The investigation into ToTok
objective-see.com
objective-see.com
I'm new to a game. I'd like to play with my friends without having to individually contact every single one of them and ask them if they also play the game.
One way could be to not return any identifiable information about others at all, but just a hash of each contact. (Kudos points if the host os returns a different hash for the same contact in different apps.) If that contact is known to the app, (because they've also installed it) then the app has all the information it needs to set up contact between two parties. The host os will probably need to provide a way to render a contact list for the app.
I'd be much happier with this arrangement. This way my personal data isn't uploaded to third parties simply because an acquaintance of mine wants to install some rubbish app. It's only if I install the same (rubbish) app will that third party finally get my personal info.
Host OS should also give me the power to determine what personal info it's given to any app. For instance, why did WhatsApp ever need my personal phone number while creating an account? It doesn't, and as such, should be regarded as an antitrust requirement.
Of course the same does not apply for example to LinkedIn or Facebook.
And it will fix all the ads/analytics/private information leaked by the app to all other SDK it use
But oddly enough Apple does not consider full-blown access to the contacts list as needing any kind of privacy settings.
Just as it doesn't consider per-app internet access as needing any privacy settings. I know for sure the flashlight-level app would need an 'always offline' toggle.
That's such a simple solution and innovative solution - just allow groups in Contacts, and let apps access only specific groups we allow.
I've not done much with mobile but have RE'd a bunch on the PC, and there an application which attempts to obfuscate its code in any way (e.g. classic case being a packed EXE) already warrants suspicion. At least there I always have the ability to open a file in a hex editor or even debugger for further inspection. IMHO this locked-down nature of platforms that makes it difficult for you to analyse the behaviour of the device which you ostensibly own is a huge obstacle to freedom and privacy in general. Ditto for all the other stuff like IoT which often communicates without your knowledge (and the traffic is encrypted, again ostensibly for protection on the Internet --- which it does do --- but with no way to inspect it locally).
It's true that not everyone has the skills to inspect, and that's a classic excuse for locking it down; but by making it harder to even get started and restricting that to "approved" people, there's even fewer motivated to try. The nature of Apple's platform is already disturbingly close to the situation in Stallman's classic story over 20 years ago: https://www.gnu.org/philosophy/right-to-read.en.html
I've been out of the domain for a while but pretty much all shareware licensing was doing interesting things. It was more or less an arms race and a pretty fun one on top of that.
IoT which communicates without your knowledge is one thing but IoT that used alternative encryption because e.g. stock bluetooth was easily sniffable is another. You don't want anyone to be able to just sniff your health monitoring data.
It is just a normal thing to accept access to Contacts or Photos, and all of a sudden, all of your data is being siphoned off.
The more I see this kind of stuff, the more terrified I am about the future. Data doesn't just erode away. 40 years later, it is going to bite us.
This is what Android already does. Without any special permission, an app can ask the user to choose a contact, a photo, a freshly snapped image from the camera, or various other things, and the app gets access to what the user explicitly gives it.
That is what almost every app should do.
It's terrifying to think just how fast some countries are moving toward full control of the internet and communication means for their citizens. From internet blackouts to intranets (just saw a BBC article on it [0]), it seems like the hot new thing for regimes is to take control of the internet because it's where people go for information.
As much as internet Jedi like a free/secure internet, the force of Empires (governments of ru, UAE, cn, US, UK, EU, etc) are striking back.
It is not "some" countries. It is "all" countries - they all feel the power/needs to monitor, control the internet.
The font sizes and colors in this article are all over the place.