Google sued: Idle Android eats mobile data to send telemetry and preload ads
theregister.com
theregister.com
Supporting initiatives like the Librem phone is also moving up in my list of priorities, once I get enough money to spare at least.
Other than that you’ll get low volume low end devices at high end or higher prices due to lack of economy of scale.
What most consumers actually want and I’ll put in that list also many many people that say they want a “Linux Phone” but in reality will go back to their iPhone/Android after a week is quite different than what a tiny niche is willing and capable of dealing with.
I used Android from day one till the LG Nexus and I switched to an iPhone after having to spend yet another weekend compiling a kernel to update my phone.
Most people want a device that “just works”.
Overall I would be good money on the fact that the percentage of people that say they want to be able to hack their phone freely and will actually do so is very slim because again Android gives you 90% if not more of that freedom already and some devices even can boot other OSes.
Sure things like the blobs on the baseband are still closed but that will always be the case no one realistically is expecting a high end 100% open source phone, and if you are keep dreaming.
And yes while having a phone that just works and one that is open isn’t mutually exclusive in principal but it is in practice especially once you account for economics.
Like it or not securing an open system is harder, and companies don’t like investing time and money developing features hardly anyone will use.
But what I mean is most of the system isn't really open like that. Configuration, application data and stuff like that is mostly managed by the system and you can't access or change that data without major hacks. Termux feels like a second-class citizen because most of the ecosystem isn't built with something like it in mind (in contrast to the "CLI-by-default" experience on other Linux systems). There's also a few (non-embedded) system components like the backup system (which, if I'm not mistaken, is provided by the Google Services Framework) which you can't easily replace.
Of course, when it comes to security this is not something you should give to anyone who doesn't know to protect themselves using it. And I assume it wouldn't be a financial success either, I just guessed this is what people mean when they say they don't like Android because it's too restrictive.
Unlike on the desktop, most important phone apps aren't so large and complicated that they couldn't be ported to or reimplemented on a new platform with a realistic amount of effort. You could offer a significantly better developer experience than either of the dominant platforms today, which would be essential to supporting the apps users expect to find available on any mobile platform today but also potentially attracting some unique and better apps over the longer term.
From the user's side, they'd be genuinely in control of their own device. There could be real security, stability and privacy benefits as a result, and you could do away with a lot of the things that annoy users of current mobile platforms.
As ever, the problem is how to bootstrap a two-sided market. It would probably have to be extremely easy for developers to port their existing Android apps. You might also have to convince one of the major phone manufacturers who can make good hardware at competitive prices to support your platform as an option, or possibly make it easy to install it as a replacement on existing phones. But with the right promotional strategy even these things don't seem totally out of the question. It's a huge potential market, on a scale where one or more well-capitalised big players in the industry could potentially take an interest.
As much as FOSS crowd loves to hate Microsoft, better get the facts right.
https://www.cbc.ca/news/business/stephen-elop-to-get-25-5m-f...
How many major phones can you buy with AOSP installed by default today?
How much development gets done on AOSP that isn't at least heavily influenced by the direction Google takes?
Does AOSP provide comprehensive privacy and security options for users but still freely connect with other devices and services using open standards?
Obviously if you're going to be Linux-based and if we're assuming some degree of compatibility with Android APIs to make porting apps easy then there is going to be common ground with AOSP, but I don't think that makes it the only or necessarily the best option.
Heck how many people do you think install SailFish on their phones? You can buy pretty decent Android phones with AOSP and even SailFishOS builds yet people aren’t taking advantage of that in any particular manner.
If almost no one uses it, even amongst those who claim they want that freedom why will build a business model around it?
I want a mobile OS that gives me complete control over my personal data.
The issue is that whilst people want it there is never a good enough “reason” for that other than I want it, Maemo doesn’t give you more freedom than what AOSP does already at least not on the software level, you can degoogle and Android phone completely and do w/e you want with it. However people don’t seem to be doing that, and those who do often do that for academic purposes rather than to have their own personalized daily driver.
Even more so often the wishes of many people when it comes to customization doesn’t even require a rooted phone and a customized AOSP ROM, if you look at what people customize on their desktop which is often limited to their desktop environment and their workflow can be done on stock Android using alternative launchers and other apps.
Wanting for an Android competitor for the sake of having competition is fine, but it won’t look much different or it won’t be much of a competitor.
The other problem is that you have to choose between hardware quality and customization, because hardware is locked down and there isn't enough economic air left in the room for a third player to be able to invest enough to compete.
