. Eventually it will be impossible for an algorithm to distinguish between real and garbage data. (And probably not only for an algorithm)

But I agree with you, it's probably the wrong approach. Personally I've deleted quite a lot of accounts/uninstalled bloated apps. In addition I use tools that actually set additional boundaries, but I'd prefer if the apps wouldn't be so data hungry in the first place.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#336

Earlier quoted context omitted.

Bad data makes it less valuable for resale. It's an attack on the market that these things operate under. Can also be used as a canary trap.

> Can also be used as a canary trap. Can you please explain how this can operate as a canary? Edit: another post explains that the method is if the bogus data end up an a data leak, but that would require keeping track of bogus submissions and generating new data for each company where you create an account. Then you’d have to cross reference like crazy. Am I missing something simpler?

I know at least one person who has their own personal family domain set up so that his family members can just create new email addresses specific to the vendor when shopping online (for example, 'amazon@familyrobinson.com' and 'bestbuy@familyrobinson.com' ). Then all their shopping emails just get routed to his domain. Being able to track which company leaked or sold an email address seems like another benefit in addition to catching all the marketing emails.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#337

Earlier quoted context omitted.

> Can also be used as a canary trap. Can you please explain how this can operate as a canary? Edit: another post explains that the method is if the bogus data end up an a data leak, but that would require keeping track of bogus submissions and generating new data for each company where you create an account. Then you’d have to cross reference like crazy. Am I missing something simpler?

I know at least one person who has their own personal family domain set up so that his family members can just create new email addresses specific to the vendor when shopping online (for example, 'amazon@familyrobinson.com' and 'bestbuy@familyrobinson.com' ). Then all their shopping emails just get routed to his domain. Being able to track which company leaked or sold an email address seems like another benefit in ad…

Gmail has this feature baked in. Append a + sign to the username and then append any string you want, ie. username+ycombinator@gmail.com. It will forward these mails to your regular email address. I started doing this for the exact same reason as mentioned above, but you can obviously do more than just creating honeypots. Also you have to ignore the fact that it's Google...

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#338
post #206

Earlier quoted context omitted.

But still, why do they need to steal your addressbook? They can offer you to spam your contacts without demanding. Is the profit contingent on selling the address book data? To the point where they won't let you invite more people (help them grow!) without it?

The pushback is minimal. A lot of the pushback possibly includes people that are going to be upset by many things. Specific Reddit communities and Hacker News are good examples of that. If these demographics are unlikely to be happy with your social product’s privacy and dark or non dark patterns, catering to them makes no sense. I don’t know any one outside some geeky sites and only one person personally who cares a…

>I don’t know any one outside some geeky sites and only one person personally who cares about any of this. Some do say lame casually. But it’s not going to be a deciding factor for using the app.

My experience is completely different from yours. Out of the dozens of people I've spoken with about this stuff, I can't remember a SINGLE PERSON who didn't express dissatisfaction with at least one of: lack of privacy and potential willy-nilly snooping by CompanyX employee; arbitrary blocking and post removal without good cause; bad interface design; low quality of content.

I don't go fishing for it either, it just happens in conversation, although I sometimes am the first to broach the subject of social networks.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#339

I don't see what the point is. "Data poisoning" gives companies a bunch of fake contacts... on top of all your real ones? Who cares? So they send some e-mails to addresses that don't exist or something? So it takes up an extra 1% of disk space in their database? If you could share an empty address book then that would actually preserve the privacy of your contacts. But this doesn't do that. I don't get it.

I'm surprised it has such a harsh name. Years ago I was wondering what would happen if people just came up with random data, e.g. derived from the own personal data, thinking about crawlers, automatized personal data processing. But I'd just call it creating garbage data because that's what it is. Eventually it will be impossible for an algorithm to distinguish between real and garbage data. (And probably not only fo…

I think the trick is that different users might create "identical garbage" so that contacts match on the backend.

Re: Fake_contacts: Android app to create fake phone contacts, to do data-poisoning

#340

Earlier quoted context omitted.

I know at least one person who has their own personal family domain set up so that his family members can just create new email addresses specific to the vendor when shopping online (for example, 'amazon@familyrobinson.com' and 'bestbuy@familyrobinson.com' ). Then all their shopping emails just get routed to his domain. Being able to track which company leaked or sold an email address seems like another benefit in ad…

Gmail has this feature baked in. Append a + sign to the username and then append any string you want, ie. username+ycombinator@gmail.com. It will forward these mails to your regular email address. I started doing this for the exact same reason as mentioned above, but you can obviously do more than just creating honeypots. Also you have to ignore the fact that it's Google...

There already exists at least one popular js validation framework which removes Gmail (and others) subaddresses per default in its "normalizeEmail" method: https://github.com/validatorjs/validator.js/blob/master/src/...
Post reply on HN