7 ms·
Smartphone Apps Are Filled With Trackers
- tomrod 7y agoAnd I for one am tired of it! How much would it cost me to have a phone with all trackers turned off? (Or, perhaps, routed through a core application that requires whitelisting?)
- criddell 7y agoIt's not possible. Even a wired landline phone generates data that the telecom companies take advantage of. The closest you could get would be to buy burner phones with cash.
- lucb1e 7y agoYou're approaching it rather theoretically. Yes, even a landline generates data and metadata, but do you feel watched when owning a landline the same way as when you see that you have like three different companies tracking you in every app or website?
- criddell 7y agoI think some people feel a landline is better as far as surveillance goes, but I think that comes from back in the day before telecom companies realized that they were sitting on a goldmine. Today, every part of your interaction with any telecom company is monetized.
- lucb1e 7y agoMaybe that's my European view on things, but I doubt that. They would have to tell me in the privacy policy that they share my phone records with third parties, with which category of companies they share them, and for what purpose. Moreover, after moving to Germany and getting a phone bill twice as high as I expected the first month, I could not even get my records to check what I was being billed for, because I did not opt in to storing that data. They (said they) didn't have the data because I didn't ask them to store it. It wasn't a large enough amount (by far) to take it to court, though, so I can't know for sure, but lying about not having the data and keeping it secret when hundreds of employees are in the know (if they are indeed selling it, or at least a handful of employees if it's just storage for billing) sounds rather conspiratorial. A little like dieselgate, so I'm not ruling it out as possible, it just seems very unlikely.
- criddell 7y agoI was definitely speaking from a US perspective. I would be so happy if the US would start doing more to lock up user data. We already protect health data (HIPAA) and I think it would be a great idea to extend that to all data connected with an individual or account.
- maxaf 7y agoRunning a persistent VPN to a pihole that’s constantly updated with new trackers as they come online seems like the only viable option.
- rrix2 7y agoIt's amazing how different my phone feels since I've set up Wireguard to a server I have set up a few milliseconds away from me and put a pihole at the end of it, too. Blocking the (web) trackers at their source, coupled with less "wake up the radio to make this network call" is really quite nice, and the in-app advert spaces don't load except for a handful of folks doing (reasonable) native advertising.
- angott 7y agoWouldn't you still have to wake up the radio to perform the (pi-holed) DNS lookup, though? Just curious because I would love to use a similar kind of system, but I am concerned about battery life.
- sjy 7y agoI've been doing this for a few months now and the impact on battery life is noticeable but acceptable to me. iOS reports that WireGuard was responsible for 8% of my battery use today.
- ignoramous 7y agoAre you on Android? Use Firefox with NoScript or uMatrix (also as your default webview) and setup AdGuard DNS [0] or a pi-hole. You could consider using a VPN like Orbot (free Tor-as-a-proxy) [1], PerfectPrivacyVPN (supports multiple exit IPs, multiple-hops, and server side firewall) or set one up using Algo/Streisand [2]. If you do not want to root your device: 1. Install NetGuard or No Root Firewall to view what's going on from network perspective. 2. Install ExodusPrivacy to generate a report on apps wrt sdks in use by them. --- If you are okay to root the device: 1. Install XposedMod, and then XPrivacyLua module, and work through the options. --- If you're okay with flashing a ROM: 1. Consider LineageOS + microG 2. If you are using Pixel, consider ChromeheadOS (edit: CopperheadOS) [3]. --- If you're okay with a new device: 1. Consider purchasing puri.sm Librem 5. --- [0] https://news.ycombinator.com/item?id=18788410 https://news.ycombinator.com/item?id=18788410 [1] https://guardianproject.info/apps/orbot/ https://guardianproject.info/apps/orbot/ [2] https://github.com/trailofbits/algo https://github.com/trailofbits/algo [3] https://copperhead.co/android/ https://copperhead.co/android/
- mindslight 7y agoIf you're worried about flashing your device, go spend $100 on a device off the LineageOS list of supported devices, and experiment with that instead. The odds are it'll go fine and you'll be happily using it three months from now.
