Never-Googlers: Web users take the ultimate step to guard their data
thehour.com
thehour.com
When you get an Android phone new, there's a moment when it asks you to sign up or sign in with a Google account. There's a "later" option". Click that, and then remove the Google one-time startup program. Install F-Droid, and get your apps from there.
The mail program on Android will talk to an IMAP server. Find one to use, and you don't need Gmail. No ads.
On desktop, use Firefox, LibraOffice, and Thunderbird. Install Privacy Badger from the EFF. Videos are uploaded to Vimeo. I have a cheap web site on HostGator if I need to upload anything for someone else to look at, and a Github account for code storage.
I've been doing this for years, and don't seem to be missing out on anything except ads.
If there is tracking data associated with a phone but it's not associated with your real name, in what sense can you say they know you?
There is a risk someone (who?) can connect it with other data somehow, and then all the pieces fall into place. But maybe it hasn't happened yet?
So, this is all preventative. Nobody knows what's going to happen, but better to avoid tracking, just in case.
My phone has a cellular account with my name attached to it.
Anynymised hash caad09aeb361e1d6052c81db1db0e8523e34fca0909b6b2f21bd2ae39f9045e2 with > 0.90 probability of nocturnal location X and diurnal location Y is not anonymous.
Make sure none of your friends upload a photo with you in it, which basically means they don't take your photo with an Android phone.
If somehow your picture does get onto an Android phone, somehow make sure you aren't labeled.
If your friends who have added you on social media also uploaded random crap and tagged you in it, it could fool the facial recognition for your group of friends, but if <distant relative> who has no mutual friends with you on social media tags you correctly in their photos, it probably won't fix it for your friends since it will probably assume they're 2 different yous.
For example, if you don't actively disable it, your phone sends the names of all Wifi-networks in your proximity to Google, so Google can tell you where you are faster and more accurate than with GPS. Even if you disable it, your phone will still fetch GPS positioning information from Google unless you change that to use another service. And so on and so on ...
That's just one example, but there are multiple occasions where your stock Android phone phones home to Google.
Nope. Sending this data to Google requires an opt in on Android (Google Location Services checkbox in the device setup flow). iOS has the same location system, but it won't even let you opt out of it, and that might be the source of your confusion.
Not from fanaticism. It's just less hassle. Google is always getting in your face, wanting something or pushing an "upgrade" or or advertising something. Don't need that.
https://digitalcontentnext.org/wp-content/uploads/2018/08/DC...
> Oh even when the WiFi is off it will still scan for nearby SSIDs to get your position?
Again, this is opt in even on Google-flavored Android devices. There is no digging through settings required — the opt in checkbox appears in the setup flow. On iOS, there is nothing you can do to stop your device from doing this.
Do you honestly believe that Google has less data on Android users, compared to Apple for iOS users?
> Again, this is opt in even on Google-flavored Android devices
No, it's opt-out. For example see http://www.youtube.com/watch?v=b2uSGGl0LWc&t=3m41s - setup on a Pixel and all the location stuff is on by default.
> On iOS, there is nothing you can do to stop your device from doing this
Oh, how do I turn this on for iOS?
When I turn off WiFi it says that "improved location accuracy require Wi-Fi".
It's amazing that somebody who works in tech would fall for that marketing when it is so obviously a lie. Consider that iOS sends every GPS location ever requested by your phone to Apple, and there is nothing you can do about it. Likewise, you can't stop Apple from knowing about every app you install on your phone or every address link you click on. If you want to develop apps for your own device, you have to hand over card details. "Out of the box," iOS tells Apple every phone number you SMS and when. And worst of all, if you're Chinese, you have no privacy at all on an iOS device.
> Do you honestly believe that Google has less data on Android users, compared to Apple for iOS users?
For users who care about privacy, absolutely. For users who care about usability, Google has more data but provides a more useful experience. That's a trade-off that is possible to make on Android. On iOS, you are stuck with poor privacy and worse usability.
> No, it's opt-out.
You are correct. That is still much better than not being able to opt out of sending every GPS lookup to Apple at all.
It's not and it's not even suggested that it exists as a feature on any of the Android devices I ever owned or played with. The dialog for setting up location has no option that absolutely turns off every method that is directly used to determine/infer location. Ok, this is also a user education problem but Google certainly isn't doing anything to suggest the "precise location" won't just provide a precise location to the user.
