Betrayed by an app she had never heard of
privacyinternational.org
privacyinternational.org
However, this is only half the picture.
If you install truecaller on Android, you're handing over ALL your personal information to them. The list of permissions they ask for is ridiculous. They ask for access to your sms messages, call log, contacts, file system, location, microphone, camera, everything. They also show you advertisements wherever possible.
Though I do not agree with the method where as a non-user I need to manually opt-out of the service, it does seem to work. My number is no longer visible on the app.
If they have full access on anyone having installed the app, it means they also have mined the conversations with your contacts.
So they might not advertise what they know anymore, but the privacy concern remains anyway.
--edit. I should read slower. I see you aren't an existing user. That is indeed BS.
edit: Make sure you put a "+" in front of your country code
That's what I remember too but the article said Truecaller only gets non-user's information when a user tags them so. Maybe the app behavior varies with the country the user is in.
> - They advertise the unlisting option more clearl
> - They send a SMS to any non-user whose number is entered to warn them someone is attempting to enter their number and ask them for consent. This would also be an opportunity to inform them about the unlisting option.
I doubt anything less than that is even really legal in the EU right now. Essentially, if my phone number is entered into that app, my personal data is being digitally processed and maid widely available without my knowledge or consent. Pretty sure that's very much illegal.
Mind elaborating on them?
The only potential issue, which I see, is some ambigiouty. However, I don't see how you could craft a legal frame work without some ambiguity, which needs to be resolved by the courts at one point.
Unless your business model is dreck, I really don't see any issues with the GDPR as such.
A simpler, more elegant solution would have been better in my opinion.
I see that happening a lot. Actually, it's more trying to apply tech skills to societal issues, often without really thinking through the consequences or the bigger societal impact. Sidewalk Labs Toronto experiments provides a nice illustration of such issues.[1], [2] & [3]
One of the buzzwords that really gets my blood boiling is "Government V2.0".
Life and society is usally quite messy and attempting to optimize it very often yields rather undesirable consequences, or just outsources the externalities to other parts of society.
A simpler, more elegant solution would have been better in my opinion.
Sure, that would be nice. But I think that's extremely hard to do with crafting legal frameworks.
If tech has tought me anything in the last 20 years is that you will have people, entities and corporations just abusing the sweet bejeezus out of any loophole, which they can identify and get away with.
[1] https://www.washingtonpost.com/news/theworldpost/wp/2018/08/...
[2] https://www.cbc.ca/news/canada/toronto/sidewalk-labs-privacy...
[3] https://www.theglobeandmail.com/news/toronto/cracks-appear-i...
It's very, very unlikely, though, that the individual running the forum in his basement has to navigate the same legal minefields as Google or Facebook.
Implying that he has the same legal expenses as companies, whoms whole business model relies on getting around the GDPR seems to me a bit of a strawman.
[Citation Needed]. Every business pay a flat fee of $10M is a simple and elegant solution.
My own biggest problem with the GDPR — other than the regulatory burden, which disproportionately imposes costs on small challengers and effectively protects large pre-existing firms — is the so-called 'right to be forgotten,' which is really a privilege to force others to rewrite history. Among other things, it effectively mandates mutable logs, which is horribly insecure (logs should be in principle even if not in fact immutable), and at a higher level it grants malefactors the ability to legally compel others to refrain from true speech about them.
Other than that, most of the GDPR is pretty good.
If the EU passes a law and it takes armies of lawyers over two years of negotiating with the EU to find a compromise of what is and isn't included in the law (with the EU changing its stance regularly), then it probably isn't a good law.
It took a year and a half of wrangling for the EU to decide that internet advertising was not a "legitimate business interest" or "necessary to perform tasks at the request of the data subject" (despite the advertising being a primary source of funding to pay for the requested task). Then the entire internet advertising industry had just 6 months to design/implement/deploy a system that can meet the requirements and migrate all their users to the new platform (keeping in mind that their users have a financial incentive not to switch, since the old system is more profitable).
There's also the weird catch-22 of how it only applies to users with EU citizenship, but you can't collect, use, or store the information on whether or not they are an EU citizen without their permission.
It does not. The Right to Erasure is much more restricted than many people seem to realize. If you can articulate an Overriding Legitimate Interest, and find a way to balance that against privacy, then GDPR gives you a pass.
