7 ms·
You can't trust Amazon Underground
- deleted 11y ago[deleted]
- seanwilson 11y agoSo the Amazon Underground tracking requires location tracking as well? If it was just usage tracking I don't see an issue with it seeing as Amazon Underground is meant to be optional and you get free apps in return.
- nharada 11y agoI too am unclear on whether or not the location tracking was related to the usage tracking. Usage tracking is basically the entire point of Amazon Underground.
- seanwilson 11y agoI'd be against high precision location tracking being required but city/country level wouldn't bother me.
- taneem 11y agoNo it does not. It only requires usage tracking to pay the developer for time used.
- seanwilson 11y agoNot disagreeing but is there a link that describes what's tracked and will always users see this? They definitely mention usage tracking in the developer documentation. Maybe I'm missing it but I can't see a mention of usage tracking for their main Underground links, just that apps are free: https://www.amazon.com/gp/feature.html?ie=UTF8&docId=1003016361 https://www.amazon.com/gp/feature.html?ie=UTF8&docId=1003016... https://www.amazon.com/b/ref=rw_tiny?_encoding=UTF8&node=9530541011 https://www.amazon.com/b/ref=rw_tiny?_encoding=UTF8&node=953...
- detaro 11y agoSo what is "data tracking"/"usage tracking" and how is it turned off/blocked on the authors device? As far as I know Cyanogenmod only blocks some APIs like location, contacts
- HappyTypist 11y agoIt is an option you can enable / disable on the Underground app.
- BrandonSmith 11y agoAny application can request the permission to track certain Android app lifecycle events. In this case, when an app gains and loses foreground focus. Data and location API access are separate permissions. But if all three are obtained, fairly detailed correlations can be made. Although I don't know much about Cyanogenmod, it is likely it enables global toggles for the app lifecycle permission.
- nameoda 11y agoAmazon Underground pays the app developer for the duration of usage of the app, and so needs to track how long you are using the app for. Perhaps it needs data tracking enabled to identify the duration of usage?
- GavinMcG 11y agoDid you read the screenshot? That's exactly what Amazon says it needs data tracking for. (For those who haven't read the article: The author only discovered this because they have CyanogenMod and a permissions blocker installed and in use. Most people wouldn't be told they were being tracked.)
- kevb 11y agoIt's actually just a setting in the Amazon Underground app to disable tracking of apps. The "actually free" apps require the setting enabled. He disabled it and it's telling him that. The CyanogenMod/Privacy Guard/Location stuff is all unrelated.
- fenomas 11y agoI can't see where the article's scary headline is justified. It appears that all that happened is, he used this service without knowing it was based on tracking app usage, and was surprised when he found out.
- jessriedel 11y agoAgreed, but it is pretty surprising, and most people will have no idea this is what's going on. I couldn't find it mentioned on the Amazon Underground homepage: https://www.amazon.com/gp/feature.html?ie=UTF8&docId=1003016361&ref_=mas_surl_undrgrnd https://www.amazon.com/gp/feature.html?ie=UTF8&docId=1003016...
- 13of40 11y agoWeb apps know when and how often you use them, too. As long as Amazon Underground tells you in its TOS I don't see a lot of difference.
- gruez 11y agoYeah, but do web apps lock you out if you deny their location requests?
- terinjokes 11y agoI've attempted to use a couple that have done so.
- deleted 11y ago[deleted]
- CrowFly 11y agoSince Amazon is telling you exactly what they're doing, it seems to me that you can trust them. You simply decided to opt out.
- venomsnake 11y agoCan't you feed it fake data?
- victorhooi 11y agoWhat is the fear here? I'm not talking about shady apps you downloaded off some dodgy pirated Android app store, or apps where you agree to this sort of tracking so you get free apps (e.g. Amazon Underground, which the author is using). I mean - official apps such as Twitter, Snapchat, or say Microsoft or Google applications. Can anybody quantify what they are scared of, if an app tracks how often you use it, or collects anonymised metrics?
- pipermerriam 11y agoThis sounds awful similar to the "Nothing to hide argument". People have a right to privacy and shouldn't have to provide a reason why they deserve it. Tracking should always be opt-in. https://en.wikipedia.org/wiki/Nothing_to_hide_argument https://en.wikipedia.org/wiki/Nothing_to_hide_argument
- victorhooi 11y agoThis isn't so much about nothing to hide - but more about doing a costs/benefits analysis. I mean - most people here use webapps - whether it's HackerNews - or more mainstream ones like Reddit, Instagram etc. We assume that the webapp developers know when we use their services - after all, it's hosted on their servers. If you were super paranoid, you could run your own "cloud" services - your own email service, your own document sharing service, your own image sharing service etc. However, for most people the cost/benefits analysis simply isn't worth it. Apps like Twitter, Instagram, Google Docs, GMail etc are popular precisely because people figure the utility outweights any "fears" they might have over those scary developers tracking their usage. In a comment above, I provided a concrete example of where telemetry data is useful: "I worked at a trading company before, and one of the reasons we pushed out telemetry was due to user's feature requests - users would request features, and we wanted to see if they were actually using them, so that we could prioritise developer time accordingly." Or the same reason most people don't use encrypted email (currently). I mean, come on - you're storing your data on their servers - there's got to be some trust there. So my question remains - what is the fear here?
