Google collects cell tower info even if location services are disabled
qz.com
qz.com
A more sensible way of dealing wirh the issue would be to use an open source Android version like AOSP or LineageOS, not run proprietary gapps, and replace its functionality with F-Droid, MicroG and Yalp-store. Your location will stay out of Apple's/Google's hands and you can still enjoy all convenience of a smartphone. Keeping your freedom in your own hands.
This is true, but it's also potentially worthwhile to consider that Apple has positioned themselves as a hardware company (i.e. the majority of their money is based on selling units of hardware), whereas their main competitor here (Google) is an ad company (i.e. the majority of their money comes from selling their users' data). Apple has chosen to highlight their commitment to privacy partially because they feel it helps their market position, whereas for Google, it would hurt it.
Certainly it doesn't mean that Apple is infallible, just that I think it makes it easier to accept that Apple is more likely to protect privacy more than Google.
I'm pretty biased towards Apple, so obviously this may not work for everyone; if you need source code to feel secure, then by all means, go for it. For people who are looking for less work but some of the benefits, I think that Apple is a decent way to go.
But this is all just marketing, whereas the reality is that Apple could also be hoovering up location data and you may never know.
You may have good reasons to trust Apple more than Google, which is great. Others may reverse that position of trust (perhaps they had their iCloud account hacked into and photographs leaked on the internet).
It isn't just marketing. This is how the alignment of incentives works. A company's incentives are aligned with the people who pay them. Apple's are aligned with those that buy phones. Google and Facebook's are aligned with those that buy ads.
Apple has a very strict internal culture of protecting user privacy.
Aside from Apple’s strong stance and history of protecting the privacy of users, we also have security researchers MITM’ing the traffic sent from iOS devices to Apple, and every jailbreak gives an opportunity to look deeper; if they were acting badly, someone would find that out soon enough.
Edit: I was beat to the punch.
Apple has demonstrated time and time again their commitment to privacy and to protecting user data.
Apple does not see user data as something to be hoarded. They see user data as a liability and work very hard to collect as little as possible in order to provide the services they do.
The idea that Apple is going to discard all of this and add privacy intrusion into iOS, doing a completely 180° on their business model and discarding all of their corporate principles, is extremely unlikely.
That alone is a very strong reason to hoard data if you're Apple.
Really the big outlier here is Siri, I'm sure they could make Siri better if they were willing to hoard data, but Apple has demonstrated that they value user privacy much higher than the incremental improvement they'd make with Siri, and violating user privacy would likely hurt their business a lot more than making Siri a bit better would help.
IMO both Google and Apple aren't saints. Apple had a fairly similar headline in 2011[1]. Now watch people here on HN explain why that was completely different. It's a guarantee.
We really should be focusing coming up with ideas on what we can do. My friend for example (and this isn't a perfect solution) but he bought 2 phones, one of these for calling:
https://images-na.ssl-images-amazon.com/images/I/41AwGb3pKCL...
(extremely thin in real life)
And then he caries a smartphone for encrypted chat apps etc. He removed a bunch of hardware chips from the smartphone so even if you put a simcard it it doesn't connect anywhere. Also the microphone was removed and some other things. It works great. At first he had it with the simcard still in, but he wanted more privacy. Personally, I would have kept a 4g only simcard or something, it's kind of a trade-off because now he can only chat on wifi.
It's far from perfect, but at least he's trying something.
[1]https://www.theguardian.com/technology/2011/apr/20/iphone-tr...
Google's entire business is carefully balanced on user trust. Anyone who posits some naive "they're an ad company" nonsense is just muddying the waters. Google is a user-trust company in a variety of spheres, and without that trust they would be annihilated.
Apple does not see user data as something to be hoarded
I've gotten downvoted elsewhere and will gladly eat it up to warn against this utterly ludicrous kool-aid fueled naivety. Apple says whatever nonsense gets a cheer at their latest product reveal. But if you don't think they're desperately vacuuming up data for their machine learning to stay ahead of the game, you should rethink your positions.