While I don't believe it's been tested in court, the general belief is that the Right to Erasure does not mandate deletion from back-ups. It's generally believed that an acceptable practice is to keep a ledger of "forgotten" accounts off to the side (or their hashes or something), and make sure that your restore-from-backup process deletes those from prod after restore. I know that logs aren't back-ups, but the same idea should apply.
The issue with compelled censorship may have merit, but I haven't seen a concrete example where I agree that happens. Like I said, the Right to Erasure is more restricted than many realize. But, Europe also ranks the importance of speech rights slightly lower than we do in the States, so it's possible that certain Overriding Legitimate Interest arguments wouldn't fly.
The main reason for that is Article 27.
For an organization that does not have a presence in the EU but for which GDPR applies, it seems to cost a minimum of around $500/year to comply. That seems to be the low end for the services that provide Article 27 representation.
That might not be too bad...as long as only the EU implements such privacy legislation. But several countries have talked about similar privacy legislation. If they all have something like GDPR's Article 27, it could quickly get out of hand.
You don't need an Article 27 representative if all of the following apply to your processing of personal data:
• the processing is occasional,
• it does not include, on a large scale, processing of certain special categories of data or personal data related to criminal convictions and offenses, and
• it is unlikely to result in a risk to the rights and freedoms of natural persons.
There's a lot of fuzziness in that. Even if other countries have similar exceptions, each country might resolve the fuzziness a different way, which could make it a major pain to figure out for which countries you need a representative.
by that measure we've solved pretty much everything.
when in reality the contrary is true: politicians are mostly career based opportunists and the inertial nature of our society pushes us to peace and prosperity.
Yes.
And you need to appreciate this before you start breaking things. Life can go from good to bad, not to better.
The problems start when politicians decide over smaller things that not everyone can agree on. I mean, damn, they'd be more than incompetent if they didn't get laws regarding murder right.
The latest screw-up of european politicians (the same who are responsible for GDPR) is the european copyright reform, which just shows a complete lack of both technical understanding and willingness to listen to experts who do understand the situation.
And where do those laws come from?
I'm not pretending the issues with politics and politicians do not exist, or that they are not enormous. However, a statement like "they have no good days" says more about one's own unwillingness to be politically active than anything else in my opinion.
One of the major achievements making civilisation possible is a judge or court that can decide who is right and and who is wrong, preventing BS from spiraling in endless retaliation and counter-retatiation. In a small system that can work with just one universally respected person or person of authority, but once you scale it up to an entire country codified laws are incredibly useful for this. Codified laws means we need people making laws, which is exactly what the entire job of modern politicians is. Sure, we could have civilisation without politicians, but our countries would have to be a lot smaller than they are; a justice system without laws just doesn't scale.
Well, no? Isn't that what is called "war"? You might argue that frequency of conflicts is lower, though I would be sceptical of that without further proof.
Having a transnational judicial system in the EU (as the most recently formed example) allows coorperation and trade to a much greater extend. Sure, the EU might go to war at some point, but the circle of people and corperations you can trust to respect law and written contracts is very big, no matter if a war is going on or not.
If you live in an area where absolutely nothing good has happened due to government in the last 20 years, your complaint about your local/regional government is entirely warranted.
Chalking it up to "politicians" as a whole is unhelpful; they aren't "all the same" (another thing I hear often), and if one thinks so, one is profoundly not paying attention.
I get that this can be dangerous for journalists, but shouldn't they maybe investigate alternative ways of contacting sources privately? Mobile numbers are not in any way secure or anonymous in most parts of the world anyways. Hell, here where I live you have to register with your government ID in order to get your sim card activated.
There are solutions other than proposing regulations or limitations on apps that benefit waay more people than it might inconvenience.
The app claims to stop unwanted robo callers...I'm sure those robo callers already have tried your method to look like something else.
It does not seem unreasonable for a service like TrueCaller to notify people that user-generated information about them is being irrevocably added to a globally public repository.
But if one wants to push for regulation to prevent the emergence of apps like TrueCaller, then perhaps we can start regulating robo-calls and sales calls more effectively? Then no one would need to install apps like TrueCaller in the first place.
Arguing that the real problem is robo-calls is besides the point. It's like saying if people just drove safer we wouldn't have to have seatbelts. Or if I had bajillions of dollars we wouldn't have to have this discussion, because I'd be off on a beach somewhere. It's marginally related at best.