And most people take the common sense approach and assume turning off WiFi will actually turn it off. Instead not only are they still tracked, they lose battery life too.
Sure. But Google being the immoral company it is has instead chosen to lawyer up, tell people it's compliant with the GDPR, and keep on collecting everything it can get its hands on anyway.
If you are not signed in, for extra safety you can also disable google play framework and all google apps. You won't get things like fused location, but hey, that one requires connecting to google services too.
The only way to verify this is to install some system level firewall and carefully inspect all logs.
Until you do that, we simple don't know.
Sure, you won't know whether the vendor of your device didn't modify the firmware itself, but what motivation is there for Samsung, Sony or Huawei to help Google to get user data?
I'm not sure about their motivation, but several vendors are famously known for bundling spyware with their phones. Usually within the keyboard app or some telemetry system.
> bring your device to AOSP-like state
That's a solution but is impossible without having a clean ROM at your disposal. Google's spyware is contained within Google Play Services, which you can't get rid of that easily.
Yes, you will get better control over software that runs on your device. You will pay for it by going through more demanding process and the risk of having instabilities, that nobody except you cares about.
Citation needed.
The problem is that while Android is OS, most apps use functions and OS-level API's available that are only available through the Google Play Services application. This is a good thing for people who have phones from manufacturers who don't update the OS's, but it's a bad thing if you don't want Google Play Services to run.
You don't want Google Play Services (or Google Mobile Services) to run because if it's running, it's talking to Google (even if you never configured an account) in order to use their hosted API's like location detection based on nearby Wifi AP's, push notifications, malware scanning, etc. Whenever it connects to those hosted API's, it POST's a unique device ID.
This is harder than it sounds. The current versions of the stock keyboard, clock, calendar, contacts manager, and even phone dialer all have Google Play Services as a dependency.
Only for apps on the Play Store. This is much less restrictive than iOS, which requires you to use APNS for notifications without any workarounds. Also, Firebase is not "built into the OS" and doesn't exist at all in AOSP.
> The current versions of the stock keyboard, clock, calendar, contacts manager, and even phone dialer all have Google Play Services as a dependency.
Those aren't "stock." Those are Google's apps. Many devices don't even use Google's by default. The AOSP implementations don't use Google Play Services at all. It is trivial to install replacements on even Google-flavored Android devices that don't use Google Play Services.
Compare to iOS. Apple knows every app you ever downloaded, and there is nothing you can do about it. Every time you click on an address link, it sends the address to Apple, and there is nothing you can do about it. Any time an app looks up your GPS location, that location is sent to Apple, and there is nothing you can do about it. If you want to write apps for your own device, you need to give card details to Apple, and there is nothing you can do about it. That is what data collection built pervasively into the OS actually looks like
Apple Maps doesn't know who you are. Siri doesn't know who you are. iMessage is E2E encrypted. Locations are anonymous. If you actually cared about this stuff, you'd be applauding Apple.
> If you actually cared about this stuff, you'd be applauding Apple.
If you actually cared about privacy, you would be damning Apple for handing over the iCloud keys for Chinese users' data to the PRC allowing the PRC to implement dragnet surveillance on iCloud documents, iCloud email, iMessages, etc. to find and disappear dissidents. This is worse than anything Google or even Facebook has done by a stupendous margin.
> iMessage is E2E encrypted.
Since Apple controls the keyserver, Apple has the ability to wiretap any iMessage conversation (https://blog.quarkslab.com/imessage-privacy.html). Since China controls the keyserver inside the great firewall, China has the ability to wiretap any conversation that occurs with at least one user in China. Compare to Android, where you can set Signal as your default SMS handler. One pretends to support privacy, while the other actually does.
> Apple Maps doesn't know who you are.
But it does know where you are and every address link you click on. From there, you are very easy to deanonymize. Compare to Android, which lets you run fully offline mapping applications and set them as the default address handler. Apple's apps are systematically both less useful than alternatives and less private than other alternatives. The only thing that saves them is slick marketing.
I've also got Google Analytics black holed in Firefox, and run an ad blocker of course which (I hope) catches most of their trackers; this just seems good for anyone to do though, even if they're not giving up Google's other services.
