Go through your family's phone settings and turn on all the privacy features
twitter.com
twitter.com
The much more likely outcome is that you’ll be marked as the odd duck in the family, and they’ll make a mental note to not let you handle their devices in the future.
If the goal is to make people care more about privacy (or really anything), an approach that breaks existing workflows and shrugs off that breakage as being a good thing isn’t really a winning approach.
That can be a blessing in disguise. :)
My family already cares about privacy, they just find it incredibly hard to navigate the maze of settings and figure out what you can disable and what is hiding somewhere doing nasty useless shit.
When I disable a setting for them, I ask if they use the feature, explain what it does. Or in many cases, we look it up together, because DAMN they made that shit hard to understand.
I also ask what apps they use, and if I know any, suggest alternatives.
Usually they're happy to get rid of a couple of useless apps that were giving notifications and other screen spam.
In general they're happy that I help them. It's ridiculous that I have to, because my family is not dumb and they want to figure it out, it's just that if you don't deal with this shit every day, it's just a swamp and you tend to throw your hands in the air and give up.
Unless you have access to an infinite pool of IPs and mobile numbers and rotate at frequent but random interval (and get your friends to do so as well especially with their numbers) it's basically impossible.
Better just not use scummy apps and services. If they can't be bothered to respect your privacy then find something else which can. You might need to pay for it but at least your privacy is safer.
Funnily, I wasn't able to read the linked post easily with my web browser privacy features (well, noscript) enabled.
I think generally it's a bad idea to impose whatever one perceives as "good" on others. And if a user doesn't care and understand what's going on, merely restricting some of the spyware they currently have on an Internet-connected device with private information on it wouldn't even protect privacy much: I think (based on a couple of times I've observed the process on Android smartphones) they had to allow all that access on installation in the first place.
I find it really troublesome that Google is allowed to blatantly lie to their consumers about the required permission by implying the app is utterly broken while it actually still works. Next year I'm going for an iPhone but as I can see it's not the promise Land yet.
It's not a "blatant lie" if it actually breaks APIs.
So it's a very minor inconvenience that you now have to type a few digits from an SMS instead of that happening automatically.
My prediction: If people stop allowing this feature becomes even slightly popular, they're gonna use longer codes "for security".
It was deemed important enough that Apple followed by implementing the API in iOS12.
Lack of this is one of those recurring struggles how you know the software isn't written any more for the benefit of the end user. There is no reason for this adversarial position (well, there is, but it has to do with you as a product, not a user).
I don't really get it. I don't think their recommender is that broken, so it seems to me like they're deliberately injecting those recommendations contrary to their expectations of what I like. I suspect those videos represent the content youtube wants me to watch, rather than the content they think I want to watch. Probably those videos are more profitable for youtube.
What I’m trying to say is maybe YouTube’s recommendations are very loosely based off your viewing habits, but they would rather you watch Doug demuro’s highly monetized channel over randomjoeschmoe’s excellent non-ad enabled review of a 10 year old car
You get it perfectly. They'll try to make any connection they can between what you want and what they want to show you, but they'll just throw it in randomly if they can't.
Stereotypes exist for a reason. But that reason isn’t optimal - it’s just convenient.
I go there either because I'm linked to a specific video, I'm searching for something specific (too specific for the recommendation algorithm), or to check if any of the few channels I follow have posted anything new.
I don't watch popular youtubers, I don't listen to (currently) popular music, I don't watch the television, I don't watch sports. I even get make-up tutorials, and I'm a male! That's all the front page of youtube has to offer to me: things that I'm unlikely to ever click on.
>I feel like without a recommendation algorithm the site would be largely useless?
That's because for you and many other people youtube is an activity, like turning on the telly. You open youtube and you expect to be entertained, and that's what the recommendation algorithm is for. For me, youtube is a tool: I open it, search for something, watch it, then close it.
I also have a lot of niches I like to learn about and travel monthly to Asia where I have 18 hours each way to watch videos. YouTube let’s me download videos onto my phone.
More seriously, if a person was known to be a privacy nut, I would serve them randomized yet diametrically opposed "advertisements" (say barbie dolls). Periodically when their guard was down I would throw in an ad for a firewall or rfid blocking wallet.
Switch the default browser to Firefox and change the default search engine too. Firefox will protect them from all the third-party, cross-site tracking. It's faster too.
And if this causes an issue for something in the next day or two, you're still there to help them out plus the previous default browser is still there too.
