It is incredible to me that location data harvesting (aka mass dystopian surveillance) is so pervasive that it requires a crowd-sourced investigative campaign. A generation ago it was neither technologically nor socially feasible to get even coarse-grained location data on a person's whereabouts.
I hate this future. We sleepwalked into dystopia because money.
Well some way along capitalism it was "found" that it's more effective to spend the money you could use to improve a product to actually brainwash people into buying the product (what would be ads here).
Ultimately it's also our, the "mass consumers" fault for behaving this way, and for not upholding a certain value regarding choosing a more quality-oriented product/service.(and i might add: consuming less instead of more frequently)
It's not really a fault of "capitalism", just reflects the commodity some people fall into.Ads were always there,and they always be, we just massively expanded the information mediums where ads could be implemented.
Folks think advertisements are "showing me something I can buy"
But really ads are a huge detailed dossier on every person, being sold so that water filter companies can bid the highest to get a water filter ad in front of the people with the largest income.
Meanwhile, you like legos and lego will never be able to bid high enough to show you a lego ad (probably they don't need to anyhow)
and the off-label uses for these dossiers... I wonder if used car salesmen can find out your "price insensitivity" and charge accordingly?
I'm not sure how true that is for advertisements. For example, there are many forms of 'hidden' advertisements that are designed to not be seen, and yet influence people. Among them are product placements. Heck, even Hacker News is an advertisement for YCombinator, though it certainly isn't seen that way by many people.
Comments like this are a weird form of semantic catnip nerd sniping that unproductively derails the discussion. "We should ban tall buildings." "Oh yeah? Well define exactly how tall a tall building is." Clearly there's a thing as an ad, because it's a common word everyone understands. If your point is that it would be hard to pin down the part of that that's actionable, well of course. It's always hard to get regulations right.
It's important to practice like you play the game (we should debate the way we want the regulations to read, if we stand a chance of ever being represented).
Democracy doesn’t work and populism is a scare word. Bet on elite outrage or accept the future only a few sagacious, disregarded malcontents warned us about.
I don't know about the sleepwalking part. I'd say we sprinted towards it. We've had dystopian scifi for much longer than we've had the tech, but the reality makes some of the scifi authors look like they didn't have much of an imagination. Now that we've seen some of the "tech", the modern dystopian scifi like Black Mirror scares the bejeebus out of me. There's somebody out there that sees Black Mirror episodes and thinks "YES!! That's exactly what we need!" Except, we have the tech to actually do some of it.
The app stores typically tell you what permissions an app requires, including location.
It would seem to me to be more efficient to programmatically analyze the permissions listed of the top 10,000 apps (or more) than have readers send in random screenshots.
> This will help us understand how these prompts are worded and could help us identify apps that are using your location in ways the app developer does not disclose.
They are specifically interested in how the location request is worded for each app, and maybe at what point during usage it asks. I think on Android the prompt is always the same, but apparently on iPhones they can add a short explanation.
You would get a lot of false positives, meaning apps that legitimately need the location. For example navigation apps or unfortunately apps on Android which use Bluetooth.
This really annoys me, because the dialog looks the same for apps that want to use GPS data and apps that use Bluetooth, and there is no way to grant just Bluetooth permissions.
Yes, and the same goes for information about the WiFi network. Lots of apps for IoT devices require this information to set up products, but the OS presents this as location tracking.
This is fixed in Android 12, BLE and Location are properly disconnected now. The permission dialogue reads “determine relative position of nearby devices” if you request BLE access.
You can also declare that your app “never needs physical location”, which excludes BLE beacons that could be used for that purpose from the data the app receives.
The problem, and one of the reason those permissions were together, is that BLE by itself is enough to get your coarse location, like WiFi is. If you are offline but can detect the bluetooth device A and B, and another internet device can see the devices A and C, then it's ease to conclude that you, the internet device, as well as the devices A, B and C are all in vicinity of each other. It's good that the precise location permissions are separate from Bluetooth permissions, but people need to understand this.
And what do we do with apps which have a legitimate reason to use your location, then proceed to sale your location history to third parties? No confirmation dialog can save us from that.
Yeah but that’s not enough, I thought? Wasn’t there that scandal where Uber figured out your location anyway from the WiFi access points you were near?
Those kind of trendy free apps, like photo filters, sticker makers, etc are usually the worst offenders. I mean, how else do people these companies make money? Android and iOS need to implement network connection permissions per app, but they won't because they both have an incentive against doing that.
Having a database like this is useless unless the masses start to care about the subject. There has yet to be a campaign successful enough in educating/convincing the masses into why this is a bad thing. For most, as long as the app allows them to communicate with friends, entertains them (or their kids) with a game, etc, and the app is free the masses just won't care.
You should reflect for a moment about how you are fortunate enough to live in the first generation where this is qualifies for being "sad and horrible".
I really support this. We need clarity on which offending apps are doing this. And it isn't just location data. It's also apps which added a proxy backdoor powering networks like BrightData or OxyLabs.
Or Contacts app that sell contact information to companies like Lusha.
It's not just apps, it's the providers themselves. e.g. Sprint sells customer location/app/usage data directly [1]. They don't even try to obscure that fact.
> "Leveraging verified, first-party mobile data from more than 32 million mobile users straight off the network"
The only solution to this is legislation. None of the politicians seem to care, I wonder why (follow the money... both sides of the isle are paid off).