- kzcqt 7y agoI think in 2019 it's practically impossible to completely brick a mobile by flashing wrong stuff on it.
- ignoramous 7y agoTrue, not because it's 2019 but due to Project Treble's GenericSystemImages that cleanly separate OEM (Samsung, Sony, Lenovo) and silicon-vendor (Broadcom, Qualcomm, Mediatek) related blobs from the Android subsystem, such that the Android bits could be changed or updated independent of vendor support. https://android-developers.googleblog.com/2018/11/an-update-on-project-treble.html?m=1 https://android-developers.googleblog.com/2018/11/an-update-...
- izacus 7y agoIt'll cost you all your apps - it's the APP DEVELOPERS who are putting those trackers in and you'll need to give the apps up to get rid of them.
- AznHisoka 7y agoApple seems to giving the appearance they are doing something about it. They claim they will remove apps that sell your location data. However Foursquare is still in the App Store, so we can’t take their claims seriously yet.
- willstrafach 7y ago> They claim they will remove apps that sell your location data They most definitely do not remove such apps. Use an app like Charles Proxy or Burp Suite to inspect the traffic of your phone when running the “Perfect365” app. It is really remarkable, and Apple is aware of what they are doing.
- stordoff 7y agoOr we'll pivot back to a paid model, or ads without / with less tracking - I don't think that's a bad trade.
- TeMPOraL 7y agoThe trust has been broken. There needs to be a way to make sure this is a transition to "paid, no ads/tracking" and not "paid plus ads/tracking". One interesting side effect of GDPR is the surprising amount of PC games - games for which I paid price that's presumably profitable to the authors - that started throwing up consent forms.
- pergadad 7y agoI just installed exodus and noticed plenty of the app's I paid for still have trackers...
- deleted 7y ago[deleted]
- Balgair 7y agoSilentPhone, formerly BlackPhone, does a decent job: https://www.silentcircle.com/products-and-solutions/silent-phone/ https://www.silentcircle.com/products-and-solutions/silent-p...
- nukeop 7y agoJust don't use smartphones, don't use Google, don't use Facebook. Problem solved.
- driverdan 7y agoRooted Android + AdAway = problem mostly solved. Never buy a phone you don't have root access to.
- nrjames 7y agoThere’s a lot of scaremongering in here. I fully support giving users full privacy controls. However, both Android and iOS allow you to toggle off availability of your Advertising ID. That’s been in there for years. Turn it off and apps can’t grab it (they get 000000000). Each vendor gets a vendor-specific ID on iOS, shared between that vendor’s apps. Delete all vendor apps and it resets. I’m not saying this is an ideal situation by any means. However, it’s just two small examples that are ignored by this article.
- kennywinker 7y agoThat does not help if you’ve identified yourself to the app. E.g. if you logged in via facebook, then any in app trackers can link your activity to your facebook account.
- mthoms 7y agoI recently installed a dating App that required authentication via Facebook or SMS. I chose SMS (because screw Facebook). But lo and behold, it turns out the App developer uses Facebook's SDK for the SMS verification anyway. And since FB has my phone number from the two factor scam [1] it pulled, it really made no difference. Not cool. [1] https://techcrunch.com/2019/03/03/facebook-phone-number-look-up/ https://techcrunch.com/2019/03/03/facebook-phone-number-look...
- ignoramous 7y agoThis is relentless from Facebook. Consider the fact that they own WhatsApp, it is pretty much "no where to hide" scenario here even for folks who have no Facebook account. Jaque y mate. Oh, how I wish WhatsApp was an independent company. I am sure Jan Koum and Brian Acton think so too [0], despite making billions off its sale. [0] https://www.businessinsider.in/Heres-The-Inspirational-Note-That-The-WhatsApp-CEO-Keeps-On-His-Desk/articleshow/30698071.cms https://www.businessinsider.in/Heres-The-Inspirational-Note-...
- skinnymuch 7y ago
- AngryData 7y agoAnd yet IM the crazy one for still using a flip phone!
