Live data from Hacker News

Android phones are sending significant amount of user data with no opt-out [pdf]

scss.tcd.ie

371–377 of 377 posts

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#371

Earlier quoted context omitted.

A couple thoughts: * Usability: An OS without network connectivity checks and time sync might not be usable by non-geeks * Obscurity: The threat from these pings is low. The threat of having a phone that behaves differently than "billions of other Android devices", indicating that it's GrapheneOS or some other security-oriented OS, is arguably higher.

Connectivity checks can't possibly be useful, because the network can go down after the check. Then what, the phone explodes?

I'm a little confused: GrapheneOS is the exception; almost every OS successfully implements connectivity checks. Also, the answer to the problem seems obvious: check again. Check every second or every 30 seconds, etc. It's just a ping.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#372
post #370

Earlier quoted context omitted.

Does nobody in the EU do computers ? How do they pass asinine laws like this ? I mean, from the outside, it always appears as though the EU is much better than the US when it comes to consumer rights, but it always feels like they don't have a very good grip on technology.

Where I live, the authentication systems implemented by banks are also used for verifying user identity to various other services, including governmental ones. Basically, there's a common (government-backed) user identification system which hooks up to interfaces that banks provide. When you're logging in to an online service that requires strict identification of the user (such as ones that would require an official…

> Where I live

Do you live in Denmark perchance?

> I don't know if this is a common thing in other European countries

There is a similar system implemented in Poland and works very well.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#373
post #256

Earlier quoted context omitted.

I was wondering if you could expand on your comment because I am confused. How is seeing what IP addresses an app communicates with a violation of GDPR? If I can't see the content of the data it's sending but just where it's going, that is not exactly a violation. It's not illegal to communicate with an IP address, there could be many reasons $app sends a request via a US server. Like a postman with an address and an…

Install the app. You'll see that it sends personally identifiable information (your ip address) to facebook, before you have opted in. 99% of apps also send usage stats and/or crash information to mixpanel, etc. also without opt-in.

If you use any service, sending your IP is mandatory. That's how the internet works...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#374

Earlier quoted context omitted.

Hi! I have a Samsung and I looked around online and couldn't find any real info on this topic. I don't doubt it's quite possible, but where is your source from? It's been hard for me to confirm. A good point, though, I'll look at the open source options....

Samsung's own privacy policy and those of the 3rd parties they use. It's been over a year and checking now some things have already changed, but if you click on the gear icon from within the keyboard you can select "about sumsung keyboard" which should give you a list of policies including gify and tenor (both used for gifs I guess) but i didn't even check those. The one you want is the legal info which tells you tha…

This is super brilliant thank you. I have never personally done that much searching through the EULA / Privacy Policy. I'll take a deep dive and look for alternatives.

Samsung could really make some advances on Apple by just being more clear on these aspects of their data collection. Even if they just said "We want to collect your data, but it's YOUR data, so we will always ask for your permission, and in case you are wondering what we collect, you can find it all here..."

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#375
post #299

Earlier quoted context omitted.

Samsung's own privacy policy and those of the 3rd parties they use. It's been over a year and checking now some things have already changed, but if you click on the gear icon from within the keyboard you can select "about sumsung keyboard" which should give you a list of policies including gify and tenor (both used for gifs I guess) but i didn't even check those. The one you want is the legal info which tells you tha…

They specifically ask you when something like that is being used. And I don't think giffy or others are receiving your emails. This is probably just usage stats, but someone needs to check that. Windows 10 start menu on the other hand send every keystroke to bing. You cannot turn it off either

But this is all speculation no? The privacy policy is concrete...

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#376
post #347

Earlier quoted context omitted.

Nah, it's not about having strong options. I've been around nerds forever, that doesn't bother me. Yours might be the impression on recent HN, but if you look around he is all over the place, attacking people on various platforms, while promoting some conspiracy narrative; derailing, gaslighting and manipulation. Whatever is going on with that guy, something is definitely going on. He doesn't inspire trust, he probab…

Micay started working on the project and got some funding from copperhead os, with the plan being that the company could provide paid support and the like. But copperhead os broke its promises and basically hijacked the project - but Micay being a professional, he invalidated the validation keys so that existing users would not get served code not associated with him. Afterwards he continued working on the open sourc…

That's what I believed until I had a direct (online) conversation, which got unpleasant very quickly. Maybe there is a grain of truth in there, but I am more inclined to think it might at least be exaggerated by a lot.

Re: Android phones are sending significant amount of user data with no opt-out [pdf]

#377
post #325
post #257

Earlier quoted context omitted.

It is not controllable at all: It still enforces any app author's will against the user's. Root is not offered, and the grapheneos maintainer seems to be personally offended by the thought that root could be helpful.

>enforces any app author's will against the user's I'm not sure what you mean by this. All apps run in a sandbox and you can deny permissions if you like. >Root is not offered Root access on Android is a security hole.

What I mean: I cannot see the app's files, I cannot edit them, I cannot backup the app locally, only by uploading data unencrypted to googles cloud. Adb backup was unreliable in the past, could be switched off by the app against my will, an is deprecated anyway. I cannot screenshot an app if the app doesn't want me to. I cannot block ads properly, only via some fake VPN app, but then I cannot use an actual VPN at the same time. I cannot firewall an app, except with a hack using another fake VPN app. I cannot disable an app into background. I cannot give a fake GPS to an app. I cannot have f-droid auto-update my apps. All of these things I should be able to do, but the anti-user "security" enforces this against me, actually hurting my security in order to make googles and shady app vendor's business models possible. And then they claim it's for my own good. A lot of the "root is bad mkay" is fueled by this more or less hidden agenda. That it helps to idiot-proof devices is a nice side effect only. Historical proof of this hypothesis is: When TCPA was first introduced it was explicitly made for DRM. People fought it a lot, so today they are introducing it disguised as security measure.
Post reply on HN