- eps 11y ago
- peteretep 11y agoI love that Apple is run by a man whose pretty vanilla personal life would get him harassed by the security apparatus of lots of countries -- it really gives me faith that Apple make a good faith best-effort to protect user privacy in their walled gardens.
- Anon1096 11y agoI have Xprivacy and Cyanogenmod's privacy guard, and also use the Amazon Underground store and apps. I can tell you that with location, contacts, and most other permissions blocked the apps work just fine. So whatever the author did to get this result, it isn't from blocking permissions. It also seems strange that someone who cares so much about his privacy doesn't have xposed with Xprivacy, because then he could have spoofed the data instead of having to block it all together.
- dajbelshaw 11y agoHey, OP here. Thanks for the mention of Xprivacy - I wasn't aware of it. :) Like everyone else, I'm always learning. Just sharing this post for others who weren't aware of Amazon's business model here (which does seem somewhat hidden).
- zobzu 11y agoits a setting in the amazon app, to enable tracking. it doesnt mean it'll be able to track, but it'll work.
- mtgx 11y agoUsing Xprivacy probably means you're giving up a significant portion of your security for increased privacy. When you are rooted and your bootloader is unlocked you're more exposed to hacking and malware. Also, last I heard the most popular root application by far (SuperSU) was silently acquired by a Chinese company. I'm not saying you shouldn't use Xprivacy or other root-enabled apps, though, as some are very useful and it may be the only way to get Google to build in some of those features eventually, but just be aware of the trade-off you're making.
- dannyrosen 11y agoWould you mind providing references to these claims?
- xorcist 11y agoI thought "rooted" in the Android sense just meant that you had sudo installed. Why would malware be helped by having sudo installed? A privilege escalation attack has no use for it, unless you think there are security holes in sudo. Has there been or do you have reason to believe there are? I heard these statements before and I'm never sure what to make of it. For a casual user, the possibility to click yes to a sudo dialog is a code path to disaster, but as these things need to be flashed specifically (which is a big hurdle in itself) I'm not sure how big problem it is in practice.
- mesozoic 11y agoIf you actually research it at all they're very clear that they track users time spent in each app as that is how they pay developers.
- dovdov 11y agoFree has a price.
- j4kp07 11y agoIt's a FREE app. If you don't like it, don't agree to the terms and quit using the app.
- dajbelshaw 11y agoIndeed, and that's the case with everything - Google, Facebook, Twitter, etc. I get it. My point in this post is that I (who am interested in privacy and rights online) didn't realise what was going on, how is Joe Average going to know?
- iainmerrick 11y agoAmazon aren't being particularly underhand here; a tiny bit of googling will explain how Underground relies on app usage tracking (not location tracking). I agree that "Joe Average" may not question the free lunch, and that's a problem, but it's exactly the same problem as existing free apps like Gmail, Facebook, etc. If you're a technical person with an interest in privacy issues, you need to pay a bit more attention.
- dajbelshaw 11y agoCheers. :)
- pmarini01 11y agoReplace Amazon Underground crapp with the regular Amazon Appstore: http://www.apkmirror.com/apk/amazon-mobile-llc/appstore/ http://www.apkmirror.com/apk/amazon-mobile-llc/appstore/ Disable "Collect App Usage Data" from settings, install apps, enjoy.
- huac 11y agodoes the regular Amazon Appstore have 'free' paid apps?
- xorcist 11y agoThere is a desktop client for Play store called Racoon. When I used my phone for several years without a Google account, from time to time I would need some app (for taxes, bankning, public transport, whatever) that was distributed via the Play Store exclusively, but I had no problem downloading that APK using Racoon and installing it separately. You don't get notified of updates, and updating is a manual process, but for for a single user that wants to avoid the Google services it's workable.
- smt88 11y ago> You don't get notified of updates, and updating is a manual process That's a lot of extra work, but it's also a huge security problem. Is it really worth the extra privacy? After all, you can't really hide yourself from Google because they index the entire web and public databases and your friends' emails...
- rsync 11y ago"That's a lot of extra work, but it's also a huge security problem." What is the security problem ? Simply missing updates that might fix vulns ? Genuinely curious...
- smt88 11y ago> Simply missing updates that might fix vulns Yes. A huge amount of hacking is only possible because software is out of date.
- xorcist 11y agoThat's the question. I think it depends on why you didn't want to install the Google Services in the first place. I mostly didn't want the remote wipe and remote code execution privileges the Google Services come with. It wasn't primarily a question of privacy as such. I doubt the security problems are huge. Most userland apps run as a dedicated user. Security problems with the Google Services are potentially much more serious.
- enig_matic7 11y agoThis happened to one of my mates: 1. Ordered some stuff from Amazon using Tor 2. Amazon tracked the change in IP 3. Amazon automatically cancelled the orders and sent a password reset email saying his account may have been compromised
- anc84 11y agoSounds like bad OPSec. If he used his normal account via Tor he identified himself towards Amazon. Amazon checking against a list of Tor exit nodes and warning customers is a good thing. I say that as a Tor lover.