Why does Google Play need constant GPS?
theregister.co.uk
theregister.co.uk
You can, of course, switch off location for google maps on android, and I'm surprised this article wasn't fact-checked for that. Settings->Apps->Maps->Permissions. Same as any other app.
I'm assuming the confusion is because the 'location settings' option in maps settings takes you to the phone's global location settings screen, which does only offer a global toggle. I don't think there's anything nefarious there, it's just that the settings menu isn't terribly well thought out.
disclaimer: googler on maps, but not android maps
edit: The article has been updated and now reads: "Although it makes far more sense for Maps to have access to your location, the latest build doesn't give you a decent option of turning it off. If you do cut off Maps' access to your location, "basic features of your device may no longer function as intended," the operating system warns."
Not that they've bothered to update the rest of the article.
[0]: http://forum.xda-developers.com/android/apps-games/app-micro...
For that matter, it'd be nice if I could stop certain apps from running in the background at all. A task killer isn't the answer here - a few seconds is enough to gather some data and transmit it, and at that point the damage is done.
What would be interesting IMO were some way to see which app has registered which intents and possibly an option to override those registrations.
When the app goes into the background the system invalidates the token, so any work waiting in queue somewhere will actually fail on the token check when it comes up.
If you want to ask a background service (of your own), or fire off an intent, you pass the ForegroundToken with it. If the work starts while your app is still in the foreground peachy, if not, it fails.
In a foreground > background > foreground cycle, your app gets a new ForegroundToken on every onResume event.
If you want apps to have true background access to a permission, that is a separate toggle (yes more complicated I know, but theoretically possible). They then can pass null into the ForegroundToken argument.
1. More finegrained permissions (per api call basically)
2. Ability to give/deny permission per use case or some time.
Classic living in the bubble.
Classic finding things to be offended about.
This article (as originally written, they've updated it since) was stating that a privacy feature that never existed had been taken away. There never was a location services toggle for specifically Maps, and pre-M it's not possible to make one that works (at least, not one that someone who doesn't trust maps with their location should be using).
These GPS changes started in 4.0.4 (or was it 4.1?) which means 98% of devices (96%) include this:
> You can try to deny Google Play access to your handheld's location by opening the Settings app and digging through Apps -> Google Play Store -> Permissions, and flipping the switch on "location."
So it appears the article is talking about M or later.
(my location permission was actually already off for the Play Store, and flipping it on and off again gave no prompt, so not sure what the author was talking about with "but you'll be told you can't at that fine-grain level")
Apple has iBeacons which can do this, sans GPS. I wonder if this user would be just as upset the prompt wasn't initiated from GPS location tracking?
Personally I think they are cool tech in theory but in practice kind of creepy.
The problem we have with a lot of modern technology, and particularly communications and payment technologies, is that while some degree of personal identification and association with specific locations or actions is necessary to perform their function, that same information is readily repurposed and easily shared if there are no rules to prevent it, or almost equivalently, if there are no effective sanctions if rules that do exist are breached.
For a single tower, yes. In practice, if you're within range of multiple cell towers, a little physics and mathematics will determine your location much more precisely, assuming knowledge of each tower's exact location, the relative signal strength received from your device at each tower, and ideally any confounding factors like awkward terrain or local sources of interference.
As an aside, if things are going wrong on the network, it's a fair bet that engineers will be out driving around with directed antennae that will find any given rogue transmitter even using a single receiver given a bit of time. This one's not so much of a privacy concern, though, given that it only tends to be used as necessary to resolve specific problems.
My guess the prompt to install an app was a BTLE beacon.
Looking Android there may be no native notification for beacons, but any app with Bluetooth background access could present the beacons as notifications. I think we would need more details to know exactly how he was promoted. The article is fairly vague on this.
My feeling is that the businesses and other nosy APs on my way to work and along other corridors I walk can review/keep automated logs of my comings and goings when they establish an API allowing me access to me theirs.
And this is reason #643 for why I've deleted Google Maps, only use Gmail accounts as spam-buckets, use DDG, and generally have mostly cut Google out of my life. I started with an iPhone before Android existed, so I can't say they chased me away, but $%&#, my girlfriend doesn't need to know that much detail about my life; why on earth would I pay good money to send it to Google?
I vaguely recall there being an Android mod or app that allows you to automate all sorts of things, with your feature being an example of what was possible.
On my mac, I use Hammerspoon to do some of this. For example, whenever I connect to a wifi network that isn't my home network, the volume is automatically muted. No more accidental nature videos playing at full volume in a public place!
I do wish I could do something like this with my iPhone. Currently I also turn off wifi manually whenever I leave the house and I feel a bit dirty every time that I travel and I find out that I forgot to do so.
> Personally I think they are cool tech in theory but in practice kind of creepy.
If it was a beacon, a little message explaining so would go a long way towards making the experience less creepy.
I've found little bits of "unnecessary" why-type explanation go a long way towards increasing user comfort.
By default, Android 5 lollipop constantly scans wifi (draining battery), and the toggle-off is hidden in some menus.