- Godel_unicode 7y agoYes. You are.
- chillacy 7y agoDo you also not use a “rewards membership” card at grocery stores where you get charged extra to not be tracked?
- RandomBacon 7y agoCorrect. I opt out of membership savings and credit card rewards by using cash and not using membership cards or giving out phone numbers. (not the grandparent, but that user is not alone)
- AngryData 7y agoPeople actually use those? I use cash for 95%+ of my purchases, the exception is ordering it direct from China.
- mindslight 7y agoI'm moving towards simply having more devices, partitioning their uses. A decent tablet is a mere $50 (eg flo) and a good phone is a mere $100 (eg herolte). It's easy enough to have eg two phones - a main one with FDroid only, and a secondary off-most-of-the-time one with YALP store convenience apps. Tablets you can diversify even harder because you don't have to carry them in your pocket.
- cptwunderlich 7y agoSo what? They can still track you across devices. Especially if they use some 3rd party ad SDK, which might use the Google advertising ID, or some other identifiers.
- criddell 7y agoIf you use them to connect to your home wifi then they show up on the internet with the same IP. It's very easy to connect separate devices to a single user.
- mindslight 7y agoModern tracking is fundamentally a product of executing hostile code on your own device. The idea is to never put apps that have built in or will otherwise facilitate surveillance on the more secure devices. This includes a javascript browser, due to its unwieldy attack surface. Separate devices draw a line in the sand, rather than just accepting amorphous insecurity as inevitable. And then you can work on slowly moving your usage patterns away from the surveillance-foregone devices.
- clubm8 7y agoI've moved more and more browsing to Tor. I have this HN account, a Reddit account, plus a few others. It's possible to do a large chunk of my browsing in Tor, though it's slow and sometimes pages render oddly without Javascript, so it's a bit annoying. But I like the feeling of not being tracked.
- ShorsHammer 7y ago
- askafriend 7y agoOk...let me try. “Physical retail stores and loyalty programs have trackers you know nothing about.” Am I doing this right? I feel like a deeper point needs to be made to justify these headlines. The conversation needs to evolve and get more nuanced.
- smudgymcscmudge 7y agoWalmart greeters have built-in facial recognition abilities. I didn’t believe this until one started greeting me by name after a few interactions.
- deleted 7y ago[deleted]
- Jerry2 7y agoIs there a way to check what trackers/libraries/"kits" an iOS app uses? I don't use many apps on my iPhone and most of them don't have background & location rights so I'm not that worried but would still like to know what they send back...
- layoutIfNeeded 7y agoYou can try MITM-ing via Wireshark or Charlesproxy but it won’t let you look into the packets if they’re using certificate pinning.
- willstrafach 7y agoA surprising number of trackers do not use pinning, so this has a pretty high success rate actually.
- lucb1e 7y agoExodus can detect a number of them: https://exodus-privacy.eu.org/en/ https://exodus-privacy.eu.org/en/ By installing their app, you can see the trackers for each app that you have installed. If you use Yalp store (an open source front-end for the Play Store), there is also a button to view trackers for each app. Edit: just saw that you're on iOS. This is probably not allowed by Apple, so I guess there will be no alternative.
- willstrafach 7y agoWorking on this. It is very tricky to do for iOS in an App Store compliant manner, but doable. Apple has already approved it.
- tombrossman 7y ago> Working on this. It is very tricky to do for iOS in an App Store compliant manner, but doable. Apple has already approved it. This is very welcome news, please do a "Show HN" or post a link to the announcement when it's ready. For now, before I install an iOS app I run the Exodus Privacy tool on the Android version and must assume the same trackers are present on both platforms. What is worse, Apple fail to label which apps contain ads in the store so I can't even tell which ones are adware before installing (apps with ads are clearly disclosed in Google Play).
- xfitm3 7y agoSmartphone baseband blobs are also something we know nothing (or very little) about.