I remember virtually identical claims about Microsoft a decade ago, as an aside. Hell, in conversations about Google versus Microsoft, no less. Then Microsoft, you know, started viciously hoovering up user data like there's no tomorrow.
I'm a (mostly) happy [0] Apple customer. The lack of evidence that they are gathering all my bits makes me comfortable to use their products. I strongly feel we'd hear leaks about how they are saying one thing and doing another if they were. Employees of Apple aren't that loyal.
Yet here we are with Google and their "it's better to ask for forgiveness than permission" attitude.
[0] iOS 11 is bad. Just bad.
Apple is also much better at privacy now. Maybe they'll also change course and then we might as well stop using smartphones, cause we're being treated like sheep.
The non-Siri Apple machine learning is happening on device. This is something that Google would consider doing for 5s, before all in the meeting would start laughing and they'd go for uploading everything.
Remind me again, which company pulled out of China, Apple or Google?
The same goes for banking apps and all official store membership and coupon apps, just to mention a few categories of apps you will have to do without.
Is called cash :) It's accepted everywhere.
>official store membership and coupon apps
Should all be burned anyway. Plastic cards and bits of paper worked fine for decades, you don't suddenly need to run arbitrary code on my pocket supercomputer.
>banking apps
Safer to use the website. My bank authenticates you by having you enter your PIN into a card reader - although they have created a mobile app, the security is strictly inferior as phones do not come with card readers (and the passcode is different from your PIN, making you more likely to write it down).
The basic pattern is, it's either important enough to be worth being a stickler over, or trivial enough to ditch entirely. Personally, I find "not being on F-Droid" as a very strong signal that I should not want to use an app in the first place. It steers me away from malicious code and proprietary lockin. And I never, ever see an ad on my phone!
A lot of people refuse to carry any significant amount of cash. It is a risk factor, especially when at events and shows or just during busy shopping hours, due to pickpockets. An app with verified identity (using the national 2FA login system in my country) is significantly more secure.
>Should all be burned anyway. Plastic cards and bits of paper worked fine for decades, you don't suddenly need to run arbitrary code on my pocket supercomputer.
It's a bunch of silly plastic cards that I then I have to carry around in my wallet or remember to bring from home when going shopping, as opposed to having the app on my phone, which I carry around with me anyway. The app automatically calculates bonuses and rebate collection marks.
>Safer to use the website. My bank authenticates you by having you enter your PIN into a card reader - although they have created a mobile app, the security is strictly inferior as phones do not come with card readers (and the passcode is different from your PIN, making you more likely to write it down).
My mobile banking app is perfectly secure, it uses the Danish national 2FA login system, used for all public services.
Surprisingly, it’s not!
A non-Swedish friend studying in Sweden recently told me of a situation (I forget the exact details) where she could not pay with cash. They only accepted payment via Swish[^1] (mobile payment system).
At the time she was with a Swedish friend which was the one to pay for both of them, with my friend paying her friend in cash.
[^1]: https://www.theguardian.com/business/2016/jun/04/sweden-cash...
I went to a festival earlier this year and the door tickets were card-only.
Reverse engineering and analysis techniques gives us enough ways to look into that so called "black box" and see what's going on.
So if Apple one day ships iOS with privacy intrusion built in, they will be caught.
I prefer to trust the motives, i.e. Apple doing reasonable things and staying away from funny business because they want to sell me iPhones.
Don't trust: the company fucking privacy because of economic incentives.
Quite simple.
- "People willing to trade their freedom for temporary security deserve neither and will lose both".
- Apple is screwing over developers AS A BUSINESS MODEL (de-value your complements) - and you want me, a developer, to support them?
And google does it with Google Play Services. All we have to go on is the historical record of the manufacturer, and apple’s is vastly better.
Obviously a high-quality open-source smartphone would be preferable, but I’m not aware of such a thing (Although I’m hopeful that purism’s phone will be good).
