Some Android apps are using ultrasonic beacons to track users
bleepingcomputer.com
bleepingcomputer.com
beacon-blocking Chrome extension and sample Android (research prototype) patch: http://ubeacsec.org/#Downloads
Silverdog Chrome Extension http://www.thewindowsclub.com/silverdog-chrome-extension-mit...
Disable Beacon monitoring on a condition in Application http://stackoverflow.com/questions/34486930/disable-beacon-m...
050217 - https://www.wired.com/2017/05/hundreds-apps-can-listen-beaco...
110316 - https://www.wired.com/2016/11/block-ultrasonic-signals-didnt...
Beacon: Phone Tracker https://www.aptoide.com/app/com.fibercode.beacon/beacon-phon...
AFAIK you don't need permission to _play_ sounds at least for foreground apps. So that means in a public space, it doesn't matter if your mic is disabled - if anyone _else_ gave permission for an app to use the mic, their phone hear your phone transmitting ultrasound, allowing you to be tracked.
"Don't think permissions really protect you from this."
Given the link-dump, I'm assuming it's "Technologically savvy people can solve this for themselves, and that's sufficient."
Can you clarify?
The messenger and the message always have a relationship. It may be irrelevant, but it always exists.
Would that even work? I'm pretty sure modern digital TV audio compression totally removes sound that is vaguely close to 'ultrasound'. I guess maybe smart TV apps could add the signal though, but why would they when they already know what you are watching?
It reminds me of a website for one of those annoying 'Mosquito' anti-loitering devices. The sound was provided as an MP3, which was of course totally filtered out by the compression resulting in a totally empty file.
The solution is simple: don't get a 'smart' television. Better still is to forego on television altogether but if you insist on having canned 'entertainment' (panem et circensis) beamed into your domicile make sure to use as dumb a device as possible. Any smarts you require can be added separately, the thing does have external inputs after all. As an added benefit you won't be stuck with a 'smart' TV running yesteryears OS on under-powered hardware while the display and sound system are still good for many years.
Will that prevent ultrasonic beacons? I assumed the speakers were the same on smart and 'dumb' TVs.
What if I want to play games, watch movies, or just sit down and otherwise enjoy myself? Is everything that comes on a screen an unnecessary diversion or is it just a screen of a certain size?
I never liked television programming, not as a child, not as an adult. There is nothing elitist about it, I just like doing things myself.
BTW, the mere fact that you're replying to a message I submitted to this forum should tell you it I do not consider everything that comes on a screen an unnecessary diversion, given the fact that the probability of me using a screen to read and enter text here is rather high. Television is quite well-defined as being a medium designed for mostly passive consumption of entertainment and information. It is the combination of hardware and a whole industry to provide programming to animate those screens. It is the latter, the industry and its products, which I dislike. The hardware can be quite useful.
After a recent experience: that's simply not possible. Every damned kitchen stove on the market has electronics in it (failure-on-delivery of which in multiple instances spurred on the search), and increasingly: Bluetooth or Wifi capabilities.
Ironically, one thing the new stove improves on over its predecessor is that there's far less electronics hum coming from it. Though several appliances still emite some high-pitched, and ultrasonic (I'm sensitive to that) noise.
It's been suggested that if I were serious about a fully analogue stove I might consider a restaurant model. I'll keep that in mind, though these tend not to be sized to typical home dimensions.
And I suspect many of these are also increasingly being electronified.
Natural-gas burning cook stoves can be had at the likes of IKEA [4], not a bit or byte in sight on these things. Maybe things are different on this (European) side of the ocean? I do find a few in the US-version of IKEA as well [5] so there seems to be some choice left.
[1] http://www.amishcookstoves.com/
[2] https://www.agamarvel.com/heartland/products/woodburning-coo...
[3] https://www.google.com/search?q=new+wood+cook+stove
[4] http://www.ikea.com/nl/nl/search/?query=+Gaskookplaat
[5] http://www.ikea.com/us/en/search/?query=+4+burner+gas+cookto...
Apologies for the late follow-up.
It's never going to be easier than it is today to buy a non-"smart" TV. It is going to get harder. In a decade, they'll probably be as niche and expensive, new-old-stock or refurb, as CRTs are relative to LCD panels now.
I imagine these apps use somewhere about 15k where some of us can hear it but really won't notice it too much during the 'empty' spaces between music, commercials, etc.
The middle aged and over execs and managers who approve of these schemes certainly can't hear it.
Lisnr: http://mixrank.com/playstore/namespaces/com.lisnr.sdk/instal...
And shopkick doesn't appear to be for Android. If someone has a link to the docs I can double check.
http://app.shopkick.com/wr2/6Z48W52-6Z6LIDX
Unless it's something else with the same name.
Permissions on an app should be checked carefully by a user, and users should be educated in this!
Having the app ask on first use makes much more sense. It's much less likely to get away with this. Even better, you can still use the app if you say no. It will just get dummy values back.
If you ask me, both should be in place. When I install an app a list of permissions (and a short text next to each from the developer explaining why they need this permission), along with manual prompting once the app is installed and the thing in question (like the mic) is to be used.
Apps on Apple App Store can't stop functioning just because of a permission is not given. If the app can't perform it's function without a specific permission the developer needs to explain it to the users and ask them to go into the settings and lift the ban.
So if an app that does not have a really good reason for asking for the mic, the use can just deny that permission and continue using the app.
No need for fishing in the sewage until you find the gold among the sh*t and it's my main reason to use IOS over Android(Though I hear its getting better).
I don't remember when iOS did this retroactively, do you have an example? When have they even added a new permission that wasn't a new API entirely?