As for not looking much different from Android, the key difference would be where the control lies, and what the mindset is around control. You should have a robust code signing and containerization/permissions system, but those should be in the hands of users. With Android every single app installs with permission to portscan every network you connect it to. You will have an app store, but the user will come first, not the ad network.
I liked my Nokia N900 and kept up for a while with attempts to keep its Maemo going after Nokia abandoned it. However, a decade later Maemo has bitrotted and its dev community has dwindled away. Nowadays the Phosh interface (i.e. the Librem phone, or Mobian running on the PinePhone) is seen as the most promising Free Software choice in the long term. Sailfish OS is also actively maintained, but its UI layer is closed source.
App distribution was also better on both platforms. Maemo used apt under the hood, and Preware[1] was phenomenal. These days the two vendors that own 99.4% of the mobile OS market[2] don't want to let you install apps unless they can get a 30% cut.
[1] https://webos-internals.org/wiki/Application:Preware
[2] https://www.statista.com/statistics/266572/market-share-held...
They both allow free apps.
[1]: https://fxtec.com/
[2]: https://browser.geekbench.com/v5/cpu/compare/4573446?baselin...
I have an Pixel2 and was thinking I'd get an iPhone next, but I'm really turned off by Apple's behaviour lately. I also don't want to send more money to Google.
I'm willing to accept that it may not be as polished as the big players, but how would you say it compares to other high-end Android phones?
And if you've tried running linux on it is it usable with reliable call quality?
Taking a serious look
There are many other uses for a car than commuting to work ;)
We're using some Xiaomi devices we purchased, and I'm currently seething. I can't root without 'unlocking', which is a process that requires me to activate a Mi Account, which then requires my email and a SIM (?!), and 'find my device' (location) to even allow installation of apps via USB. To unlock the computers I bought, so I can use the root account, to install an alternate.
Seems the prison walls are just set far enough away that we don't notice.
tl;dr, in order to get some privacy, I'm being asked to associate my IMEI, my IMSI, my email, and my location.
Mere tamper-evidence - having a "bootloader unlocked" warning on boot - isn't obvious enough for a new user who has just bought the phone for the first time. So all manufacturers have added time locks and anti-fraud detection for bootloader unlocking. The time lock in particular is the best way to cut down this effect during the early sales process after which time it's hard to catch up in review score. But a time lock can only be implemented securely via a remote server out of the user's hands.
Xiaomi getting the telemetry is a cherry on top, but it's not originally nefarious - or at least - it's less nefarious than the problem it's intending to solve
The "we're protecting people from themselves" argument seems spurious.
Because it isn't the argument at all? The goal is to protect your reputation from having malware and ad laced versions of your latest hardware flooding the market (and hitting the news). Users are just a secondary concern.
In a way, it’s to protect naive users. And it still allows you to root the phone - go through this idiocy once and then never worry about it again.
adb shell pm uninstall -k --user 0 com.[miui,android,xiaomi].<appname>
Have you investigated if xiaomi.eu firmwares successfully curtail those connections?You can also grab a used device with a confirmed unlocked bootloader. You usually have to ask a seller, and some won't know the answer, but you can provide the steps for them to determine this.
I really have enjoyed the LineageOS and it's been great to have a phone that isn't as dumb as a flip phone but doesn't have all the bloatware and spying of other devices. The security around the bootloader is my biggest concern.
https://www.reddit.com/r/LineageOS/comments/ev9c4v/is_androi...
FBE is only secure when the system partitions have dm-verity enforced and verity is only enforced when the bootloader is locked.
FDE is a bit more resilient with an unlocked bootloader since there is less data left unencrypted.
However in either scenario without a locked bootloader and verity it is trivial for an attacker to insert malicious code that can then run once your device is unlocked and send off your files.
(I believe this is an example of an evil maid attack, although that name for it is somewhat new to me.)
A locked bootloader would prevent such code from being installed, or at least refuse to run it.
If you're in a position that your chain of custody is broken, just wipe, revert the device to stock signed binaries, confirm by locking the boot loader again, then unlock and re-flash your custom binaries.
Or am I missing something here?
The Play store and what it gives you is incredibly hard to live without, unless you really just want to use your phone for texting, browsing, and calling. If you're a minimalist, then great. If you're accustomed to what a smartphone can do, not so great.
The alternative app stores are full of unimpressive, small scale apps. Dozens of calculators and little games, but no maps apps (of worth), no yelps, no IMDb (which I use often), no Sheets or Photos, the list is huge. I'm sorry but these apps make a smartphone worthwhile.
To avoid such a spartan experience, I ended up just installing microG (an open source replacement for Google's Play Services) and Aurora (a replacement Play store client, which allows me to install most apps from the Play store).