That’s not a great argument when you’re talking about the single most lucrative consumer product in the history of the world. At that point, the risk to your existing product by making an abrupt 180 like that is far too great.
If only HW and chip manufacturers released Linux sources (or ideally had support in the mainline Linux branch) soon with proper drivers (ideally open)...
Manyfacurers keep releasing lots of closed junk smartphones every year :/ but as long as people will continue buying it, nothing will change.
And this would be swiftly called out by someone soon after release, putting a very ugly stain on Apple's reputation. There is absolutely no advantage they would gain from this which could outweigh the PR nightmare.
Another sensible way (if you are prepared to 'phone' a bit more frugal) is a Sony Xperia X with Sailfish. (But check together first.)
Isn't it likely to be more lucrative now? I imagine that the number of people choosing iOS over Android purely for security/privacy reasons is fairly low. I think the incentive exists for them now and they've ignored it.
Smartphone or not, carrying any phone means providing this information to your carrier at all times.
I don't like the idea of sending this information to anybody, but to be honest, Google is the entity that I'm the last concerned with at the moment. Unlike literally every cell carrier on the market, hey have an excellent track record from a data security perspective, and their entire competitive advantage relies on them not providing that raw data to any third party.
You can't have privacy without security, but security by itself does not equal privacy.
The best security in the world doesn't mean that you have privacy if everything you do online is tracked. And no company arguably tracks you more than Google. The volume of tracking data they collect about users is mind-bogglingly gargantuan in scale.
It's baffling how Google escapes scrutiny on their data collection practices, particularly from the tech community who seem happy to give Google a free pass on matters of privacy and online tracking.
Google has much better security than the phone companies anyway, so letting the phone companies know where you are is bad enough.
I had the idea to "red team" myself and find out if there's a way of finding out my location history from shady online data broker and then take countermeasures.
There is no way to ever completely trust a cellular device.
Hopping out of "airplane mode" can be made arb fast.
So, short answer, customer demand. I bet eventually they will get too creepy with the data and demand will happen.
It is only obvious when one enjoys a wealthy life.
There are lots of countries out where people can barely afford something better than a feature phone, and when they do, their hard worked savings are just enough for an Android device.
So about three times the average monthly wage if the numbers I find are right.
(Sneak edit) Just to write it down another way, that means 25% of the average yearly income. For a phone.
No. The "obvious" solution here is to regulate companies and give huge fines for doing stuff like this, without explicit user permission. Google went through hell in Germany over its "error" in collecting user data from their Wi-Fi hotspots. Why can't the U.S. do the same in this case?
It's not just an absolute privacy outrage, but also an outrage because Google will drain my phone's battery life without permission, just to serve its own interests.
Dont fool yourself that the problem is the "current" administration and the next administration from the "good guys" will solve everything.
I used iOS and Android phones and I like both. However it makes even me nerveous to use a banking application or similar on an Android. Can’t imagine what kind of shit my dad would have running on an Android device with all the fake fishing apps, bloatware, tracking etc going around.
With a non jailbroken iPhone I have a lot more peace of mind.
Do these people not do banking on Windows machines? The malware situation was infinitely worse on Windows - I see an Android device with some unwanted ads maybe once a year from a friend or family member, but Windows devices are a weekly occurrence and the really nasty stuff - like password sealers and banking trojans do exist, but are extremely hard to come by on Android, compared to Windows where clicking a pop-up and a run button could leave you permanently infested.
They don't.
Almost everyone I know does banking exclusively on their phones. I do that too.
Sorry, legitimate Android app developers! I would like to pay you for the things you create, but your neighborhood is too sketchy for me to visit.
I would argue it the other way round. On mobile (Android or iOS), apps have much fewer permissions compared to on desktop. e.g., one app can't look into the data of the other app. On desktop, it is possible to write a binary which steals user cookies (e.g., https://github.com/rash2kool/cookie_stealer). For all purposes, the binary would be legitimate, and no antivirus or OS APIs would mark the binary as bad.
