Google reportedly peeks into Android data to gain edge over third-party apps
arstechnica.com
arstechnica.com
“Collection of data is disclosed to and controllable by users”? Well, if the users presume that collection is going on unless said otherwise, then maybe.
Annoying thing is, I'd quite want to use the voice assistant. Do I like to fiddle with integrations and workflows? Oh boy. Damn well I do. Do I know that my voiceprint won't turn up on Google's servers the minute I use the assistant? Nope.
(Btw, another baffling trait of the Android ecosystem is how many well-known and widely-used hackish tools are closed-source: those from XDA and such. “Flash this binary to root your phone”, “install this blob for low-level customizations”. Eeeeh? I think I'll just disable all Google's misfeatures instead, for now.)
Similarly, if you use the default Gboard (keyboard) on Android, it's constantly trying to call home to Google servers, as with most other stock apps.
Android is just increasingly becoming spyware and best route is installing AOSP without GApps. Unfortunately, Google seems to be keen on limiting this behavior and increasing their lock-in with recent changes to Android, making it harder for the open source community to have control over the OS.
More to the point, you're essentially recommending that everyone pony up $1000+ for an iPhone. None of those lesser known options (or modern dumb phones) are known to the average smartphone user, average people don't know anything about these hardened Android forks, etc. Boycotts are really not very reliable, because most of it is exactly this: just telling people to do a boycott and then stopping there. I know it's not reasonable to expect everyone floating ideas to have a plan for implementation, but when it comes to these kind of boycott suggestions, nobody has a plan. That's why shifting the responsibility onto the consume isn't going to work. You're not going to mobilize near enough people.
You know what does work, though? Strong privacy regulations with harsh penalties.
Less than $70 per supported year.
https://github.com/microg/android_packages_apps_GmsCore
Currently, the easiest way to use MicroG is through CalyxOS, a distribution of Android 10 that preinstalls MicroG instead of Google Play Services. It supports all Pixel devices and the Xiaomi Mi A2.
Unlike most Android distributions, CalyxOS is designed to be used with a locked bootloader, which is more secure than an unlocked bootloader.
Google's moves to lock down the platform further is also disgusting. They will be mandating a new App bundle format (AAB) instead of APK beginning in 2021. This will force more apps to run through Play Store, enabling more tracking & analytics. They will also require devs to give a copy of their signing key to Google for them to sign applications.
https://www.xda-developers.com/google-play-billing-v3-app-bu...
What.
>Mandatory Android App Bundles for Newly Published Apps in 2021
>The .aab file contains APK files for the base application and all supported architectures (ARM, ARM64, and x86), languages, and layout variants.
>This format requires giving a copy of your app’s signing key to Google so the Google Play Developer Console can generate a bundle with signed versions of each APK in the bundle; the correct APK for a particular device’s architecture, language, and layout are delivered via Google Play Dynamic Delivery....
I'll use a version of AOSP without the data harvesting spyware baked in, although Google seems to be keen on shutting aspects of it down.
I don't trust Apple much and don't hold them to any high standard. I am not a fan of their locked down ecosystem and their moves to remove things like headphones, which become accepted as industry norms. We know they sell overpriced hardware and ads are not a core business for them, it's the big thing that enables people to trust their [recent] "privacy" marketing. Now that they've made a big deal about it, we can expect them to (atleast) protect their brand aggressively and try to not screw things up.
As much as I hate to say it, I am going to give iOS a trial run soon. I've gotten custom ROMs on my phone in the past to remove analytics SDK, trackers, and other hostile app functions that tries to exfiltrate data from my device without my knowledge. If I have to give up some OS level leverage to get more control over my user data overall, I'll consider it.
You can say that "core services" is "the important stuff," or you can look at the individual pieces that comprise "core services" and get some insight into Google's business rules for Android. Everything that can't be disabled indicates a GOOG business requirement.
Do you want Google to know your soul by 2025 or the CPP by 2040? :D
https://developer.android.com/about/versions/10/privacy/chan...
It really seems like most of the android developer culture came from the oldschool windows freeware scene, which also has a baffling aversion to publishing source code.
https://github.com/TeamWin/Team-Win-Recovery-Project
The most popular Android rooting solution, Magisk, is also open source. All Magisk modules (plugins developed by the community) in the official repository are required to be open source.
Google Assistant uses servers to run voice recognition so it's certain that your voice print will end up on their servers. Same for Apple Siri and pretty much any of them. As far as I'm aware, only the Pixel 4's improved Assistant is capable of partial offline execution and even that ends up on Google's servers.
