Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

361–370 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#361
post #152

Earlier quoted context omitted.

Most banks in EU require phone app based confirmations for transfers and other operations (according to PDS2 directive). Visa and Mastercard also introduced 3DSecrue system which piggybacks on the same system of confirmations. Vendors are incentivised to adopt it by lower rates. In essence when paying with card or making a wire transfer (or using some instant transfer method, for example Blik in Poland), you get noti…

Didn't know this was driven by PDS2. As much as I appreciate the convenience, I still find the whole drive fucking annoying - especially that, with all the talk about data portability, I still can't get a simple API endpoint I could point a script at to fetch me my account's balance. Yes, I'm bitter. If there's ever a bank that puts end-user automation first, I'll switch in a second.

From all the banks I've tried over the years I always check for this feature, sometimes asked and never got what I wanted. "No the API is only available for our 100k a month or more users" is the closest I got.

However when I really wanted a solution i build a small service that receives the confirmation SMS most banks offers and pushes my balance in a small API.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#362

Earlier quoted context omitted.

Is the pocket router battery powered. Really we need an suitable open source, easily compiled OS to run on a suitable "smartphone" that can be re-purposed into a "pocket router". This to function as the gateway through which our "phones" reach the internet.

The router/modern is battery powered or it will run continuously off a USB charger. The one I'm using currently is a Vodafone (Huawei) R216. Here are the specs: https://wirelessgear.com.au/vodafone-pocket-wifi-4g-r216-mod... . That link is the first one I found, if it doesn't work for you just search the modem's model number. The R216 lasts for at least 6 hours on battery, often much longer (and the battery is remova…

Regarding a portable router - I wonder what you think about that one?

https://www.gl-inet.com/products/gl-e750/#specs

It's about double the price, based on openWRT (but not fully open source).

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#363

I use GraphineOS and LineageOS without Google Play Services. They are great and are suitable replacements for Apple and Google. - Osmand(FOSS) for maps (supports being fully offline!) - Signal and Discord for messaging (Discord is sandboxed) - Newpipe(FOSS) for Youtube - F-droid(FOSS) for my FOSS appstore - APKmirror for the few non-free apps I need - Libretorrent(FOSS) and VLC(FOSS) for watching movies - Firefox(FOS…

Same here. I can also recommend : - Organic Maps which is cleaner than Osmand - KeepassDX for password management - AntennaPod for podcasts - I have a Tutanota email address. Their app is fully open source, downloadable on FDroid's main repos.

Organic maps isn't there yet IMO. OSMand is huge, but it's the only app to match Google Maps features.

I can also recommend BRouter (with OSMand) for bike navigation. It's ugly and hacky, but once it works, bike navigation is much, much better than Gmaps'. E.g. it's not sending you down cobblestone roads all the time.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#364

Earlier quoted context omitted.

I'm surprised to hear you say that. I've played the most demanding Android games on the Pixel 3a with no issues. I've never experienced anything but a butter smooth UI on Graphine or Lineage to be honest. The battery life has been all day for me even when using GBA emulators for multiple hours a day. I agree the default camera app of Graphine isn't great, but it's picture quality better than the iPhone I came from (i…

Can you install GCam as apk from somewhere? Will it work? I use GCam on the default Android (8) on my Nexus 6P and it works well. I am thinking of upgrading to Pixel 2XL or 3A and install Lineage OS with GCam, so I believe it would be a much better experience than the default ROM on a Pixel. But I have no idea whether GCam would work in LOS.