But if that's the line you really want to take, TrueCaller could have a "That was spam" button, and if enough people click it then it could block the calls. The faux caller ID part doesn't need to be part of the service.
Google Voice offers a somewhat similar service, but it flips the onus around. When enabled the caller has to identify themselves before the call can get through, and then the recipient can screen based on that. This approach is wildly more discoverable for the caller (who the information is attached to), and similarly filters out robo-calls.
If they live in Europe, as far as I'm aware, they should actually also need the users consent if the information contains anything like a name (which it most likely does) and a way for users to have their personal data erased permanently.
Maybe there's some exception why they don't need to do this; can someone provide some more info on this?
Does every Wikipedia entry about a person in Europe need that person's permission before it can be published? Can I make Wikipedia delete my Wikipedia page permanently with no way for anyone to ever to recreate it? What about a blog post? If a write about a friend of mine doing something on my blog, do I need my friend's written permission before I can post?
I'm guessing that this answer is "no."
If there's a large enough public interest, then information about a person can be published.
And no, I can't just create a wikipedia page for my neighbor and post their phone number there, that'd be illegal and would get me into serious trouble.
> I'm pretty sure even in Europe things aren't as bad as this.
I get your point, but from my (European) perspective, it's the rest of the world where things are bad. I personally do quite enjoy the fact that, in theory at least, everyone is not allowed to simply publish my personal information as they see fit.
Actually no. Most of things I tell my friends I do by publishing it on the Web (e.g. Facebook, or other social forums).
> I personally do quite enjoy the fact that, in theory at least, everyone is not allowed to simply publish my personal information
You realize what you are aiming at is control over the speech of other people? I.e. you say "since other people call me Dave Whatshisname, now every time anybody utters the sequence of letters 'Dave Whatshisname', I want them to ask permission from me beforehand". This "personal information", taken at this form, is an insane construct - in fact, you are asking to control what other people think and speak in private (if the computer records are extension of memory, which effectively they are) about you. I can't imagine larger violation of privacy than that, and yet it is done in the name of privacy. Doesn't it feel weird?
Your post advocates a
( ) technical (X) legislative ( ) market-based ( ) vigilante
approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea.)
(X) No one will be able to find the guy or collect the money (X) Requires too much cooperation from spammers (X) Requires immediate total cooperation from everybody at once
Specifically, your plan fails to account for
(X) Lack of centrally controlling authority for email (X) Open relays in foreign countries (X) Ease of searching tiny alphanumeric address space of all email addresses (X) Asshats (X) Jurisdictional problems (X) Extreme profitability of spam (X) Technically illiterate politicians (X) Extreme stupidity on the part of people who do business with spammers (X) Dishonesty on the part of spammers themselves
and the following philosophical objections may also apply:
(X) Ideas similar to yours are easy to come up with, yet none have ever been shown practical
Furthermore, this is what I think about you:
(X) Sorry dude, but I don't think it would work.
That's the key difference with phones - phone numbers and call are (quasi-)centrally controlled - by your network provider. A simple legislative solution is just "user gets $10 discount on their phone bill for each spam call" and watch the problem solve itself...
Where does the $10 come from? (Who pays it? Who collects it?) Also, you just invoked a Cobra Effect. https://en.wikipedia.org/wiki/Cobra_effect
In India we have a national DND (Do Not Disturb) registry that anyone can signup for and choose whether to receive marketing communications or not, and what categories therein. The regulator has made the operators enforce the reporting mechanism along with penalties (monetary and otherwise) on the marketers for violations. But still, there are cases where a marketer may claim that the person receiving the call/SMS opted for it and signed up or had some transactional relationship with the company.
My only guess is that you misunderstand what is being proposed. The spammer is not part of the transaction.
The phone network is controlled centrally. Government can force handling spam by phone companies, the same way they can force them to give police call logs etc for the purpose of collecting evidence.
Further more, Robocalls usually are of a more local nature (not international). Government may instruct Police to investigate origins of Robocalls and enforce sanctions. A formal complaint process could be made , where any end user may file a complaint, Providing proof is trivial. Both for the act, and origin (Robocalls are advertising a specific product from a specific company.) A law could be made which mandates a speedy process for filing relevant lawsuites with small claims court, if found guilty the offending party will be levied a large fine.
This is from the top of my head. It probably contains many flaws. But it certainly doesn't seem impossible to combat Robocalls.