The expression is both sides of the aisle since traditionally each party sits on its own side of the legislative hall. I like this use however since it suggests they are all off on an island separate and distant from the rest of us.
A friend introduced me to localblox.com a couple years ago to get some company data, though it looks like they have already closed up shop.
These guys seemed to have everyone's data. The demo started off by showing me the company data we were interested in, but then veered into picking a random person's life to delve into.
The deep dive began by showing work/education info, then went into where they live, the cars they drove, how many kids/pets, then even deeper into the location data...
They showed detailed maps of everywhere they went on a daily basis. The routes they took to work, they places the visited, etc.
Any of the data was for sale if we wanted it. It was beyond disturbing. We obviously passed on working with them.
Is there a way to examine the libraries that an iOS app uses? There might be a way to find apps that use common libraries/frameworks that pass your location to other services, if so.
Excellent thinking! These are the SDKs to worry about. Next is, who do they ‘phone home’ to?
An easy way to find things is with a local proxy or DNS log, as your phone looks up things on behalf of apps. Which things are looked up by more than one app?
The article seems to make the assumption that this data is collected by apps that would otherwise have no good reason for requiring permission to access your location. Seems like a bit of an assumption.
It strikes me that to build a useful location dataset, just one widely used app would be more effective than any number of niche apps asking for strange permissions. I would build an app that provides many people with a really useful service that obviously requires access to your location. So it would probably provide some sort of mapping or navigation service. To consistently collect data it might well force the user to have data enabled rather than just hold the map data on the phone.
Perhaps I could also shut others out of this lucrative operation, if I could just get my app pre-installed and enabled by default on every phone.
42 comments
[ 3.0 ms ] story [ 79.0 ms ] threadI hate this future. We sleepwalked into dystopia because money.
We should just ban all ads. That would solve all of these problems.
If people feel they still need ads, we can create a nice sandbox for watching ads.
Ultimately it's also our, the "mass consumers" fault for behaving this way, and for not upholding a certain value regarding choosing a more quality-oriented product/service.(and i might add: consuming less instead of more frequently)
It's not really a fault of "capitalism", just reflects the commodity some people fall into.Ads were always there,and they always be, we just massively expanded the information mediums where ads could be implemented.
Please define what an ad is.
But really ads are a huge detailed dossier on every person, being sold so that water filter companies can bid the highest to get a water filter ad in front of the people with the largest income.
Meanwhile, you like legos and lego will never be able to bid high enough to show you a lego ad (probably they don't need to anyhow)
and the off-label uses for these dossiers... I wonder if used car salesmen can find out your "price insensitivity" and charge accordingly?
I made this comment[0], where I talk about "building buzz."
Basically, ads without ads.
[0] https://news.ycombinator.com/item?id=28788169
[0] https://en.wikipedia.org/wiki/I_know_it_when_I_see_it
Higher screws up light.
It's important to practice like you play the game (we should debate the way we want the regulations to read, if we stand a chance of ever being represented).
Its just mind boggling that society can self-devour in this way, but apparently its part of "how things work"
It would seem to me to be more efficient to programmatically analyze the permissions listed of the top 10,000 apps (or more) than have readers send in random screenshots.
They are specifically interested in how the location request is worded for each app, and maybe at what point during usage it asks. I think on Android the prompt is always the same, but apparently on iPhones they can add a short explanation.
This really annoys me, because the dialog looks the same for apps that want to use GPS data and apps that use Bluetooth, and there is no way to grant just Bluetooth permissions.
It might still make sense to split these permissions, but it should be clear that you're giving up your location.
You can also declare that your app “never needs physical location”, which excludes BLE beacons that could be used for that purpose from the data the app receives.
https://developer.android.com/guide/topics/connectivity/blue...
Or Contacts app that sell contact information to companies like Lusha.
> "Leveraging verified, first-party mobile data from more than 32 million mobile users straight off the network"
[1] https://www.inmobi.com/company/press/inmobi-acquires-u.s.-ba...
The expression is both sides of the aisle since traditionally each party sits on its own side of the legislative hall. I like this use however since it suggests they are all off on an island separate and distant from the rest of us.
These guys seemed to have everyone's data. The demo started off by showing me the company data we were interested in, but then veered into picking a random person's life to delve into.
The deep dive began by showing work/education info, then went into where they live, the cars they drove, how many kids/pets, then even deeper into the location data...
They showed detailed maps of everywhere they went on a daily basis. The routes they took to work, they places the visited, etc.
Any of the data was for sale if we wanted it. It was beyond disturbing. We obviously passed on working with them.
An easy way to find things is with a local proxy or DNS log, as your phone looks up things on behalf of apps. Which things are looked up by more than one app?
A few I noticed back in 2019:
Then you can also see who is invoking them coming from the domain tree:- https://securitytrails.com/list/apex_domain/app.link (2962)
- https://securitytrails.com/list/apex_domain/onelink.me (998)
- https://securitytrails.com/list/apex_domain/bttn.io (60)
It strikes me that to build a useful location dataset, just one widely used app would be more effective than any number of niche apps asking for strange permissions. I would build an app that provides many people with a really useful service that obviously requires access to your location. So it would probably provide some sort of mapping or navigation service. To consistently collect data it might well force the user to have data enabled rather than just hold the map data on the phone.
Perhaps I could also shut others out of this lucrative operation, if I could just get my app pre-installed and enabled by default on every phone.
Just speculating - who really knows.