However, on mobile, one app can't peek into the private data of the other app. So, the Uber app can't peek into my browser cookies.
- banks often use phone (for example, SMS) as a second factor for authentication, for example to confirm transactions. Compromising a phone thereforer provides full access to your account. Some banks even allow to perform payments by sending SMS without logging in.
- many phones do not receive security updates in time. And those updates close only public vulnerabilities.
- while Android has good permission system, many apps have a very wide set of permissions, including permission to read or send SMS messages, or permission to use accessibility functions, so compromising such an app can also be enough.
Ignorance is bliss.
From my point of view, the sandboxing and authorization model of iOS is way better than what is available on Android right now.
You could argue that newer versions of Android provide a way to ask for permissions, but suffices to target API level 22 on your app and you're off of it. And fon't get me started on full disk encryption and buggy TPM implementations on Android.
So.. what do you know that we don't?
No. The alternative is to install Lineage OS, don't install any Google trash, use F-droid only and a Play Store interface if you have to.
[1] http://news.gallup.com/poll/166211/worldwide-median-househol...
Currently I have a iPhone 6 that i got for 200, no contract. Seems pretty affordable to me. In Liberia, maybe not, but I imagine there are millions of iPhone 4s they would be welcome to take off our hands.
For one it's more expensive, I have to pay a hefty price to get a recent Iphone, compared to being able to get a usuable android phone starting at 100€ or less.
Additionally, I'm a primarly linux user and from what I've gathered, Linux is not supported by Apple at all, rather, you have to buy into the Apple ecosystem to properly use an iphone.
Which is the third point; to use an iPhone I need to become part of the Apple ecosystem while most Android phones interop with any OS and Hardware relatively straightforward most of the time.
There is very much a reality of smartphones existing for over a decade before this type of data collection was done. It is in no way required or critical. If it was beneficial, it still should be a setting that can be turned off.
This isn't applicable just to service companies like Google who value user information, even when purchasing from a product company such as Apple has laptops phoning home at an incredibly unreasonable rate compared to MacOS 1-2 versions prior.
It's like having to run a firewall on your own devices to protect yourself from the manufacturer. Can we imagine if our routers do this, or did?
It's not like Google has a monopoly on tech knowledge.
Living in a walled garden to escape prying eyes is sacrificing freedom for security.
http://blog.chron.com/techblog/2013/10/your-iphone-knows-whe...
This is literally from the article:
> “In January of this year, we began looking into using Cell ID codes as an additional signal to further improve the speed and performance of message delivery,” the Google spokesperson said in an email. “However, we never incorporated Cell ID into our network sync system, so that data was immediately discarded, and we updated it to no longer request Cell ID.”
The only way to regain control over SW and to prevent spying and data leakage is by using free software, where you can read and modify the source code, build the firmware yourself. Because as long as there is source released and some company decides to add a tracking functionality, people will notice and make a fork without it.
This is how it works on GNU/Linux for a decade and I am happy I can use it. Now I only wish people stopped buying these smartphones with proprietary blobs tracking them and demanded free software.
Most people are easy (I don't want to say stupid) and don't see the problem unfortunatelly. :(
Always follow the money.
Well, pricey hardware, at least.
> In the case of google they sell you
No, they aren't in the slave trade; they sell ad placement, not people.
It’s not the placement that’s the value that’s being sold, it’s watching the ads that is. So they definitely use your data to sell your attention, which is the currency you’re paying with.
Yes, it is ad placement that is the actual thing being sold. Advertisers hope to get something else out of it (usually sales), but what is actually sold is placement.
> So they definitely use your data to sell your attention, which is the currency you’re paying with.
No, they are selling the placement. The placement is valuable because, in aggregate, there is an expectation that a certain share of the people to whom it is shown will give some attention to it, but the advertiser generally pays by impression, not by seconds viewed × share of viewers attention devoted to the ad during that time.