I'm confused by the lengths people have gone through to "protect" themselves from internet giants while freely giving away their info to credit card companies, traditional retailers, small businesses. Credit card transaction data have been sold for years without most of us knowing about it. Small startups, boutique stores rarely have the security or data governance resources to ensure your data is stored and used properly. Data breaches are common even at large brick-and-mortar retailers.
Given the state of data security outside of big tech, my best option is to trust only big tech.
A mom and pop store I give my credit card to in town can't track me across the Internet and correlate my browsing activity to my purchases, for whatever nefarious purpose, for instance. They can't read my email and correlate it with my location data. And so on. That's the difference.
Worse, Google in particular is financially incentivized to track me and perform all that correlation for the purposes of advertising. A family owned business I visit downtown, not so much.
You are invalidly generalizing. I try to eliminate all contact I have with the tech giants, and I do not have a credit card, I am at a privacy respecting bank (GLS Gemeinschaftsbank), and I use cash.
Additionally, by sharing your data with a company, you give that company power over yourself and others by enabling them with the knowledge they have over you. Considering this, it is less problematic to give access to data to a small company compared to a tech giant.
You do you, but I'm happy to get free airline tickets and other perks from using my credit card at the expense of....... having someone else know I bought a mechanical keyboard last month?
I respect your choice but I honestly do not understand why people go to such great lengths to hide mundane data. I'll tell you the color of my underwear for free, I don't care.
More significantly, you are understating and trivializing the kind of information that many services force us to expose. If you share your buying history, that may reveal locations, your movements, your schedule, etc. What a set of data reveals is not up to the one the data is from, but the one analyzing it. For you it is mundande, for them it is enough.
I would be more worried about scams, bad investments, bigger purchases, or a pattern of impulse buying.
That's not why you're getting free airline tickets. You're getting them because you're a) subsidized by people who carry a balance and b) pay higher prices on goods to make up for the merchant fees, while being partially subsidized by those people who pay with cash and aren't getting free flights.
However, if you're worried about data mined from tracking your personal behavior, which is what the users here are worried about, then it makes sense to spread your data out. Traditional stores are not going to send each other your transaction history to build a profile of interest and personality, and each store won't have a complete enough history or even the expertise to mine it.
"Traditional" as in "before the age of Amazon"? They do, through store rewards cards. Harris Teeter knows what I have bought and has figured out what I only buy on sale, Target can identify pregnant women with stunning accuracy, and I'd be surprised if other retailers didn't do similar stuff. You're probably thinking of independent/mom and pop shops.
What is more likely to impact you negatively: Google building an internal profile based on your information and targeting ads based on it or your card information being stolen from insecure smaller vendors?
Obviously those 2 choices are picked arbitrarily but they may explain why the OP chose to prefer the former over the latter. I would think every time we decide to share some of our information we do so because we stand to gain something (otherwise why do it) and it's up to us to decide if what we stand to lose is worth it. As technically minded people we tend to be more focused on technical problems and what we consider more dangerous may be more related to our familiarity with the subject matter rather than the objective potential negative impact it has.
As for the magnitude of privacy invasion regarding financial transactions, I feel very safe in saying the data Google has about/from me is far more revealing than relatively opaque transaction logs.
Where are you meeting people who fit the description you give?
In practice, yes, most of us are clueless. In theory, if you've seen one of these[1] (and if you're an American, you most certainly have) then you "know about it." The Gramm-Leach-Bliley Act has a whole lot of room for improvement, but the single-page uniform privacy disclosure it brought to financial institutions is infinitely more consumer-friendly than 90 pages of 10pt grey legalese used by big tech.
[1] [PDF] https://www.ftc.gov/sites/default/files/attachments/press-re...
No, we don't. We are just not given a choice by this bullshit capitalist society. Just like many people "freely live on the streets" or "freely get murdered by the police".
That presents a challenge for resident Gregory Kelly, who can't get enough of the stuff. He'd rather not truck the 40 miles or so to Columbia to stock up on it, but he's also loath to buy it from the company's website, which he says is riddled with tracking software from Google"
Somebody get this man a Firefox Privacy Tab
To demonstrate how implausible this is:
* Toyota Prius (hybrid) - 50/53mpg
* Honda Accord (entry level sedan) - 30/38mpg
* Ford F150 (small pickup truck) - 20/26mpg
And that’s only for the latest year models. If his truck is 10+ years old or larger than F150, expect mpg to be way more disastrous.