First, there is no sane way to grant permissions "just for a few minutes" rather than forever (unless revoked). E.g. a banking app that has a screen with nearest ATM locations doesn't need GPS access granted all the time - only when I ask for the directions.
Then, there are apps that ask for just about everything (a long sequence of "grant AppName access to something") at startup. It's a subjective opinion but I believe this sort of "fix" to deal with the new permission model on SDK update was quite popular, as I saw it relatively a lot.
And it's good if denying access is an option and you just aren't asked the same thing again until you either give up or kill the app. It's probably not an issue if that's some flashlight app you can uninstall without even thinking about it, but isn't so much when it's an app from your mobile network, allowing you to manage your plan, or something unique enough to be considered valuable.
I see only two options how to fix this for real. First is more and more regulations. Second is improved app isolation and permission spoofing (silent mic input, empty contact list and filesystem, no persistent identifiers across reinstalls, etc), and activity indicators "app is trying to access the camera right now", "app had accessed your contact list recently" that would both raise alarm or allow to grant access, depending on the end-user decision.
Also, Android permissions are strange. Like, why does an app need access to Contacts to use my Google Account to sign in? An account is not a contact and just because I want to let you unify my logins, that doesn't mean I want you to have access to my contacts.
It is true app makers are happy to ignore recommendations, but users with M+ are much more empowered. So, for example, if the app makes permission requests repeatedly, on the 2nd ask Android will provide the "Never ask again" check to auto deny permission requests. So if an app is being annoying about a permission you (the Android user) don't want to give you can silence the app.
Also, you can always deny individual permissions after you've granted them, which also includes apps that don't target M+. So if you don't think an app should require the Contacts permission then you can deny only that permission. You can argue that this is a "power user" feature, but if you're interested in app permissions I think M+ gives you the appropriate levers. And surprisingly, I've seen the developers who fix their app if enough users uninstall it and leaving a review citing poor permissions.
However, you don't really address my concern that Contacts is grouped up with Accounts when it shouldn't be. I cannot deny an app access to my contacts while allowing it to use my account to sign in. Android app permissions need to become much more granular and fully backwards compatible.
Ironically, I'm sitting here not upgrading my phone to Nougat because I really dislike the material design aesthetic of the UI. It's ugly, blinding white and turns every icon into boring circles. It also apparently breaks a lot of stuff that I use everyday.
https://www.recode.net/2016/9/16/12933780/average-app-downlo...
It seems likely that lots of folks already realize 'experiencing the joy of the Krispy Kreme app" will not improve their life in any way, shape, or form.
I see a need for a good, simple, slick and solid interface that allows you to select what functions an app can and cannot do on your device, be it laptop, tablet, smartphone, car, whatever.
These kinds of things have been going on for years, and yet the U.S. government, for one, just reduced privacy protections for consumers.
True. I have higher hopes for the EU
To combat this, you can add forward error correction code, and have the audio source transmit data at low bit rate. Also, it's possible to modulate data using spread spectrum sequence (similar to GPS and ultrawideband) to reduce the energy below hearing threshold.
The state of the art is not to embed data at all, but use audio fingerprinting, aka Shazam.
Wouldn't it be far easier to just transmit a wifi SSID that encodes this information?
100000+ SMS Messages Moziberg 2.4 1,000,000 – 5,000,000 McDo Philippines Golden Arches Dev. Corp. 1.4.27 100,000 – 500,000 Krispy Kreme Philippines Mobext 1.9 100,000 – 500,000 Pinoy Henyo Jayson Tamayo 4.0 1,000,000 – 5,000,000 Civil Service Reviewer Free Jayson Tamayo 1.1 50,000 – 100,000
so from those 5 with significant install base are minimum 3 targeted at Philippines market, the other two probably too, though they mention India
also note: Within the 1,320,822 Android applications, our scan yields 2 and 1 samples with functionalities of Lisnr and Shopkick, respectively. These samples are either applications that have been released by these companies themselves or by other companies officially collaborating with Shopkick or Lisnr. The user is thus aware of the deployed technology and needs to start the audio analysis manually.
so conclusion is, from 1.3mil tested apps, around 230 have this functionality, around 5 have significant user base and all of these are in third world countries (PH/IN). also according research many devices have issues detect these higher frequencies and they didn't find it working in TV streams or European shops. also from those 230 in most of them they use technology of Shopkick and Lisnr where you need MANUALLY start audio analysis. it's interesting research, but let's keep it in perspective
TLDR: don't give microphone permission to apps which have no use of microphone
And these apps should always listen, that will drain battery quickly, so these apps will be listed in top power-consuming apps and user will notice it.
Yes, battery drain is an issue. Most apps use a background service that wakes up at a fixed interval. The longer the interval, the longer the broadcast has to be though, so it's basically a trial and error kind of thing.
Also the apps on the phone have access to the microphone (even though they probably do not need this permission for any other purpose), so these apps are all potential listening devices.
NTP sounds like it would work. As you kindly noted, just make sure the beacons broadcast at a agreed upon time and in fixed increments.
The second point however is an overly broad generalisation disregarding the technical inaptitude of the target group of such apps (wherein I might include myself).
Reading the article, it's actually worse!
This sort if things should be taught in school, don't give an apps permission to your mic, GPS, camera, contacts, etc... Unless you understand why. Not everybody will write "hello world" in JavaScript in their life, but most people will installed apps on a device.
Embed inaudible tones in tv content to sell you stuff. Never saw the appeal.
But as we know the appetite for tracking is endless, foe some reason.
The only problem is that dogs and other animals won't like it ;)
[1]https://security.stackexchange.com/questions/47345/surveilla...
https://www.ftc.gov/system/files/attachments/press-releases/...