But, in any case, either selling placement or attention is different than selling the user, which is a flatly inaccurate description used solely because of its emotional charge.
I noticed several chrome instances running on "Task manager" almost all the time. Used Chrome maybe months ago. So I uninstalled. Who knows what they were doing, collecting. I trust them as much as I (would) trust a hustler on the old 42nd street
It would be even greater if you could upload a zip archive of the plugin.
[1]: https://superuser.com/questions/156913/what-is-the-google-up...
What is your life like to where you think not having a cell is impractical.
In any case a smart phone is fundamentally a weak point in privacy/security no matter which one you get.
In the 90s it was inconvenient to be out and about if you were expecting a call. You might be able to check your messages though, by dialing your answering machine from a payphone.
Payphones barely exist anymore, so it would be even more inconvenient. If you need to be reachable at all (nowadays by email/sms), a cell phone is nearly a requirement. If you do not need to be reachable, you still put yourself at a significant disadvantage by not carrying one.
What is your life like where you would not be inconvenienced by not having a cell phone?
Donald Knuth gave up email in 1990. Too distracting. (I dunno but I wouldn't think he has a cellphone)
When I started grad school in '07 I wanted to forgo a cellphone. I couldn't. My advisor was even annoyed I held out on a smartphone for as long as I did (caved in 2010).
In 2013, sick of my smartphone I went back to a dumbphone. It was great until 2015 when I started working at a place so crappy I have to routinely tether my phone for productive internet access.
My point: it's very possible to live w/out a cell phone. Frankly it's not even hard (I "forget" my phone at home). However, unless you're tenured or are otherwise your own boss, you'll be forced to have one.
Mostly pleasant and stress-free. I haven't owned any phone in ~6 years.
This sounds like advertising. Also, I'm fairly sure that Apple also sells data. Indeed, given current privacy laws, it's basically guaranteed that if a company has proprietary software, it is selling data from that software.
They make it very clear that they are protecting data, to a far greater degree than Google offers if you use their ecosystem.
I don't think it's at all fair to resort to an "Everyone is the same" argument here.
Can you point to a source that shows this? This sounds like a lie to me.
Maybe they're even promoting drug use to kids under 5...I mean it's possible.
If they weren't selling location information, then they could just say it:
https://www.apple.com/legal/privacy/en-ww/
Collection and Use of Non-Personal Information
We also collect data in a form that does not, on its own, permit direct association with any specific individual. We may collect, use, transfer, and disclose non-personal information for any purpose. The following are some examples of non-personal information that we collect and how we may use it:
We may collect information such as occupation, language, zip code, area code, unique device identifier, referrer URL, location, and the time zone where an Apple product is used so that we can better understand customer behavior and improve our products, services, and advertising.
The obvious answer is not to get an iphone. Today it’s android, tomorrow it’s apple—you’re willingly using a massive closed stack to handle your location at all times. Trust is simply naive.
If you accept you’re trading privacy, security, and money for a massively convenient liability, you’ll be much happier.
A week ago, I moved from my previous home that was close to my work, to a different city about 20 miles away. Since I wasn't sure where all the points of interest are, I've been turning on location on my Android phone and using signed-out Google Maps on my phone.
Yesterday, my work computer's signed-out Google Maps has centered its default view on my new city, on the exact highway interchange next to which I now live.
The IP -> location mapping is googles secret sauce, but it collects data from a lot of places, and is for most users very accurate. We're talking street level accuracy in many cases. The data you or another user feeds into it you could easily get back as your reported location, especially if you were trying to fool it.
Your phone doing a wifi scan for nearby access points to determine it's own location, then doing a google search could easily mark your whole home external IP as being in that place (after a few hours), which would then affect non-signed in google services from other devices in your home.
There are cases it's very bad too though, especially VPN's and frequently-shifting dynamic IP's.
Clear cookies, and you'll see it again.