The problem is that most modern apps require a mammoth cloud backend, which costs big money to run, which means you're going to need a huge company running it. You'll never find big scale apps like this on F-droid.
I use them all the time for tracking expenses, tracking information for myself, creating forms and responses, etc.
And let me tell you, I almost never have to open up the playstore except for updating my banking apps, because f-droid has a much better selection of apps anyway.
For example, NewPipe is a much superior alternative to the official youtube app and it even works perfectly fine without a youtube account. I don't have to ever worry about having my google account deleted because NewPipe backs up my subscriptions to xml.
I can only recommend this approach of "degoogling" but still having the ability to fall back in case it is really needed. But so far microG has been great, they even implemented the Covid Exposure Notification framework very quickly.
OSMAnd
>no yelps, no IMDb
What do these apps provide that the mobile sites don't?
In particular, I seem to recall if you landed on Yelp, a lot of content was "here's 150 pictures, but you can only see 3 on the browser."
And you don't think this is related to Google Play Services constantly running in the background, searching for networks, location, open & installed apps, and OS metrics, per the linked article?
Reading through r/BlackBerry, it seems my KeyOne is only useable because I've disabled Google Play Services - otherwise it would be dramatically slower with much worse battery life.
you may have gotten that wrong
'google play services' is software package (app) that sits between the os (android) and the (other) apps. it provides a lot of middleware like maps and push-notifications. it has grown in power to the point that an android phone without them is pretty much pointless, hence micro-g tries to substitute.
My Blackberry Q10 served me well for years but the battery is starting to go and the OS + apps are no longer supported. I can actually say I've skipped Android/iOS entirely.
Still Android, but you keep the HW Kepboard and the batterylife and build on it is insane. Not nearly as clean as stock or the Key2, but much more freedom respecting.
I just got mine and it is significantly buggier, crashier, and slower than expected. The USB C port is also of low quality. It is overall worse quality than expected.
It's coming along fine though and in a few years that might be true! For now, a great device for tinkering and contributing back.
Source: I've used the Outlook app before my phone was enrolled with my company so I noticed the differences :).
text is insecure but thats not my threat model
Phones still have a lot of compute and sensor hardware that standalone apps can make use of. Heck, my Galaxy S3 can be a desktop replacement with MHL-out and USB or Bluetooth interfaces. And a lot of patience.
Interesting, so 350MB of data per month is abuse, iPhones 175MB per month isn't. I guess Google now has to half their data use for it to be at parity with Apple and we're all fine?
iphones i have set up use about 30MB per month for "System Services" dont know how much of that is from real usage vs. telemetry an stuff.
If there is any OS level telemetry it would fall under general which for my iPhone is 105MB in total since I activated it about a year ago. In general over a year+ (11 Pro Max) its 2.5GB with software updates and document sync accounting for over half of it both of which can be explicitly set to use WiFi only same goes for most other services as well.
Just to put things into perspective my total mobile data usage on this iPhone is 253GB, all system services is 1% of that.
I assume that the under active use category is covered broadly by the terms of Google, Apple, and any other application you’re using. While that may be an actual problem, it also might not be a legal problem given how the contracts are defined today.
If you don’t like this, then you’ll need to advocate for actual laws. Otherwise, this is the best attack that can be waged against this type of behavior today and is why people appear to be “okay with” the current usage in the general case. You’re only going to see “not okay with” if a lawyer thinks they can actually win a case.
What I want now is an open source Android device where I have controls.
The #1 things I want to control is app permissions. I should be able to shut them down. If an app "needs" my location, it should get a random spot in the world. If it "needs" my contacts, it should get an empty list. If an app "needs" my network, it should see that it's offline.
The #2 thing I want to control is data going out.
#3 is having security updates forever, rather than sudden EOL with no notice.
I think someone should fork Android and do that. Ironically, I think several Chinese companies are well-positioned to do that, from a market perspective, but not from a cultural perspective.
Does anyone have any open-source suggestions for DIY deep-packet analysis?
Android AppManager [0] (if you're willing to spend the time configuring it via the command line) might help here.
> If an app "needs" my location, it should get a random spot in the world. If it "needs" my contacts, it should get an empty list.
Some Chinese OEMs do have these features. I know ColorOS (Oppo and Realme) does.
> If an app "needs" my network, it should see that it's offline.
Android 11 natively exposes ability to firewall apps individually. All major Chinese OEMs (Xiaomi, Oppo, Realme, OnePlus, Vivo) have supported this for a long time.
> The #2 thing I want to control is data going out.