Honestly, I want disposable phone numbers (which are still compatible with public networks) something akin to email aliases. So if one number gets a lot of spam calls, I can just route it to /dev/null.
We need a complete array of legislative + technological solutions.
This suggests some fundamental difference compared to the US which maybe should be changed instead of a third party band-aid app with lots of problems, but again I don't know this difference and thus will refrain from judging...
Another thing is also that most people I know no more publish their telephone number in a (public) phone book, as it used to be still common 30 years ago. That's something where you easily can grab tons of private information from. How common are phone books in the US?
You could be a mountain man and value your privacy.... but if you just know someone who uses tech you are exposed in any number of ways.
In the US things like third-party doctrine have not aged well in the information age as just communicating with people can expose you in ways you can't ever control.
agreed. it's by design and i don't think anyone will be allowed to escape it
It's just convenience. People don't want add users names they just want it to work.
I believe signal are/were working on a way to work out this information without actually sending to the server
That's what I do. It would be impossible to communicate with friends and family otherwise. I just have to put a little more effort into figuring out who's texting or calling me. The app also still shows me people's (self assigned) nicknames in group-chats.
My only gripe is that I still have to give the app access to my photos. I wish there was a way I could give it sandboxed access to only the photos that it adds to the collection.
In practice, most apps would rather have their own in-app photo grid. Nothing to do with wanting to violate your privacy, I'm sure :)
* User clicks "attach photo"
* Phone asks, do you want to use "Photos", "Gallery", "Google Photos", "Camera".
* User wants to share a screenshot - so they don't know which to pick. They choose "Gallery".
* The built in gallery app doesn't show images apart from those taken with the camera. User goes back.
* User picks "Google Photos"
* Google photos only shows screenshots under a confusingly named "device folders" link in a hidden-by-default side menu. User doesn't find that.
* User tries "Photos".
* That turns out to be an alias of Google Photos put there by the phone manufacturer.
* User tries "Camera". That lets them take a picture, or to scroll through another list of past camera photos.
* User gives up.
And we wonder why apps don't use that feature of the platform...
The problem is that granting full save permission also grants read permission, it would be more ideal if those were split.
If you want to share a photo you just have to leave the WhatsApp app and start the sharing from the Photos app and select WhatsApp as the target.
Fun fact, that has technically been illegal for a while here in Germany. There's quite a few videos / articles on how "Using whatsapp is TECHNICALLY illegal". Of course, nobody really complains, so no legal action was ever taken against any user, but it's still a good excuse for me to say "I'm not installing that. It's illegal."
Whatsapp and other facebook apps, access my contact list every 3 minutes.
Even the 3 minute delay is annoying - it's common I meet someone, add them to my phone, and then want to send them a Whatsapp message and they don't appear in the list. I have to awkwardly hang around for a minute or so before being able to send them the message I wanted to send.
(for context, in most of Europe, Whatsapp is used pretty much like iMessage or SMS is used in the USA - wouldn't it be annoying not to be able to SMS a new phone number without waiting 3 minutes?)
WhatsApp used to function like that, too; you just added a new number in the UI. That was until FB decided that syphoning Contact info was lucrative. On my phones WhatsApp is still denied Contacts permissions and it works fine.
I know it is now too late for me as FB already have my contact list, but will do (and advertise) that for now on.
If we solve the spam problem, we can regain some privacy back.
This is very good analogy - in fact I think that it's even more dangerous because when it comes to Facebook people are slightly more aware about privacy-related issues. I'm pretty sure that TrueCaller extensively profiles users, links all possible connections, gathers data - Facebook might not know that one visited certain doctor or that one has some medical conditions, TrueCaller? Who knows. It is possible to gather a lot of data and build detailed profile just by linking who calls who.
Additionally according to HN comments [0] one doesn't just simply "opt out", truly terrifying
While it was weird to get SMSes about SoCal drug deals, the strangest thing of all with that phone was opening the Lyft app and being automatically signed in to someone else's Lyft account on the basis of my auto-confirmed phone number. Their active credit card was linked to the account and I could take free rides!
(I didn't... but it was very hard to sign into a different Lyft account when the phone # was actively linked to another, live account.)
I sent Samsung some feedback about this but don't think the issue was on their side per se.