But they both used Chrome. Today I switched them over to Firefox with uBlock Origin. And with some wankery you can make firefox look like a reasonable Macintosh application.
https://i.imgur.com/VaMnux3.png
But so far so good. And, as I have commented in the past about the pihole and when people leave the wifi at home they worried their phones were compromised because ad people have lost their fucking minds.
So now the twins can can have a reasonable internet on their computers.
Please can you un-ignore that in one sentence? ;-)
On the other hand, too much frustration is just too much, so you definitely need to balance.
Ublock has broken all kinds of sites for me, and I don't know if it's because these sites used a third party JavaScript library or some video provider or what, but I know to turn off all the privacy tracking things I have in my browser when a webpage looks broken, and often that fixes it.
Also, the default behavior is to first ask the user, and with iOS 13 you get again several notifications from the OS that a particular app used your location multiple times over the last X days, with a scary map showing where the app requested the location too, and that’s yet another chance to change the setting with a single tap. Happened to me with Waze.
Bottom line, his complaints are baseless. And no offense, but if he cares so much about the privacy of his family, why is he not encouraging them to quit using FB?
Edit: moved to root, was initially a subcomment by accident.
I'm an android user right now, but having the option to see when/where app take advantage of their permissions sounds amazing.
What is this iOS feature called? Does anyone know of a simple way to do this on Android?
[0]: https://techcrunch.com/2019/09/19/ios-13-security-privacy/
Yes. It's a secondary revenue stream. Even if they don't sell it now, if it turns out they have a reasonable good dataset they can sell it later on, especially as the revenue starts dropping.
Also make sure to enable automatic data deletion under https://myactivity.google.com/myactivity and Location History if for some reason you want to keep those on.
Their business relies on it. They'd still be collecting it and using it as a signal for ad-targeting among similar nasty things in a plausibly deniable, not immediately obvious way.
Sure, you don't have to believe what they say; but then again you should also probably stop using Apple, Microsoft and any other closed software as well. After all, they collect data too and they could also lie to your face about what their devices send to the server. It's not a useful way of thinking.
Besides that - explicitly telling Google you don't want data collected is strictly better (even as a grounds for class action lawsuit) than not telling them that.
Regarding Apple, Microsoft, etc, their business is based on selling hardware, software & services. Ads make a insignificant part of their revenue, so there's less incentive to be malicious and put the rest of the business at risk for a tiny share of the profits anyway.
Google? Their entire business is based on ads, there is no other way for them to stay afloat given their current expenses. So there's much more incentive there to be malicious, and they've got both the lack of morals (cf dark patterns) and the engineering talent needed to do the bad thing in a covert, undetectable manner.
Google currently is not GDPR compliant. I'm not overvaluing incentives, I'm just looking at facts.
I was sorta surprised that wasnt the most coveted prize of the exchange that the majority wanted to steal. About half said they didnt want any creepy listening device in their house.
"And even if you turn off location services for an app, the app may still get this data by examining the metadata from your photos. (I’m not sure if iOS13 fixes this.)"
So is this fixed in iOS13 or not?
I mean, people upload pictures of themselves, their family members, their homes, offices, places they visit, to a third party, such as FB. Is really the location stored in EXIF headers the biggest issue here? Think how much can be automatically extracted from content these days.
I don’t mean to diminish the importance of the location leak, I just find it odd what our collective priorities seem to be, even among the tech literate.
That said, I'm also surprised a cryptography expert can't figure this all out:
> It’s sort of amazing to me how hard this has gotten, even on iOS, which advertises itself as the “privacy” OS.
Let's get this bit out of the way: iOS is the privacy OS. Android apps were using the camera in the background without user knowledge until Android P: https://www.theverge.com/2018/3/7/17091104/android-p-prevent...
And what percentage of Android users have Android P or above as we approach 2020? 30%? Less?
In the past, granular permissions did not exist in Android. You were simply given a list of permissions that any given app would simply use at any time and you either downloaded the app or you didn't.
Final example: Android lets apps simply write and read to/from the file system anywhere they want, until very recently (Android 10?). If I'm not mistaken, that means that any app that's granted permissions to the file system could just read common storage locations like your Facebook cache directory to gather personal information.
> My wife asked me how Facebook knew she walked by a particular store yesterday, so I dove into the Settings. What a mess.
iOS does not give these permissions away. The answer is obvious: his wife gave Facebook location access.
> First, there’s this “Privacy” tab in iOS settings, but under it you’ve got this ridiculous and ever-growing list of crap. Every app appears multiple times, and you have to know where to look.
On the one side of the ring, people ask Apple to make things simpler, and on the other side of the ring people ask Apple to expose more granular control. There's no winning here.