There are two or three no-root firewall solutions on the PlayStore (disclaimer: I built one, too).
> #3 is having security updates forever, rather than sudden EOL with no notice.
Legacy devices may have other problems than what an Android distribution can address: https://grapheneos.org/faq#legacy-devices
An iPhone with Apple's Safari browser open in the background transmits only about a tenth of that amount to Apple, according to the complaint.
But, you could be right.
A 2x multiplier barely reaches the level of noteworthy. I look forward to my $12 class action payout, but let's be honest, this isn't going anywhere, and would almost certainly be a bad precedent. Legally requiring premature optimization would be the real world result of a ruling in favor of the plaintiffs. I can't imagine a result that would actually inhibit Google from continuing to advertise to you.
Which seems like the point of class action lawsuits and far more significant than most of them.
So the case is purely about whether it's too much logging data, not whether there is any logs at all. And since we measure that logging in actual bits sent over the air, then yes, it comes down to a technical spec.
I would be absolutely shocked if the court ruled as you suggest. That would be tantamount to suggesting that the business model of every website is illegal.
That said, the right amount of auto transfer of content should be close to 0,a few bytes to notify of updates may be reasonable. Certainly we don't need to have books-worth of software and content transferred without the phone's owner agreeing with that agreement used with extremely narrow scope (I use the word owner here colloquially, as the user paid for the phone).
Stop the abuse of "could" and begin questioning with "should."
That kinda supposes it's content the user wants. But what if it's data, like ads, that the user doesn't exactly want but they're going to get anyway? I don't know where the lawsuit will end up, but I can see this ending up as a buried, default-on, setting that most users will never change.
TLS connection setup is ~10k so if do an 1 HTTPS call/telemetry that's 48 calls home/hour. (11,600/10k = 1,160 https connections/day. There's 1440 minutes/day) Of basically calling home every minute and sending not much.
Ok calling home every minute...but maybe when idle that's not bad for notification updates?
We run long do running TLS connections using MQTT, this works for 5-6 figure of units. And our actual usage when we have good cell coverage is around 25megs/mo, including data. But when you have the qty Google and iOS have....maybe that's prohibitive?
In which case the suit would incorrectly be blaming the store, instead of the real app that is sending the data.
Whether it's something minor like this or a major antitrust cases (eg, the recent adwords EU case), what is and isn't legally actionable seems arbitrary from a non-legal perspective. Even legislation efforts like european "cookie laws" and such seem bumbling and naive.
What's the legal fix to this, assuming google lose? An extra tick box? T&C update?
The reality of interacting with large software companies as a consumer doesn't lend well to brick and mortar analogies. A T&C section is not analogous to a rental contract. Even residential or employment contracts are usually subject to legal filters... cultural norms at least.
The "problem" here is one of structure. Google own android to (a)dominate the mobile phone market and (b) support the targeted ads business, the main business.
Whether or not google are "stealing" data allowance from customers, or acquiring this right voluntarily/contractually from customers is interesting in the abstract, I guess. In is so peripheral to the actual problem though.
I realize this case isn't supposed to be dealing with the wider problems of legal monopolies. The legal/legislative whole is. It seems that whatever the goal of the action (from litigation to legislation or regulation), they pick around the irrelevant edges.
What, legally, should google be legally allowed to do given that it's leveraging the fact that they control your phone, own a lot of your data, etc. If the answer is whatever the T&Cs say, the answer is "everything."
So we break them up. We regulate their conduct, we interrogate their business and ensure there is no apparent conflicts of interest going on.
Mobile OS solutions LTD would develop Android OS, wouldn't unduly favor any given party more than another.
It's possible, but you'd need to essentially have complete and total access to the daily affairs and perform audits to ensure compliance.
Legislation can fix this but it'd be a mammoth task to challenge Google.
There's definitely a social problem here, but I think for once people HN are underestimating the importance of a technical problem.
That depends. Assuming an uncorrupted chain of delivery between you and the manufacturer, if you're running a vanilla AOSP, the only organization having root access is Google and you. Even with Samsung and other manufacturers, they are the only additional party whose packages have admin rights.
The situation is more nasty with devices bought/leased from a carrier because these insist on preloading all kinds of crapware - which is why I would strictly recommend everyone to work out their own financing and buy a stock device independently from a carrier. Chances are it's gonna be cheaper in the long run anyway.
It depends on what you call "admin rights", but from my point of view you're wrong. On Samsung devices, DT Ignite (Israel-based ad company) is preinstalled, which has the rights to install new apps. Getting the right to install new apps means you can get any user permission. (like silently access camera, microphone, or screen capture to capture you typing your password)
Apple has their own issues, but at least the above carrier crapware issue isn’t one of them on iOS and never has been.