Also additional question for HNers: Do you consider Apple's "Digital wellbeing" feature on iOS spyware as well? Is there a difference?
Google doesn't need this tool to track usage statistics for ads. The ads SDK used by app developers is orders of magnitude more useful as a data source.
This has such an Orwellian tinge to it.
This is the Western version of CCP controls, the means just take another form. I don't imply the two are in the same category and therefore it's not equivalent, but within the constraints Google has ... this is what it looks like.
It's closer to the Windows cracking scene and such, where the expectation is that if you don't trust something, you either don't use it or disassemble and analyse it yourself. After all, a lot of app modding is done using decompilers.
On the screen I can see all my interaction history with the assistant with 2 taps.
The reality is, if you are a business, Google is your competitor. Which means Google getting a hold of any information about your business should be part of your threat model.
You may not be in Google's sights today, but you very well could be tomorrow. And they will use your usage of their platforms to screw you.
Meanwhile, give a start-up with 5 people a few million in revenue, and they'll be jumping with joy at their success. Plus they'll have a lot more passion, and more carefully manage risk while growing the business.
Control over apps, control over the store, over what users are allowed to do. If you don't need any of that to make money why not run a regular Linux distro.
Opens source phones will never be mainstream. Same as desktop Linux. But it would be nice to have a widely supported option for those of us that care
[1]. https://puri.sm/products/
[2]. https://www.pine64.org/pinephone/
[3]. https://en.wikipedia.org/wiki/List_of_open-source_mobile_pho...
> It seems like we're getting there with Prism [1] and Pine [2]. Seems to be a couple more I've never heard of [3].
But are they standardized? That is, can I have a single "phone OS" distribution which can be installed unmodified in all of them? We're already there with the Raspberry Pi: the 64-bit Fedora I installed on mine boots through UEFI, and the same Fedora install should boot on any other UEFI-using 64-bit ARM board. That's the only way to get the necessary scale; otherwise, the community will stay split in separate silos (a purism silo, a pine64 silo, etc).
Pine doesn't employ software developers, but the Manjaro and Mobian communities are also doing their best to stay as close to stock desktop distributions as possible.
A key difference between the Pi and both the Librem 5 and Pinephone is that the latter two made an explicit design choice to use stock-standard (nearly) blob-free hardware. Unlike Raspbian, which relies on a custom kernel, PureOS, Mobian, Manjaro, etc... are very nearly standard desktop operating systems, with relatively minor tweaks to system defaults. Heck, PureOS and Manjaro are desktop operating systems just running on the phone with mobile-oriented shell .
There was a nice, related post on this from Purism a few days ago: https://puri.sm/posts/investing-in-real-convergence/
Apache and Linux were open source. The Internet was designed to be distributed. We failed.
We still had centralization. We still have SPoF...
The issue is economic, not technical.
When corporations like Amazon and Google have severely unfair competitive advantages we're going up in this situation again and again and again.
The only way to change this is to reform tax law.
I, for one, see technological replicating the stagnation and over-complexity of human systems (say US was kinda alright in 1790, Unix in 1970). I Hope that if the technological and organizational problems of free software/hardware can be solved, we can use that experience to tackle the real-life problems.
I'm curious what kind of tax reform you have in mind?
I don't think an ecosystem based around SoCs from a notoriously proprietary and open-source-unfriendly company is at all a good model of an "open source phone".
They used this as a negotiating tactic for acquisitions they made in the space...
Pretty much every manufacturer has them - Apple was collecting/uploads this data (cell towers, wifis and your location) in iOS 4 as well: https://www.computerworld.com/article/2507791/iphone-secretl...
Google is desensitizing us to this kind of bad behavior, to the point that this sounds like it’s only half the story, or not such a bug deal.
Other than that, Google being able to process more data about their own platform than others, is something to be expected.
If Google is artificially inflating opt-out costs for the user, then that’s something to watch for.
Looks like it’s basic metrics like how often the app is launched. It is not sensitive (user content of the apps would be sensitive).
It is an antitrust issue but barely a security/privacy issue.
If we call every issue equally important privacy violation, one day we will overlook the one really important issue, which this issue isn’t.
Or another analogy. If Google threatened to blow a nuclear bomb over Manhattan, Google gaining knowledge about competitors would not be an issue.
Yeah, Google spying for other apps is bad. But let’s not miss the forest for the trees.