Did he figure out if it the Google location tracking or the McDonald's food?
:)
https://www.reddit.com/r/blackberry/comments/3s26ym/priv_own...
Google Play Services probably does it so that all Android in-app ads can use the location as well through it.
I doubt this is very legal in the EU, as the user hasn't given "explicit consent" for this. It might be worth mentioning it to @vestager on Twitter, who's already been lining up official antitrust charges against Google.
Google Play Services are a trojan horse and a mobile device battery murderer. It takes away the power over your device. Have issues with it? Tough luck, if you'll downgrade, it'll be updated back automatically.
I want Android before 2012 back and not this proprietary fuckup.
There is a certain segment of society who knows exactly what's being done with this massive surveillance network. That segment generally does not contain the people who are under surveillance. The fact that Google knows it has to be coy about it knows that it's unsavory. And exactly what assurances do we have that Google is properly vetting access to this information, given their complete lack of customer service and their historical inability to properly run adsense, their core business?
You could probably ask the thousands of ex-employees who'd love to make $$ by breaking the story to the media. Don't you think it would sell?
Also, often when I hear stories about that company not providing support, it's for a service that has at the very least hundreds of thousands of clients/users, a lot of whom pay very little or nothing. How would you provide support to all of them? Would someone who spends $1Mil / yr on Ads have trouble reaching someone quickly?
Can you elaborate? Not criticising, genuinely interested. Given that "people who are under surveillance" are generally aware of the revelations made to the press by Snowden and others, I suppose you mean something else, hence my curiosity.
> and their historical inability to properly run adsense, their core business
From a business perspective their ad network is hugely successful, what do you mean by saying "inability to properly run"? Or perhaps you refer to the lack of privacy options offered to the public?
In fact isn't the first thing ISIS does with kidnappees is pull up their LinkedIn account, so they can see who they just kidnapped and who they can ransom?
This data should never be collected. At all. Screw advertisers.
Do we need so much of it?
Can we just cut out about 99.99% of advertising? Can I see 1-2 ads per day instead of being bombarded constantly?
They can use information like GPS, ip address and cell towers. So I don't know why this clickbait article is just pointing out these two google apps.
Seriously?
> Google knows your location,
Yes, that's the issue: you can no longer deny Google the ability to know your location as long as either Maps or Play is installed.
> your phone provider knows your location without asking
First, Google is not my phone provider, and second, my provider only has access to cell tower info, not GPS info. GPS info is much more precise than tower info, and it's obviously not possible to deny cell tower info to the provider.
> and probably many other apps that you've given location access to knows where your location is.
The key phrase there being "that you have given access to". You cannot turn off access to Maps and Play and more. That's the problem.
Today, 6 hours since the full charge I'm looking again at the battery screen: 38% battery left.
16% Chrome (Background CPU: 1min 24s, Foreground CPU: 16s, GSM: 2h36min 58s)
16% Google Play Store (Total CPU: 10s, GPS: 6h 20min 6s, GSM: 1min28s)
6% Screen
4% Android system
Chrome is most surprising, as it's not usually there. I did a single web search three hours ago though. The phone is idle all day otherwise. There's something rotten in the mobile software industry that's literally making our pockets warm for no good reason.
Dear Google, please at least be a good citizen in your own ecosystem.
I thought the article would be about tracking via wifi use, which they probably do.
To me? it is a desition that makes want not to use Android.
McDonald's uses a beacon protocol to suggest downloading an app without using location data.
This security researcher just doesn't understand anything about his phone.
"Otherwise, how would our beacons and geofences work on the customers who explicitly don't want it?"
At least Google can claim that they are collecting location on behalf of the rest of the Android apps on your phone.
Also, I will say that some of the AOSP-based distros, such as Cyanogenmod, run just fine without Google Play installed; you get most of the (open-source) apps from F-Droid or if you need something from the Play store, sideloading or downloading from APKPure is a possibility.
But Google does it anyway, because it costs them less than that to implement.
edit: For instance, Facebook says each user is worth about $0.73 / user / month. [1]
[1] https://www.theguardian.com/technology/2016/jan/28/how-much-...
> If you happen to live in Europe, including the UK, you’re only worth one-third of a North American to Facebook, at $4.50 every three months, while the “rest of the world”, which includes most developing nations are only worth $1.22 per user.
That's about $1.50 / user / month... which is higher than I thought. brb, going to start social network
4 dollars a month.
"Security researcher Mustafa Al-Bassam reported on Twitter that he "almost had a heart attack" when he walked into a McDonald's and was prompted on his phone to download the fast food restaurant's app."
Google makes most of its money selling your attention to marketers. This could easily be used to tailor ads.
Within 100 yards of Barnes and Noble? "Ding! Get 10% off your purchase when you present this QR code!"
Both of your comments seemed reasonable to me.
Over the last week or two any browser in my home not using an ad-blocker sees heaps of MuleSoft ads. Almost as though the ad network has noticed that my phone at work travels to my house and has created a linkage between the two.
Do you have any proof that Apple uses this information for advertising purposes? Their privacy statements say otherwise. This would be a huge deal.