- nyolfen 7y agoon ios, if you have a pihole set up, you can use dnscloak[1] to block advertising and tracking servers. (alternatively you can use one of the servers listed in the app by default if you care to trust someone else's dns server.) you can set it to 'connect on demand', ie always on mode, at the cost of a bit of battery (not enough for me to be bothered). it acts as a vpn but only for your dns queries. afaik this is the best single step privacy option on ios at the moment. [1] https://itunes.apple.com/us/app/dnscloak-secure-dns-client/id1452162351?mt=8 https://itunes.apple.com/us/app/dnscloak-secure-dns-client/i...
- kmlx 7y agopihole? you have got to be kidding. i’d trust basically anything else than a dns box.
- nyolfen 7y agookay
- snazz 7y agoIf you don’t trust the Pi-hole developers themselves, it isn’t too hard to build an equivalent setup with dnsmasq and your own configuration. Pi-hole does prioritize convenience over security in a number of ways so this isn’t an unreasonable choice.
- revvx 7y agoWhy?
- kmlx 7y agoAll of your traffic, every single DNS query going thru a single unverified codebase off of github? i mean i know regular folk are quite naive with tech. but i hoped us tech people are less so.
- bobbydreamer 7y agoMay be that's why politicians use Nokia 3300
- h1rschnas3 7y agoThat's one of the reasons I use AdGuard on my android phone. No problems with ads and trackers anymore.
- saagarjha 7y ago> Most people use the Google Chrome browser anyway Nope. Safari is by far the most popular browser on iOS.
- deleted 7y ago[deleted]
- dontbenebby 7y agoI know Algo vpn[1] can be configured to block ads with a DNS resolver, but does anyone know it also block trackers? On desktop I use extensions to limit tracking, but it's harder on iOS. [1] https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- novaRom 7y agoWhen someone asks me about what is the most important challenge of this century, I reply: PRIVACY. The way it goes right now shows us very clear sign there will be no privacy anymore. Anything you say or watch is preserved and can be used one day against you. My apologies to all future politicians. It is serious. Porn habits? No problem. Drunk jokes? Will reflect. The way to solve this conundrum is a change of social norms, but it's a long way.
- wavepruner 7y agoThere's a show on Netflix called 'Easy' that has an episode about how the solution to this is changing cultural norms. Specifically, the recognition that we all make these mistakes and will inevitably start forgiving each other. Season 1 Episode 5. Great episode. But yea, it's going to take a long time. And it's going to be a crazy ride.
- Scapeghost 7y agoThis is indicative of a much larger and deeper issue that few people seem to notice: TYRANNY. The people in power can see, learn and know everything about the commoners. But if a civilian tries to dig up something on the oligarchs or plutocrats, they can be made to disappear as if they never existed, unless they had managed to gain some credible attention in the media, but even that will not save them from being isolated, demonized and silenced (like Julian Assange; they even rounded up his friends as a precautionary measure against ""blackmail""). This gradual erosion of individual privacy is feeding into a nigh-inevitable tyranny that will be almost impossible to break out of, save a meteor resetting our fundamentally-flawed society for us.
- ndnxhs 7y agoPrivacy is very important but its just a drop in the ocean compared to environmental disaster. Google tracking you browse the internet seems unimportant compared extinction.
- Nextgrid 7y agoThis raises a question, how much does the cancer that is advertising & analytics consumes in terms of electricity and engineering time that could've been put to better use?
- Pmop 7y agoOne of these days, I took some time to analyze network traffic going out of my phone. I wanted to know what was happening behind. I learned that some apps that I wouldn't think of, such as banking, ISP and credit card, were tracking me and sending information to advertising companies! I got angry at some things. For instance, ISP app should provide me information about data consumption and means to buy more. However, it decided to do more things behind the scenes, in addition to doing the tasks it was supposed to in a overly complicated manner—requests travelled back and forth over multiple servers over multiple companies before it did anything. After this exercise, I realized how great it would be if these companies had to provide a clean and well documented API. Users could implement their own apps, liberating themselves from having to trust their private data and resources to companies that would care less if, if allowed.