(Also, please don’t use ad hominem arguments, the conversation becomes emotionally loaded rather than coldly rational.)
Edit: also, your entire justification for this spying is that it could be worse. That reads to me like an ad hominem attack in itself.
I use some numbers which are my estimations, and not random numbers. I could explain how I made these estimations if you asked (Short version by definition of risk which is damage multiplied by probability). Also if you disagree with these estimations, you are welcome to suggest your better estimations, how these three scenarios compare to each other.
> your entire justification for this spying is that it could be worse. That reads to me like an ad hominem attack in itself.
It would be ad hominem attack if I said it could be worse for you. But I didn’t, and not everything is about you, so my argument wasn’t ad hominem.
Also, probably best to admit this conversation is derailed and stop it for the good.
"Within 38 hours of resuming transmission, the flag was located by a collaboration of 4chan users, who used airplane contrails, flight tracking, celestial navigation, and other techniques to determine that it was located in Greeneville, Tennessee.... after a field at the location was set on fire, the artists were again forced to relocate the project." -- https://en.wikipedia.org/wiki/LaBeouf,_R%C3%B6nkk%C3%B6_%26_...
And it gets better (at another location): "In the early hours of October 25, 2017, vandals unsuccessfully attempted to set fire to the flag using a flaming drone, before crashing the remotely-piloted aircraft."
Never underestimate how much can be gleaned from leaked information, or the extent to which harm can be done with very little information.
¹Watch out for your privacy, though, if you don't remove Google "services" from your devices.
Also, being able to reach a person on the phone regarding my Azure billing was radically different to being in contact (or lack thereof) with Google.
You can see what information (broadly) Microsoft collects through Windows 10 in the opt-in screen for telemetry. More detailed information has been published here: https://docs.microsoft.com/en-us/windows/privacy/required-wi...
https://www.microsoft.com/en-us/p/diagnostic-data-viewer/9n8...
They slurp up contacts, emails, location data, search, pictures. Everything you would get from a social network they already have, just from disparate sources.
Incidentally though they do have some settings you might want to check out though. One in particular let Facebook spy on your other apps so fine tune their ads.
If you really care about your privacy in this case, Apple devices won't save you either. The difference is just in the fact that ArsTechnica decided not to write an article about it, but your data is being uploaded all the same :/
Ah! I was hoping the Google Cemetery meme would die out soon. Not so fast I guess.
Apparently in this day only carpet-bombing with services bears fruit.
Google and Apple can at least plausibly infrastructure an anonymized data collection service and control access to it reasonably.
- You probably should worry more about the per user per connection logs your "loggless" VPN provider keeps in crappy open to the world datastores.
- The data sniffing and tracking your own ISP is doing.
- The uninstallable malware / bloatware etc that comes on huge number of phones built by third parties (ie, not google or apple).
Whenever I sign up for a "free" service (like google analytics or its equivalent for android) I am under almost no illusion that google isn't also using that data to help track users access the web target them, figure out what ads to show on my site (if I let them) etc etc.
And yes, we will find out that facebook tracks the URLs of sites people share on their platform and "snoopes" on that to figure out popularity trends. And twitter will watch tweet metrics related to their competitors. I wonder if we will get some headlines over those issues.
Finally, some folks come up with weird threat models - google is out to get me and now they can. Heads up, google could get you before this as well if they cared to. Can you imagine a govt having google's power. That would be a near dictatorship!
Google is excellent at this kind of word maneuver, designed to confuse and mislead.
Google gets confronted about an egregious practice, and a PR representative responds with "well, we would absolutely never do [slightly worse unrelated thing]". This happens over and over again.
They get caught, MSM blindly repeats Google PR talking points with enormous spin and PR manuevering, and everyone forgets until the next scandal.
If they're collecting this data, I strongly suspect they feel obligated to, maybe even compelled too. Possibly for purposes like app security, user security, OS security, user experience, etc.
This doesn't really make sense; none of those are compelling use cases for such invasive data collection. And this additional new tracking does not seem very useful for security, and even then there's no reason for all of the data to leave the device if it's for security.
Source:
https://support.google.com/googleplay/android-developer/answ...
Trash all of them and just put GNU/Linux on your devices if you really have to have a smart phone.
We have this saying in Germany about data collection. What it means is you can usually assume that given enough time, companies will do the worst with the data that exists, so the only reasonable approach is to never collect so much data in the first place.
And i agree companies should only be allowed to gather the minimal data necessary in a given situation.