And anyway, the organization is quite logical. It's organized by permission category.
> Browsing the “Location Services” tab alone is a nightmare. There’s no way to sort by “Always”, which is usually the particularly bad permission you care about. (Although “While Using” is a bit ambiguous too.)
How many apps do you have where sorting is an issue here?
Also, "While Using" is not ambiguous. It means "While Using." The text on the original dialog was "While Using the App." What else could it mean?
This is an interesting criticism because it's another piece of granular location control that Android either doesn't have or gained very recently.
> And don’t get me started on this “Bluetooth” tab. Why do any of these apps need direct access to my Bluetooth other than crappy tracking?
Both iOS and Android basically gave away Bluetooth access because it was never assumed that it could be used for anything serious. We all know better now and Android 10 and iOS 13 both added this piece of granular permission in. I can tell you that my Sony Headphones app and Apple Music most definitely need access to Bluetooth.
> And even if you turn off location services for an app, the app may still get this data by examining the metadata from your photos. (I’m not sure if iOS13 fixes this.)
This is not necessarily something "to be fixed," this is simply the fact that granting access to your Photos grants access to your Photos. If you gave your photos metadata in the first place, that metadata will be there. I do admit that I'd love some more fine-grained control over this (although you may notice that the iOS share sheet does add some control over whether to include location data in iOS 13 - I wonder if any other popular smartphone operating systems have this built in and installed on >50% of their install base?)
You're advocating permanently crippling this hardware over privacy theatre. If you don't want apps to have this access, deny the permission as a user. But stop advocating crippling the most powerful pocket computers we have for everyone else please.
More examples might include apps that interface with smart/IoT devices.
Simply saying "no app gets bluetooth access" just to remove a permission screen would diminish the usability of the device.
He's upset that he had to spend time as IT Support with his family, not that Apple or anyone else did something wrong with the OS.
having a set of permission for each app is not sustainable and annoying. anything annoying is not going to get done. last time i had to go through all my apps to make sure they all have the correct permissions for notifications. i do not want to have to do it again. but i will if i ever factory reset or get a new phone. why aren't there global sensible options?
some apps won't work if you don't grant access to photos or camera. they claim to be "camera" or "photo" apps.
are we going to pretend there is nothing to fix here and shift the blame on OP or his wife? seriously?!
What none camera and photo apps stop working if you don’t give them access on ios?
There is nothing to fix. iOS gives you granular control over location services or a choice not to allow anything. What else do you want?
That's only true for the "shared" storage locations (SD card, and internal emulated SD card). Unless facebook is braindead they should be keeping private data in app storage, which is only accessible to the app itself (each app has its own Unix uid, and app storage is mode 600).
Facebook is probably doing it right but someone else might not be. I’d rather the operating system prevent the bad action in the first place.
It's like, if a Unix program made private files world-readable by default, you wouldn't blame Unix for providing permissions in the first place.
There’s an option to toggle between Off / Wi-Fi / Wi-Fi & Mobile Data for all apps, and there’s a list of every app that uses background app refresh with a toggle button next to each one if you want finer-grained control.
How can that be made way easier?
I just feel like, iOS gives this great sense of control and so it's easy to become complacent without realising there is this backdoor of sorts to a lot of info (you can infer location based on IP collected from Background App Refresh for example).
At more than 50% for US and rising.
> Final example: Android lets apps simply write and read to/from the file system anywhere they want, until very recently (Android 10?). If I'm not mistaken, that means that any app that's granted permissions to the file system could just read common storage locations like your Facebook cache directory to gather personal information.
This is not true at all since cache directories and other private storage is and have been isolated since the start.
Can you please not spread misleading information about things you're not informed about? It just fuels dumb brand fanboyism.
Even if you’re stuck on iOS 10 with an iPhone 5 your security situation is better.
I may be wrong about the particulars of Android isolated file storage but that doesn’t mean I intended to spread misinformation. In fact apps are allowed to carelessly write private data anywhere they want if they aren’t designed well [1]. Apple’s idea to completely disallow apps from accessing common storage and rely on the share sheet was, from a security perspective, the right call.
And I’m not a fanboy. I use Linux at home. I’m not into Apple’s brand beyond their phones being the only viable option for someone who wants a phone that lasts longer than three years. You cannot buy an Android phone that will get 5 years of security updates, and I don’t think a shelf life of 2 or 3 years is acceptable for a piece of hardware. 5 really isn’t even enough: we wouldn’t accept that for our personal computers.
You are making tons of incorrect assumption in your posts. Where exactly do you get your information from?
This is a privacy discussion. Please pause your unpaid missionary work for a moment.