I use this: https://github.com/lukaspieper/Gcam-Services-Provider to make the GCam app work

You should be able to get GCam via Aurora Store by setting the spoofing to a Pixel device, but newer versions of GCam check for something that cannot be spoofed with an app (issue #22 in above github) so you have to get a modded GCam app if you want to user newer versions and use an android rom that does not spoof this.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#365

A distinction needs to be made clear here with regards to the data being transmitted to Google by LineageOS in this study. In the cited paper ( https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pd... ), the device used to test LineageOS was a Google Pixel 2 running LineageOS 17.1 which also included an installation of OpenGapps 10.0 nano . It's not the OS that is transmitting the data over to Google, but rath…

Yep MicroG is the route I'm going on Pixel3a I just bought. You don't need to sign into any Google services to use them. For now I'm just using maps. I found a nice Reddit article on de-googling even more as well. If you install OpenGapps you might as well forget it- https://www.reddit.com/r/fossdroid/comments/clg2ca/how_to_de...

My exact setup. Using Gaia for maps.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#366
post #359

Earlier quoted context omitted.

"...if you want an airgapped phone, use it in airplane mode." Right, that's what I do. In fact this post comes from a smartphone sans SIM with airplane mode on, with a firewall against apps phoning home, no Google or Gmail account, all Google Gapps nuked including playstore - in fact all Gapps have been completely removed - not to mention that most replacement apps come via F-Droid. Yes, technically it's not fully ai…

Interesting approach. Which goal gets served by the separate router? I've been thinking here for a while, but the only thing that comes to mind is a very restrictive "allow-list only" firewall. Which dumbphone are you using? The majority thereof seem to be KaiOS based, which frankly is not sufficiently dumb for me to warrant the switch.

First, the dumb phone is just that—voice and SMS only sans internet but more on that in a moment.

The router was designed to serve three purposes and I use all three of them: (a) to simultaneously connect up to five devices (smartphones/PCs etc.) to the internet via normal WiFi connection which it then routes to the internet via a mobile SIM card; (b) it's also a WiFi LAN switch in that it will allow local interconnection between the five connected devices; and (c), it has provision for an onboard SD card to which the five devices have access (i.e.: it acts as one's local mobile mini NAS). You'll see reference to detailed specs of the Hauwei R216 that I use in my previous post in reply to 1vuio0pswjnm7.

In my case, I use a fully-fledged reasonably current Android smartphone operated without SIM card and set to airplane mode for normal app usage, location and maps when needed, as well as internet browsing and non-Google email (POP/IMAP)—thus, the phone's only internet access is by either WiFi (to the router—my usual way) or Bluetooth—to another phone's internet connection (normally off).

Note: the phone is never used for telephone calls and it cannot be used as such as the router's SIM is a data-only type (that's to say one has a mobile phone number that cannot be used to make normal phone calls). Moreover my ISP, as many do, differentiates a data-only SIM/service from a normal one that does both. (In data-only services, one trades normal voice phone for extra data/cheaper data rates—you know, the usual ISP con job of artificially inflating a mobile phone's data charges. Nuking phone/voice access in data SIMs somehow—as if by magic—justifies ISPs to sell you data at a much cheaper rate. Furthermore, normal SIMs often won't work in routers for similar nefarious reasons).

As mentioned, I deliberately avoid Google services but using a phone this manner doesn't preclude one from doing so. I've found that if you use Google services, etc. then there's an added privacy advantage of disconnecting the phone from the actual telephone number as that now belongs to the router, moreover any app that that reads the phone's IMSI number will not be able to find a corresponding telephone number. I've several phones that I connect to the internet in this manner and every one of them has never had a SIM in it so Google is unable to link the phone's current ISMI-only configuration to any former IMSI/telephone number combination as there's never been one. Furthermore, in one instance when rooting one of my phones I accidentally formatted the partition containing the IMSI information, etc. and whilst I had the means of putting the info back I decided not to—thus apps no longer have even an IMSI number as an ID reference. Incidentally, this is still legal as far as regulations are concerned as the router and router SIM now provide the IMSI/phone number combination.

My phones also gain extra privacy from the fact that they're rooted, one can use the many Xposed Framework tools and such to improve privacy, nuke ads etc.

