If data is shit, approach dies, because it's not economically viable. If it's just unethical, it will never stop.
It's not finished/perfect, but changes a lot of things.
I'll never pass recaptcha, but idc, i installed this on my wife's computer as well and i'm starting to explore a way i can make a ios build using the recent tethered jailbreak for ios devices (besides the most recent releases). One day, It would be fun to try a prank on a day I actually go into the office and exploin a vuln in the old cisco router firmware to try to get installed on other devices on the network and see if how many people actually notice the changes and/or start using the browser because the dont get ads anymore lol
I understand this case, but GP suggests to fake data for all apps. There are apps which are useless without location data. Or worse, you definitely wouldn't want to [accidentally] fake data for some apps, like a "SOS button" app.
If they want to send fake data then they should have the right to do that.
It's my phone, so if I want to set my location to another country I should be able to. Of course this should be on a per app basis.
An SOS button app? This is a niche usecase.
Not at all. In fact, more and more emergency services providers (i.e. the callcenters where 911 gets you) get your location automatically when you call them. I'm not entirely sure though if they only geolocate by cellphone tower, or if the handset also sends location data along with the emergency call. I vaguely remember hearing about this being "supported by all modern phones" or something, so it might be the second. In this case, you absolutely don't want faked location data because it could cost lives.
Those mechanisms are not running as untrusted applications on the OS anyway, I believe most/all of them are implemented in radio firmware.
Of course not everyone will run a Librem (understatement). But interesting ideas might find their way into more mainstream platforms.
I don’t know. It’s a good signal to me, a user, that it’s an app I probably don’t want to be using anyway. Also, it’s the perfect solution to change the supply and demand structure. If people keep using the apps, they won’t know the difference.
Finally, it’s their app and this their price (personal data). You can chose to pay with it or not. Just like with any other currency, the choice is still yours as a consumer, but you are not entitled to the product by default.
There’s a reason selling organs is illegal in most countries, otherwise people end up cornered into a position where they have no other choice.
Regulation doesn’t work (or doesn’t want to work, see the GDPR), the only thing left is guerilla tactics like poisoning the data so the ad-tech scum can’t tell whether they’re being lied to or are getting real data, putting in question the integrity of their entire database and them out of business.
What happens if your GPS is disabled right now and you dial an emergency number? Depending on the OS/phone we could either:
a) live with the consequences, or
b) have a bypass mechanism that can only be enabled for very, very special apps and emergency numbers
s/block/fake/ doesn't change that.
However, if everyone sends them garbage datathen they don't really have anything valuable then. The whole business model falls down.
At some point, our ad partner contacted us letting us know that some of our data was coming from blacklisted IP addresses--AWS, Linode, known bots, etc. Ranges where a human almost certainly isn't actually viewing ads, and told us to fix it asap or get out.
We ended up licensing an IP blacklist. It updates daily, and it comes with both individual IP addresses and cidr ranges. We didn't have time to write a fraud system to ban users, or do this check via our api. So my solution was to check every IP that came in through our load balancers against the blacklist and blackhole it somehow.
Since we were using nginx, I swapped to open resty because that comes with Lua already fully baked in. Next, I wrote a Lua script that just checks if an IP address is in the blacklist. It even had a caching module! That was awesome.
The real hard part was where to keep the IP blacklist. I came up with the solution to use Redis. If an IP address exists as a key in the Redis DB, it's blacklisted. This "if key exists" check is O(1) in Redis as far as I still know. So I wrote a cron job that runs every day to download the new blacklist, expand the cidr ranges, pipe the individual IPs into a second unused redis db, save the DB and restart production redis so it picks up the backup and refreshes its list of addresses. This list was massive, btw, especially when you expanded the cidr ranges, some of which /8. And the Lua script would just run a GET query on redis. If the key exists, open resty would just return a 40x code. Lua+open resty and redis are all super fast so we didn't lose much by checking every single API request this way.
After that, the ad agency was happy and we didn't get booted. But it was a super close call. Basically if redis didn't exist or wasn't as awesome, I'm fairly certain some engineers would have worked a solid 72hrs to write the php needed for an effective ban system that could go into production. I wrote the lua/redis solution and got it into production in an evening. So simple and really fun to write.
If this were to happen to a company getting bad data from a browser, either they'd have to clean up the data or get kicked out as well. Ad agencies pay for this data, so it's not like they're gonna turn into a charity and accept it. I'm sure it also messes up their datasets as well. I can't even imagine what it would take to clean data coming from a known good source/ip but with bad info. Yikes.
Fake data pollutes the stream.