Re Spam: Pre-screening, and people that actually say something useful to the (automated) screening service. Actual spammers should get fed to a blacklist (filtered for multiple confirmations), and organizations that prosecute spammers should be able to read THAT list. Everyone else has to use a more public API that's rate limited.
Yeah, that had me kinda puzzled as well. Sure, the app seems like a terrible idea, but ultimately it was one of her contacts who put that information into it.
Which suggests: everything this story describes also applies to intelligence and law enforcement services. Imagine you're conducting espionage, or are tracking money laundering or drugs smuggling.
Online communication is hard. The burden of security falls on every parties.
The real hard problem for an investigative journalist here is "Considering the ubiquitous nature of communication tech How do I handle my sources so they don't blunder before I even meet them ?"
The smart thing to do is to have a public number and a private number. It makes no sense to call cabs with the same number you use to contact sources or whatever.
This is easily done with dual sim phones and can be taken much further with Google Voice or other dial-in phone number vendors. It's not very complicated and if your life depended on it you could easily assign a number per person.
What's the easiest way to do this?
Most people use second-line apps like Hushed, or the traditional method of getting a second line from your carrier.
(or a double SIM phone, but then you still risk messing up yourself by mixing data / calling from the wrong number / etc)
It's a geographic (local) number to our office and costs £7.99 per month. Seems like it would be easy enough to add one for personal use as well.
You'll also need a SIP client. Some Android phones have these built in but you can also use things like Grandstream Wave. I have no idea about iOS, MAc aor Win but there should be several options for those.
Also didn't she tell the contact that maybe it'd be better if they didn't tell anyone she's a journalist? Sure, it's a pretty obvious thing, but I feel like in her situation, you'd make sure that they know, just in case, that it's a huge dickmove to make that sort of information public.
One of the biggest sources of spam I have is non-technically-oriented persons who I know either professionally or personally, that have my name and email address in their address book, who click "yes" to everything on their ios and android devices. Some of these particularly less sophisticated individuals have probably had two dozen unique apps from random developers copy the entire contents of their address book.
As a society we have most definitely moved in the direction that data about a person is somehow under their right to control: the right to privacy, the right to be forgotten, etc. We've subsequently run into numerous difficulties with this notion, such as the inability to warn our friends about bad actors, leading to different rules for "public people" versus "private people," arbitrary dividing lines, different rules for minors, different rules for individuals vs companies vs really really big companies, and a number of other abstruse rules about when or where you might be violating somebody's privacy, which seem to change significantly over the years and from jurisdiction to jurisdiction with no hope of ever settling down (because IMHO there is no rational obvious place for this to settle into).
Even if the laws were clear, universal and watertight, privacy is still fundamentally your problem. Laws will not control everybody else, and depending on everybody else to behave doesn't seem like a sane strategy for anybody. So you'd best keep your secrets to yourself and those you trust.
For this reason we need to think beyond the old ways of dealing with data.
Another big one is balance of power. If a entity — be it a state, company, individual or a group of indivdiuals — knows everything about you, they thereby create a asymmetry of powers they can leverage for their own interest. In addition to protecting the individual, privacy laws are also meant to reduce or limit that kind of asymmetry to avoid the social consequences that might be linked to it.
Not without a reason it is Germany which has one of the strongest privacy movements in the world, because many of them know first hand, what data in the hand of fascist and communist governments can do to the life of individuals.
When the Nazis marched into the Netherlands, the having the religious orientation in a central database was was made the difference to many lifes. And that is, what makes data different than somebody’s knowledge in their heads: if the Nazis march into your nation you could take the decision whether to tell on your jewish neighbour or not, while in the case of real data you can’t.
I appreciate the situation that the journalist found herself in, but if she wants her number to be a secret, she needs to make sure the people she calls know that, too.
I will file the information in this article as “good to know,” not “omg disaster”.
It's just you.
The example of the journalist is a very good example of exactly why this is such an extreme issue, but it really starts with the small things. What if you want to call someone, and not tell them your name? well, f#$£ you then, the app already told them. Don't want everyone knowing where you work? well f$%& you again, maybe somebody added that with your name in the app (just as the example of the journalist).
So now you call, say, your beloved grandma and your number shows up as "Henry the drug dealer". Maybe you don't even deal drugs, but someone a) thought it'd be funny or b) wants to hurt your reputation.
Or even worse, imagine you call a company regarding an application for a job. It's already a big enough problem that someone else posting a picture of you doing something stupid while drunk can ruin your chances of getting a job; now we're talking about attaching random, possibly personal, possibly untrue information to your phone number for everyone to see without even informing you.