I hope Mr. Kelly is a pseudonym for the article. If not, Big Geez now knows his breakfast cereal proclivities.
For what it's worth, I'm in full sympathy of his plight, and agree that advertiser surveillance is creepy, dangerous, and evil.
To get his cereal delivered the shop needs his address, doesn’t it? So google could know that the person at that address likes those cereals. Unless the shop is not sharing the address with google ( which it should not, but can you count on that?)
wonder if he also prefers cash? although this article is google-focused, not more generally on privacy which would presumably involve defeating credit card companies with cash.
i'm wondering what order of magnitude of people would do the same across the country. tens of thousands?
I presume the lack of cash tolls is semi intentional. I mean all cars are being photographed, as you can borrow and EasyPass.
So making collection easier not only handed over our privacy, it made doing it (i.e., tools) more often and for less money.
And there's Liberty on the side of the road...death by one penny pricks?
I think we have closure on the American experiment. Laziness/convenience trumps anything else.
What prevents the surveillance state from just putting some cameras on the highway?
There are cameras there whether it is a cash toll or not.
so, it's either a highly connected society, or more cynically, a high surveillance society.
in a sense it's a self fueling machine: you need to have that data linked to collect outside the tool booth, which requires data linked from DMV or whatever local equivalent is, then strong (enough) justice system/penalties/enforcement to get those who didn't pay at toll booth to pay, etc.
you can bet that the smarter investment, despite these drawbacks, in less "advanced" countries is to have manned tolls because there's a high probability that they won't be able to collect using the sort of infrastructure upon which this relies.
You certainly can do both open-road and accept cash, but the traffic for the cash booths can back up onto the highway and slow down open-road traffic as well.
Ads have been in Gmail for many years, they just became more obvious with their recent design changes.
>Joshua Greenbaum, of Berkeley, Calif., said he pays about $100 per year to use Microsoft Office 365 software that he says has better privacy protections than Google's.
At least he's willing to put his money where his mouth is, though he's probably still using Windows. If I had a dollar for everyone who complained about Google but refused to self-host or pay for someone else to host their email... (Also, people who use free VPNs to avoid tracking. It's free for a reason.)
That'll show em, post on facebook about it...
1) The IP only changes when your lease expires or you manually renew it. This is not a normal part of starting an incognito session. Google has a confirmed identity (such as by being logged into a Google service) of tantalor at IP x. A few seconds later IP x shows up at SteamyHotPornSite.com that's running Google analytics or otherwise providing tracking for Google - a recent study of 22,484 porn sites found Google trackers present on 74% [1]). That's 100% tantalor.
2) Even in cases where the IP does change, it's constrained to within a group. As most dynamic IPs are also geomapped, it's often a relatively small group. Now what information is exposed during incognito can be cross-referenced against a very small group of potentials. You can likely hit near 100% on this as well.
And that's just one datum, though granted it's quite a useful one! Incognito should be seen as a tool that does little more than disable any cookies you have and automatically [kind of - depends on your OS] deletes your local browsing history.
[1] - https://www.businessinsider.com/facebook-google-quietly-trac...
E.g. from this ad tech company[0] specializing in IP tracking (take it with a grain of salt):
> In fact our research has discovered many homes that have theoretically dynamic IP’s, but have held the same IP for multiple years. Because of this recursive reassignment the typical location targeted by El Toro has held the same IP address for 7 months.
0: https://www.eltoro.com/how-long-does-an-ip-address-stay-atta...
https://www.businessinsider.com/eric-schmidt-googles-policy-...
The problem with such a policy is in thinking that cultural and legal boundaries are fixed and inviolate. The very process of repeatedly pressing up to a border may trigger the backlash which moves it, and can leave the fate-tempting party in deep water -- with its own culture, processes, amd institutions unable to adapt, or with goodwill so badly burnt it never recovers.
Google should have seen this coming long ago. It's a colossal failure of leadership that they've not.
Unfortunately, Google is far from the only company that tracks users and collects data on them, so even if you were to somehow completely avoid Google tracking and data collection, you'd still be subject to tracking and data collection from others.
Kinda creepy, actually, when I say it like that. If Google is just a front for NSA then I'd say Big Brother is complete.
dammit grandpa get to the point!