For someone not familiar with "move fast and break things" and the huge toxic part of the tech industry, it would be reasonable for them to expect that a high-profile company such as Facebook or Google is complying with all local laws & regulations and isn't acting in bad faith otherwise they would've be fined out of existence long ago. After all, we have regulations for things like food safety that mean you can buy any food item from a mainstream supermarket and be confident it's safe to eat, and there are severe penalties to ensure that remains the case and deter potential offenders.
It's totally reasonable for these people to not be suspicious when they're downloading a popular app that's been around for decades and used by everyone and not suspect bad faith or malice when the app asks for contacts or photos, because regulation is supposed to crack down on fraud and lies (which dark patterns are).
The problem is, of course, that the law hasn't caught up with tech and with all the corruption... I mean lobbying - around I don't think we'll even get there. If an individual lies and gets access to something they're not supposed to it's called fraud and there are real penalties for that, even more so if the fraud happens on a computer (and the definition of that is so loose even implied legitimate access to a web server could be argued to be "unauthorised access"). When Facebook lies to you regarding their usages of the data however, it's no longer fraud nor hacking, even though it fits the bill perfectly, including the "on a computer" part. This is the real problem.
I am not saying privacy isn’t important, but it is a false equivalence to compare it to food safety. (In the US at least.)
It's very difficult for everyone, regardless of how "technical" they happen to be. It takes time to read through the options and actually understand the implications. These things change too, sometimes dramatically. There's a lot of settings.
It is right for people to feel a certain level of anxiety about this stuff and to be a bit angry. I am more concerned with folks that uncritically put their trust in the apps they download and their phones.
Sadly, it will take quite a few more high-profile "privacy disasters" for the masses to truly get wise to the risks.
1. UIImagePickerController - This opens the system image picker and ONLY returns the user selected image to the application.
2. "Access Camera Roll" Permission - This is what WhatsApp, Facebook, etc. use so that they can show their own image picker UI. It just gives the app permanent access to APIs that can retrieve photos.
Both leak EXIF information to the app, but the first one only leaks the information for a specific picture.
Or EU should grand couple of billions to someone to do it.
Privacy should be number one feature for every OS, and every browser.
Either that or we need laws to ban location access and web tracking altogether.
I"m really glad that Firefox is (barely!) holding back a full-on Chromium/Webkit monoculture.
Also, I am donating each year real money to Mozilla, without using its browser. Call it FUD, call it I don't know what, but on desktop I am using Chrome, with the usual ad-blocking plugins, on Mobile I am using Brave.
Bottom line is that Android without Google Play services and Google Play Store doesn't work well: most apps are only on Google's store and use Google specific APIs all over the place (after all they are treated mostly like normal Android APIs). And of course Google doesn't let you ship those in an Android fork.
[0] https://twitter.com/matthew_d_green/status/12095023270250905...
He also complains about the "Bluetooth tab" in privacy settings, saying that companies would only need this permission for "crappy tracking". In essence, he makes it sound like Apple is in the wrong for having this setting configurable at all. But has he ever used a phone before? Apps didn't even need to request permission to use Bluetooth radios in older iOS versions. Besides, disabling them completely would break functionality for apps that need to search for bluetooth devices (Smart devices, namely).
His statement about it being used for tracking isn't too far off. Of the apps in the screenshot:
Alexa: ok sure, maybe you need it to setup Amazon Echo devices
Amtrak: ???
CVS: ???
Domino's ???
wifi should require a whitelist of sites an app can access by default. any app that has WiFi access should not be allowed the scan my network for vulnerable devices etc.
same for Bluetooth. most apps dont need this at all for anything legit. those few that do should default to some whitelist of devices they are allowed to access
Apple/Google/Microsoft should be working to make this happen
What's the pain? Why does every app need access to all of the internet. I know of no apps I use that need that access accept my browsers and I'm fine if Apple/Google/Microsoft added a new permission
(a) no internet access
(b) access only these sites
(c) full access
I'd only give my browsers full access. You'd be free to give all your apps full access.
I'm all about helping out on privacy related topics but unless they want to learn about the how and why you're turning on xyz they won't care in the long run.
[1] https://en.wikipedia.org/wiki/Surveillance_capitalism
[2] https://www.icsi.berkeley.edu/icsi/projects/networking/hayst...
It's times like this HN needs to allow the fire emoji.
He's absolutely right and the fact we pretend otherwise is a total fucking lie that lets everyone feel a bit better about about the wretched state of our industry.
I’ve been impressed with their approach and how they make improving privacy easier