In Chrome, it also uses the TLS Client Channel ID, which is a persistent unique identifier established between a browser and a server which (on capable platforms) is derived from a key stored in a hardware security module, making it hard to steal. Ie. if you clone the hard drive of a computer, when you use the clone, Google will know you are a suspicious person, even though you have all the right cookies.
Sounds like another reason to limit my personal use of Google's Chrome browser.
Dumb question, but how often do you close your browser though? Mine stays running in the background so it's not often that it gets completely closed.
My point is, I highly doubt my browser usage pattern reflects the way the median user browses the web, and yet even my careful usage wasn't enough to keep Google from correlating enough data about my browsing's attributes (IP, sites visited, location info, logged-in geo-IP), and then expose that cross-bleed in my face.
That aside, to have a setting that doesn't do what it says is disturbing. If that's don't be evil then what's their definition of evil?
I've dug around and it seems like this no longer exists, if it ever did. Privacy Guard now seems to just allow granular controls on what the apps are allowed to request.
If it doesn't exist already, someone should definitely work towards implementing something like it.
EDIT: I see that the related XPrivacy app has a menu option for "Fake Data", so maybe this is what I'm thinking of.
It worked as advertised but boy was it a hassle. I had a template XPrivacy setting which constantly broke app. It was too common to find apps requiring tons of permissions than they need and had to resort toggling the permission to see which work.
I got fed up and switched to iPhone late last year.
With iPhone, I can at least control which data to share with the app. With Android, I don't have control with either app or google.
I feel relieved and have been recommending iPhone to family and friends if possible.
But this is all pure conjecture.
That ephemeris data is good for 2-4 hours, so one simple technique to improve lock times is to save it, and then if you turn the receiver back on within that window, you can reacquire a lock almost instantly using the saved ephemeris data.
Another technique is to download the ephemeris data from a source that can provide it more quickly, such as the cell network. This skips that long transmission at 50bps from the satellites themselves. Pretty much any GPS chip in a cell phone these days will do this. This is called assisted GPS, or A-GPS. (This is not to be confused with another technique also called A-GPS, where the GPS chip captures the signal and sends it to the cell tower to offload the computation. This was a popular approach in older phones to comply with 911 reporting requirements, but doing the computations onboard is cheap now.)
Starting with a coarse guess of your location can also help shorten the time to initial lock, although it should be fairly short regardless. That guess can come from looking at cell signals along with known cell tower locations, and a rough altitude estimate can be made from the device's barometer.
All of which is to say, getting a dot almost instantly when you turn on location services doesn't necessarily mean too much here.
It could be tricky to do securely. How do you prevent a malicious device from spoofing bad location data?
Android and iOS do something sort of like this already, determining position by looking WiFi base stations with known locations and attempting to do some triangulation. This can speed up a fix if the GPS signal is having trouble, and can be essential for indoor location because GPS signals don't penetrate structures well at all. My understanding is that the database gets built up by the devices. When they have a good location fix, they'll report back on the WiFi base stations they see, so that the mothership can build a database of where the things are. This is a little bit like what you describe, but with a really roundabout data path.
Privacy from who? Security from what? What's the perceived threat we're trying to protect against?
Everything is a tradeoff. To absolutely protect your privacy, you must never be seen in public or interact with any other party in any way.
The original assertion was "If you care about privacy, don't use Android". A more nuanced and useful assertion would be this: If you don't trust a specific private company with your information, don't volunteer it to them. If you don't trust Apple/Google/Microsoft with all of your data, don't buy a device with a radio they have root access on and store all your data on it and carry it with you everywhere you go. This isn't Android-specific.
I actually have location history in google maps turned on deliberately. You can't imagine how often it helped me to know where I was exactly, one and a half year ago, at a precise time. (That's how I managed to get a copy of my nexus 5x's warranty papers after it died on me)
I don't really care about them collecting info about where I go, because it's actually useful for me. I probably would care if they were a small company with no record, but I do know that the worst Google can do is to target ads based on where I am.