This isn't a molehill. It's borderline criminal.
If you meet someone for the first time, and the person heard from someone that you're dealing drugs, and you tell her you don't, and ask them where they heard that, they might trust you over the rumor, and you'll try to eradicate the rumor.
There are differences, mainly in that the call receiver has greater power to reject the call based on the information they have.
I think the real story is in the interaction and how the app behaves, for the receiver. Were they aware that they were putting Chloe into the database? The article doesn't say. Without this, it's hard to judge whether the same thing couldn't have happened in a world without internet (imagine a small village). It doesn't seem to be entirely black and white.
A lot of people don't understand that it's silently uploading their contact lists, personal information and call behavior off to the internet.
The customer service agent in the article from truecaller is correct about the usefulness of the app. A friend of mine was able to track down the owner of a fraudulent dishwasher service center in Bangalore because of truecaller. The photo and name of the owner in the app attached to the business mobile number.
At least in the case of the tags, is that true? How do they think it works then when they get a call from a new number and it has the person's name / other information?
In your scenario, if someone wants to spread rumors about you in bad faith, they have to spend a lot of time and resources to make sure everybody you might interact with knows about the rumors.
A service like TrueCaller makes this much easier, which I personally think is very problematic. And as others have noted, another issue is that people even might not do this in bad faith. Just as a little prank, without realizing the potential consequences.
Reporting a number as spam should then just result in future recipients seeing a “Probably Spam” or “Spam” etc based on reported levels on Spam vs Non-Spam reports for the number.
But I do agree that the journalist should have practiced better opsec and advised her sources that they probably don’t want her name to show up on their phone if she calls them at an inopportune time such as when around the very people she is investigating.
Also, disabling outbound caller ID would have helped.
Lessons learned all around.
How do you secure against something that you're not even aware exists?
Maybe outsourcing operational security? But how can a journalist aford that?
I would expect journalists to have some opsec training by their newspaper/publisher given maintaining confidentiality is a given in this line of work. Even if they didn’t have such formal training, I’d expect them to pick up a few things like this with experience.
I agree. But I still think it's a tall order to expect a journalist to know every service and every app, which may violate their privacy and protect against such entities.
And then there are things, which you just can't control, even being aware of them.
As a for example: How do you, as a journalist, prevent that your pictures are tagged by others on Facebook?
Edit: Slight clarification
The reality is that phone databases like this are an invaluable tool in the war on robo & spam callers. I think that there should be an option in these databases to be able to tag numbers as spammers without the need to have their identity preserved. I don't use TrueCaller (I'm a YouMail user) but see numbers flagged all the time as "Real estate scam" or "Probably a Canadian Pharmacy" come up without revealing a name or affiliated company.
Truecaller, even without breach is a privacy nightmare. Even if one doesn't use Truecaller for privacy reasons, if any of their contacts use it; then their phone number + other details are already in Truecaller's database.
Before android 6.0, contact permissions weren't existent in consumer android devices and India basically being an android country lead to Truecaller's data trove.
If one wish to use Truecaller without uploading their contacts then they can use their web version, which is a progressive web app; it can be saved to phone & used like a native app. Just don't select 'Enhanced Search', it will upload the contacts from email which is used to sign in(better to use a Truecaller only email id for it).
[1]:https://economictimes.indiatimes.com/tech/internet/real-thre...
As a non-user you can unlist here: https://www.truecaller.com/unlisting
Edit: July 2010 release, 10M+ downloads, nearly 200k reviews. From long ago memory seeing names that have been submitted may be a paid subscription option.
would it stop new people from adding my number to their database?
ie, I unlist in May2019. i give my number to a new contact of mine in Aug2019. and they use truecaller. would that re-add my name to trucaller database, or would my number stay unlisted forever no matter how many new contacts save my number in their phones with truecaller ?
Unlisting to me seems like they only stop advertizing that they know your profile.
If the answer contains personal information, it's not okay to expose it to everybody in the world.
It is.
So I click on "suggest a better name" in a naive attempt to erase myself from the grid.
I can't because they "don't collect personal information about private individuals in the EU".
Had to make a fake Microsoft account via Sneakemail to even search it, though.
I tried to unlist my number but it said "Deactivation required", ie bait for me to create a real account?