On the matter of firewalls, I normally use one on the smartphone itself rather than say installed in the router for purely practical reasons in that it's easy. The drawback of course is that if the firewall stops for any reason, which on occasions does happen (especially so after a full restart), then any apps that have a collection of data will use the opportunity to send it (my default is that no apps have internet access unless it's specifically needed as part of the app's function and the firewall is set accordingly—this also acts as extra method of nuking ads although I mostly use F-Droid's ad-free apps). This risk can be essentially eliminated with a rooted phone but I've not time to go into that here. BTW, I use several Android firewalls apps (not on the same phone of course) but I've found the easiest to use is Karma Firewall.

Re my dumb phone, I've been using an Aspera F28: https://asperamobile.com/phones/easy-phones/aspera-f28/ and its later incarnation the R30 but I'd not recommend them and they're unlikely to be available in many places. Their batteries are too small and of inferior quality and have to be replaced often (at least they're removable). Nor would I recommend other Aspera phones for similar reasons. I doubt that they use KaiOS, if they do then I've seen no sign of it. I reckon you're right to be worried about KaiOS especially so since Google has invested millions into the project.

Incidentally, I've other better flip phones such as Motorola ones that I can no longer use as they're only 2G (which is ideal for dumb phones) but unfortunately where I live they've now killed 2G. Doro dumb/feature phones may be worth considering as they've have always had a reasonable reputation (in the past I've thought about getting one but I've no practical experience of them). I know that Doro used to use their own OS but I cannot tell you much more than that except to say they do use KaiOS on at least some of their phones, the 7050/7060 for instance.

Of course, much depends on what you actually want to do. As I've mentioned in my previous post to 1vuio0pswjnm7 that carrying three devices instead of one can be rather inconvenient as there's more bulk to carry around and also the chances of losing one of the devices is potentially higher—one needs sufficiently large pockets to carry them thus size and bulk matters. As a person who's always carrying around lots of technical junk this is a hobbyhorse of mine and I'll address it in more detail when I reply to Iolaum.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#367
post #362

Earlier quoted context omitted.

The router/modern is battery powered or it will run continuously off a USB charger. The one I'm using currently is a Vodafone (Huawei) R216. Here are the specs: https://wirelessgear.com.au/vodafone-pocket-wifi-4g-r216-mod... . That link is the first one I found, if it doesn't work for you just search the modem's model number. The R216 lasts for at least 6 hours on battery, often much longer (and the battery is remova…

Regarding a portable router - I wonder what you think about that one? https://www.gl-inet.com/products/gl-e750/#specs It's about double the price, based on openWRT (but not fully open source).

That Mudi GL.iNet router/modem combination seems a very substantial device with excellent specs. I've not seen it previously (but I've not been looking of late either), with specs like that I'd certainly consider it when deciding my next purchase.

Here, it seems to me the key issue of whether to buy that one in preference to, say, a somewhat lesser model with fewer features will depend on how you use it. Right, that's stating the damn obvious but from experience I've found it's very important when it comes to mobile stuff, all too often I (and others) have glanced over this important portability factor.

If your intended use is to, say, carry it in your luggage and only use it after you arrive in your hotel or conference room then I'd reckon there'd be nothing better than to buy the Mudi GL.iNet device. On the other hand, if you intend to use it like I use my Huawei R216 router/modem, that being as part of my kit to replace a normal default-type Android phone (as per my previous posts to 1tSlEv and 1vuio0pswjnm7), then a physically smaller device would seem preferable.

As mentioned, carrying around three devices instead of a single smartphone is rather inconvenient in that there's more bulk to carry around, also there's more chance of losing one of the devices. I'm pretty adept at doing so now but when I first started some years back I'd sometimes only take the smart and dumb phones and forget the router/modem—thus I'd have phone access but no internet (right, being Don Quixote and always tilting at windmills isn't necessarily the easiest way to run one's life) :-)

My 'combo phone' isn't the only stuff that I carry around, it has to share my pockets with other junk like screwdrivers, pliers, thumbdrives, multimeters, etc. so physical size is major consideration. From the specs, I've noticed the size of the Mudi GL.iNet router/modem is 145 x 77.5 x 23.5mm and weighs 285 grams; by contrast, my R216 is 95 x 58 x 11mm and weighs only 77 grams. Thus my R216 is only about 22.9% the volume of the Mudi unit and weighs just a nudge over a quarter of its weight. This difference is very significant if one is trying to carry it in, say, one's jeans' pocket along with both a dumb and smart phone.