- TeMPOraL 7y ago> After this exercise, I realized how great it would be if these companies had to provide a clean and well documented API. Users could implement their own apps, liberating themselves from having to trust their private data and resources to companies that would care less if, if allowed. That's why we don't have those APIs. It's not in the interest of any company to make itself more interoperable. This would allow users to develop ways at getting directly what they want and paying the sticker price, without being exposed to all kinds of garbage. Problem is, this very garbage is an important, and sometimes primary way companies make money. Put another way: most companies aren't your friends, they're here to abuse you. Hold on tightly to the rare ones that are friendly.
- jimjimjim 7y agohey everybody. buy stuff. with money.
- vlozko 7y agoAs an app developer, what worries me if the third party tools we use do unintended tracking. For example, we use Firebase for tracking crashes and knowing which versions of our apps are being used. We’ve also recently started using them for push notification handling for Android streamlining reasons. In one of the apps I’ve worked on we need location permissions to do geofencing but it’s all local, on device stuff. On the same app we’ve also recently added support for adding/removing calendar events. Again, it’s feature we added that’s local-only and theres’s no data transmission associated with that feature. The only tracking we do is our own home-grown solution that we don’t share externally. With all that in mind, I’m curious how much of that data does Firebase, aka Google, share with all the rest of its services. Does enabling location tracking suddenly causes Firebase to report location data without our knowledge? Does enabling calendar access suddenly cause Firebase to read the calendar data on its own and report that, too? I’m not at all accusing Firebase of doing anything without knowledge and maybe it may be a “good citizen” with regards to how it manages and accesses (or doesn’t, even if it can) private data but I’m confident that that’s not the case with every third party tracker.
- deleted 7y ago[deleted]
- willstrafach 7y ago> Does enabling location tracking suddenly causes Firebase to report location data without our knowledge? > Does enabling calendar access suddenly cause Firebase to read the calendar data on its own and report that, too? These are good questions to be thinking about. As for Firebase specifically, I have never seen it automatically collect additional data based on user-granted permissions (at least in iOS apps). However, there may be a few other SDKs with this sort of issue. It is important for app developers to be careful of this. For example, when working on similar location tracking research (see: https://guardianapp.com/research/ios-app-location-report-sep2018/ https://guardianapp.com/research/ios-app-location-report-sep...), I noticed that quite a few prominent apps use an SDK from “Braze” (https://www.braze.com/ https://www.braze.com/), and if location permission was granted to the “host” app, the SDK automatically sends back the user’s GPS coordinates when communicating with the Braze API. I remember at least one such app developer had no idea Braze was doing that and rushed a fix out soonafter to make it stop sending the GPS information to Braze. I hope we see more pressure on analytics companies to offer more open source SDKs instead of compiled binaries and headers. This sort of issue would be easier to spot and deal with, instead of being unsure what exactly the SDK was doing.
- hendrikh 7y agoYou are Right, but XML should also Not be used, and what to consider as Configuration? Maven: Pom.xml as well? JSON is neat, like to use it. Write your own parser to fix Tage issues you see. But in the end: what Format do you propose for config files?
- Jemm 7y agoI have raised the issue of trackers in analytics SDKs on developer forums and the result has invariably been negative towards me. When speaking to friends and coworkers about these issues, the result is mostly people calling me paranoid. Developers mostly don't care as long as they get money. Users mostly don't care as long as they get cheap apps. As a developer who does not use third party SDKs that track users (other than the OS) because I value my user's privacy and realize that many of my users are in places where data is expensive and scarce, I sometimes feel like I an engaging in a futile and unwanted effort.
- Buetol 7y agoSince it's not yet mentionned, here's an alternative: > The Librem 5 represents the opportunity for you to take back control and protect your private information, your digital life through free and open source software, open governance, and transparency > As a social purpose company, Purism believes building the Librem 5 is just one step on the road to launching a digital rights movement, where we—the people—stand up for our digital rights, where you place the control of your data and your family’s data back where it belongs: in your own hands. Let’s declare, “We will no longer allow unfettered access to our photos, videos, email, text messages and application and usage data without our permission.” https://puri.sm/products/librem-5/ https://puri.sm/products/librem-5/