...
> They send a SMS to any non-user whose number is entered to warn them someone is attempting to enter their number and ask them for consent. This would also be an opportunity to inform them about the unlisting option
For this to be effective in cases like the one in the story, the SMS would have to be sent almost as soon as the attempt is made to add the number.
In many cases, that would allow the person whose number is being added to infer who tried to add it. If the caller is involved in some criminal activity, that could be dangerous for the person who tried to tag them in some parts of the world.
Moral of the story: spam callers and countermeasures are a risk to democracy. And we'll have to decide, eventually.
If it's suspected spam it will tell me (I can also report spam calls). If it's a business listed with Google Places it will show the business name.
I personally rely on TrueCaller daily, and do not pick up any call that doesn't have identification I recognize. Otherwise I'd have to listen to bots telling me my Social Security number has been arrested, screaming at me in Chinese and people trying to get me to give them money for a myriad of reasons that I really don't have time to listen to. I get several such calls daily. Before, I was seriously thinking about just never picking up the phone at all. Now that I found TrueCaller, at least I can get calls from normal people or businesses that aren't shady and want to talk to me.
If you hate spam calls that much, it's very easy to not pick up a call from an unknown caller. I can come up with a dozen ideas just off hand that could potentially solve this spam issue far more elegantly. It's baffling that even this is up for debate and that there are people who would defend an app like this. This is not a philosophical or technical problem, this is not like spam emails, this is simply not a difficult problem to solve.
Would some variation of private/public key or authentication work? For example, if each number and the device/SIM or IP it is registered to have a unique key that must authenticate or handshake with the service provider to connect, then a spoof call with that number but lacking the key would fail, potentially be logged and reported to the FCC/authorities.
If no handshake can happen, call fails. If the number and hardware dialing out authenticates via key with the service provider or central store, call goes through.
Taking action on such violations today can only be done within the scope of existing laws on fraud, security, etc. That won’t work very well for these cases. The Indian Supreme Court also doesn’t understand technology and doesn’t rely on experts. It seems to go by whoever talks the loudest (based on the hearings in the case against the biometric based unique ID, called Aadhaar).
For the last 18 months my phone is on silent, no vibration, so I am completely oblivious to whether someone is contacting me. When I check my phone I catch up with any missed activity. It is hard to explain just how much better it is to operate this way.
That being said, I'm not sure why this is changes anything for reporters. People can already put a phone number online or share it with the government. The same precautions they would need to take without this service would still be valid.
The only solution I can think of is that everyone start using one-time numbers.
You still have a main number and a number "domain service". When you call someone you get a new number, the call receiver can get your name out of the "domain service" only if you have that number in your address book.
And I've found out that the best defence is a good offence: registering my number myself but with totally false information seems to supersede what other register about me. And that's what I did. Not with Truecaller, but with another app (CallApp) that seems less greedy with permissions.
> iPhone automatically suggests new contacts from messages you receive in Mail and invitations in Calendar, and from other apps. To turn this feature off, go to Settings > Contacts > Siri & Search, then turn off Find Contacts in Other Apps.
[1] https://support.apple.com/guide/iphone/add-and-use-contact-i...
You can add phone book apps there. Seems to be an iOS 12 feature, it wasn't there before.
Otherwise it will just use your contacts.
For that reason I've unlisted: https://www.truecaller.com/unlisting
Yea, good luck with that.
Has somebody a copy?
https://ifex.org/serious-privacy-concerns-raised-about-the-a...
Will improve the situation somewhat
The journalist has not agreed with the company, but the company is still revealing information that they connected to her through a third party.
Yet, the contract only exists between the company and third-party, and not the journalist.
There is a failure here. The company has assumed that the third-party has a right, when they likely do not.
I use none of their services and properties.
So are you arguing that it's right that they spy on me regardless? Like they do on any other human being who is not in a business relationship, whatsoever, with this company?
Pretty laughable - buy a new sim every week, it's not even hard to do in india/south africa. You can buy a new sim almost instantly from the corner store equivalent. You might get called by the local police if you buy more than 5 a month though - happened to me when i was testing out different carrier's data/sim services and bought 6 sim cards at once in india. They just took down my details and never bothered me again
I think what you mean to say is that it is not the app that committed the betrayal, it was the source who was enabled by an app that otherwise had a non-nefarious purpose. Which, fair point, but I don't think the article would disagree.