This brings me to one of my pet peeves; that being the ongoing and progressive decrease in the depth of men's trouser pockets over recent decades. This is no joke or trivial matter; I lost an almost brand new HTC smartphone after going to a concert and sitting in laidback seating, it just slid out of my pocket without me noticing its loss, by the time I had then it was too late. If I were a conspiracy theorist rather than someone who understands that such negative occurrences are 95% the consequence of fuckups then I'd believe there was a conspiracy between phone and clothes manufactures to sell more phones! I cannot understand why the average guy isn't up in arms over the continual withering of his pockets; after all, surely the cost of extra cloth necessary to correct the problem would hardly be measurable in the overall schema of things (BTW, this pocket problem even extends to coveralls/overalls). Anyway, as someone who's been sartorially challenged from birth, I've largely overcome the problem by ignoring fashion altogether and taken to wearing ex-military BDs or equivalent cargo pants. Penny-pinching accountants haven't yet sufficiently infiltrated their manufacturing to have made much difference.

The upshot of this is that I keep the smartphone in one of my trousers side pockets and the dumb phone in the other whilst the R216 router/modem I put into one of my shirt pockets. The caveat here is that it's important to have shirts whose front pockets can be buttoned or zipped up to stop the device falling out whenever one leans over. Given the average size of shirt pockets—and they too have been shrinking in recent years—then there's no way the Mudi GL.iNet router/modem would fit in them.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#369
post #11

Companies like Google hold a lot of power over their users. It's all-or-nothing, and not being part of the Google ecosystem is extremely inconvenient as more and more services depend on it. Only legislation can give power back to the users. It shouldn't be necessary to put up with this level of surveillance by big corps in order to function in society.

>Only legislation can give power back to the users. It shouldn't be necessary to put up with this level of surveillance by big corps in order to function in society. Don't worry, after about 7 years there will be a low key class action suit and we'll miss the $7 payout and lawyers will collect the leftover millions for the sake of symbolic justice. Then perhaps big industry won't ever learn it's lesson again. Congres…

I would go further and say that this describes the ineffectiveness (I’d say corruption) of Congress and the justice system across all industries. This is just the one you notice because you’re well acquainted with it. If you have a strong stomach go look up Steven Donziger.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#370
post #180

Earlier quoted context omitted.

It depends per bank; mine discontinued the paper OTP pad as well as the SMS codes, and gave me a separate 2FA device when I didn't want to use their app. I don't think banks can force you to have a smartphone yet.

Does nobody in the EU do computers ? How do they pass asinine laws like this ? I mean, from the outside, it always appears as though the EU is much better than the US when it comes to consumer rights, but it always feels like they don't have a very good grip on technology.

Where I live, the authentication systems implemented by banks are also used for verifying user identity to various other services, including governmental ones.

Basically, there's a common (government-backed) user identification system which hooks up to interfaces that banks provide. When you're logging in to an online service that requires strict identification of the user (such as ones that would require an official id document if done in person), you first pick the bank you're using, and the service forwards you to the bank's website. Once you log in with your bank credentials, the original requesting website gets informed that you've provided valid login information, and the identity that the login matches with.

I don't know the exact technical details of how that works, but essentially the bank also acts as a user identification service for various official and governmental online services. It's treated as similar to proving your identity with a document, or to signing a document with your signature.

I don't know if this is a common thing in other European countries, but if it is, that might be a reason why the EU has an interest in enforcing 2FA.

You're not strictly required to use a smartphone, as at least my bank has other means of 2FA that satisfy the regulatory requirements, but they are more cumbersome.

Post reply on HN