I deeply hate ads, I prefer to pay, and I actually often pay the "no-ads" premium if it's available, but if I do get ads, I prefer them to be as personalized as they can possibly be, because this way they are at least mildly useful sometimes.
The marketing parasite. I know in the US it has taken over the host so I guess its up to Brussels.
- Worried about Google? Android is bad. Google collects your data.
- Worried about the government? Since Google must obey warrants for your data, Android is bad.
- Worried about malicious third parties? Since Google has failed to patch even the Pixel line for KRACK until the December update... yeah, Android is bad. And malware through the Play Store that hits large numbers of devices is quite common.
To be clear: I greatly dislike iPhones. But Apple controls their store with a quality approval methodology, they patch all of the devices on their platform promptly going back a number of years, their business model is not built around data mining, and their privacy features have frustrated and irritated the government.
I dislike the iPhone, but if you want privacy and security, you should get an iPhone.
> I dislike the iPhone, but if you want privacy and security, you should get an iPhone.
If you want privacy and security, don't buy a smartphone.
You should discourage them from carrying a portable radio transceiver, ie a cell phone, with them at all times. You only know about this because you read it in the news - Android is not the only outfit doing this. Sending tower-data back home is a fundamental part of your cell phone's operation. Without that information, your carrier would have no idea which tower to route incoming data/calls to.
Yes, your carrier already has this information, and should be considered depending on the threat model you're concerned about.
However, NO, this does not mean that other unrelated parties have any business with the data!
The attack surface goes up exponentially with every additional data holder.
Keeping track of which cell tower your phone is closest to is fundamental to cellular technology. You can't make or receive calls unless Verizon, T-Mobile, or whichever carrier you have knows which cell to communicate with you through. Regardless of whether Google is tracking this, your carrier certainly is, and with a warrant (or a national security letter), law enforcement can definitely access this data. If you're worried about hackers, I can guarantee you Google protects this data more securely than your carrier does.
This sentence is completely insane in this context, did we read the same article? Google should not have access to this data, and it sure as hell shouldn't be sending it up to itself when disabled by the end-user. It's absurd that you typed that out for an article titled "Google collects cell tower info even if location services are disabled".
In what world does one operate in if you consider this as "Google protects this data more securely than your carrier does"? Your carrier is supposed to have this information (and in fact needs it), it's a complete privacy violation for Google to be collecting it though.
> I can guarantee you Google protects this data more securely than your carrier does
Part of acting as a company who cares about user's data includes not collecting data that is sensitive. This is especially true with location data, and is extra especially true when you do it anyway without the user's permission.
Acting like this proves to me, the end user, that google does not guarantee to protect this data more securely than my carrier.
I can see how one could be easily confused by the original comment, but if you take a moment and review it again you'll see it rings even more true now.
This is absurd. Me not wanting google to have this data has nothing to do with how secure they can keep it.
This seems to be implying that this level of tracking is expected, or required. It's not. Not by Google anyway, which doesn't need and should never access this information.
But breadcrumbing it and phoning home to the phone vendor/advertising company?
Oh wait, that's what Google did.
That's not true at all. My carrier falls under strict EU privacy laws and regulations, Google - doesn't.
What do you think a cell phone is? It's literally a portable phone. It's purpose it literally to be carried with you. You completely missed the point and you gave up all your rights as a person and as a customer to a foreign corporation. Millions years of evolution and we ended up with someone like you.
If the phone is compromised, it doesn't matter what google has access to, the tracking kit can just enable it's own tracking and spoof the system status (depending on the level of the compromise)
If you have a concern about your phone tracking you, don't bring your phone with you.
Classic example of Google's "ask for forgiveness, not permission" mode of operation.
Meaning you can still be triangulated by towers
Which I had run legally for LEO at Sprint back in 2003-2005.
Towers gotta know where you are to provide service.
Don’t want to be tracked? Leave your phone at home.
Not saying it’s ideal but it’s how technology works.
Isn't this almost identical to what Apple was doing in 2011: https://arstechnica.com/gadgets/2011/04/how-apple-tracks-you...
Saving location history in a local file is not the same as sending it to Google, just like cutting your finger is not the same as getting your hand blown off.
https://www.kickstarter.com/projects/zoltancsaki/1984-stealt...
If I want Android without google services, what options do I have? So far I know only cheap chinese phones and F-Droid app store.
There's also a fork with replacements for some of the Google services: https://lineage.microg.org/
CopperheadOS is a good choice if security is a priority.
If you need proprietary apps without using Google, you can install and use Amazon's app store app, and download them from there instead.
If you can't do that, some phones just let you disable google services. On others you can try getting root access and then disabling them.
As an alternative (or addition for closed-source apps) to F-Droid I can recommend APKUpdater. It is highly configurable, has multiple apk sources, has search and can install apps from Google Play Store.
I can't download apps, but the phone itself works fine, and it came with a bunch of pre-installed apps anyway.
That category no longer applies solely to apple. Google's flagship phone [0] is just as expensive as Apple's, has no headphone jack and no fingerprint reader.
However, the phone looks very cheap and dated. I'd be willing to get an iPhone over that :P
That's not how commerce works(anymore). You are technically a consumer...and you are fundamentally the "product". Companies buying advertising are the actual consumer - to which you(ie your data) are for sale.
If you cannot look at it that way, modern corporate America/Elsewhere will never make sense. There is no free lunch, no company anywhere wants to help you out of sheer kindness and goodwill. Free software? (sometimes) free phone? ...really?
That should hopefully make these actions uneconomical.
Imagine this: would apple ever let you not pay for a new iPhone? Its entire incentive in making iphones is to sell them for money. So it will never allow you to get phones for free.
Google said they're taking steps to fix it. Surely they wouldn't lie to us.
They kind of lied when they made the location tracking work even when you disable it.
I feel like I'm misunderstanding your question.
Shareholder profit > all, remember? /s
The employees a of company (from executive level, down) work for the Board of Directors, who are a proxy for the shareholders. The employees do not work for the customer. If there is conflict between what a customer wants and what the Board wants, the Board wins.
I was happy to learn it's possible to disable Google Now yesterday: https://news.ycombinator.com/item?id=15743055
Another option besides an iPhone is to replace Google Play Services: https://news.ycombinator.com/item?id=15617615 (supported devices: https://wiki.lineageos.org/devices/)
Location information, ads viewed, and offline credit card purchase information. Google now has all three. Google uses this to determine which ads led you to spend and sells more of those ads.
https://consumerist.com/2017/05/23/google-following-your-off...
They're not going to stop collecting location information, even if you tell them to.
Since the FCC is taking the Alan Greenspan approach to a self-regulating market / ISP, which nearly every Republican legislative office support. Which lawmakers and regulators are up in arms?
Couldn't it be used to avoid faulty towers ?
I am not an expert at all, but I was told several times that it was a problematic issue.
Not that it would be an excuse for collecting it when location sharing is off but I am curious to know why I can be helpful to FCM
I am really curious to know how Qz determined that Google was collecting this data.
So why isn't Google is slapped with a fine then?
It doesn't have to be perfect: calls and texts should work, a camera and browser would be nice, and the complete freedom to use it and control it in the way the user wants.
The first run to sell maybe 1,000 or 10,000 units? My cash is waiting...
Google: "Yah, ok, I know no means no, but...."
And the thing is, Google, Apple, Microsoft, are less still evil than Time Warner, Verizon, Road Runner, Xfinity, etc. But I'm concerned they are not sufficiently opposed to that fiefdom to maintain a neutral balance on the internet.
When do we finally realize RMS was right all along?
There was a misprint, it was :
"Do no evil?"
If only they'd use this data to at least do something useful, like create a machine learning-enabled firewall to block "rogue" cell towers like cell site simulators. But no, of course not, it has to be done only for ads...