Notice that Apple is also sending data? Is that also for ads? Should we be breaking up Apple, too?
This is almost certainly related to boring things like checking for app updates, and less boring but still controllable usage & diagnostic data (Settings > Privacy > Advanced > Usage & Diagnostic).
It's mostly just that Google, and realistically all apps, need to be far more conservative with cell data use than they are. Many developers forget it costs money and isn't infinite in amount.
Specific example of harm: international roaming data fees are outrageous and even a small use of data can stack up. If I visit Canada using my UK mobile phone, I have to be sure to keep data roaming turned off because I get dinged for £6/Mb (about US $7.50/Mb). Over a couple of weeks, google sipping a bit of bandwidth here or there can actually end up doubling or tripling my monthly bill, even when it's single-digit megabytes.
(The real problem is of course the existence of the search/advertising hybrid business model, which needs to be addressed at a legislative level. But no, costing me a noticeable amount of money under unpredictable circumstances is not an abstract/trivial problem.)
Should the phone sit quiet when you're not using it? Sure. Is £6/Mb even close to a reasonable rate? Not unless you're on Mars.
They're both problems.
(1) Google will clarify and establish their right to do whatever it is they're doing. Rarely will the result be google changing. (2) The do-whatever-then-ask-forgiveness mo may actually be reenforced. Google actually lost their EU antitrust case. It was about adwords, the google moneymaker. If Google had known in advance they would be found guilty and fined $1.4bn, they would have certainly done it anyway. (3) Whatever harm is acknowledged here will not be acknowledged as what it is, a part of the larger issue of google's abuse of power. Sipping data is the least of it.
I myself found it out the same way when Google service somehow managed to bypass every lock on roaming traffic.
The “solution” isn’t forced legaleze on customers, it’s more “do what’s in the customer’s best interest” not “do whatever you can legally get away with to make the most money off them”.
> 5 minute delay
I honestly feel that’s even more user hostile than the “onerous terms” in the first place.
I stand behind my point, if one has such “onerous terms” that something is warranted like you suggested, then the company failed and the app/service shouldn’t exist.
Actual "commercial relations" are based in custom, and law... not just contracts. Adam Smith talked a lot about custom, rarely about contracts.
The T&C ritual is a bureaucratic farce, our version of medieval catholic indulgences. It can only be understood anthropologically.
It's possible that the device they ran the test on had an unlimited data plan, in which case, this might not be a bug, and the judge will throw out the case.
https://developer.android.com/reference/androidx/core/net/Co...
The true solution is technology. We need software that blocks all kinds of telemetry and advertising while also leaving all the other good functionality intact. We simply make it impossible for them to abuse our good will in any way, their business interests be damned.
I don't know if this would work with DoH. (but DoH is terrible anyways)
For instance if my VideoApp serves content from videoapp.example.com and I use my own DNS also at videoapp.example.com, served over DoH, I think that's basically the end for host-based content blockers.
If you're using Android: Blokada from f-droid is another option if you want to skip even that.
Cheaper compared to the income & cost of life ? With the median world income being $30/month, I doubt so !
First of all, this isn't even true - it's around $240/month.
https://news.gallup.com/poll/166211/worldwide-median-househo...
Second, people living in those countries aren't buying US data plans at US prices are they? You don't live in the Congo but shop for your data plan at a California strip-mall, do you?
https://ourworldindata.org/extreme-poverty
Which should be around 5% these days.
> Second, people living in those countries aren't buying US data plans at US prices are they? You don't live in the Congo but shop for your data plan at a California strip-mall, do you?
Ok, so what are these prices ?
https://www.cellularabroad.com/packages-congo.html#tabs-2
That's $100/Go for 3G. (Which is still 10 times cheaper than my first data plan !) But I suspect that this website is directed to rich westerners, anyone from third world countries here that might shine a light on this issue ?
I know some eastern nations that have 50gb G4 for 10-15€, which is about as much as you'd pay for 1 meal in a pretty cheap restaurant.
Assuming you know what to block, the connection would fail after the first DNS query thus saving you bandwidth and privacy.
I struggled with a similar issue with Spotify to play to networked devices from my device.
This may point you in the right direction...
https://en.community.sonos.com/advanced-setups-229000/yet-an...
The bad news is, GPS still turns on on its own and camera seem to click sometimes </tinfoil>
[1] https://play.google.com/store/apps/details?id=com.frostnerd....
I'm no lawyer and have no special knowledge, but this is for "new account" and represents log files, according to the suit. I can almost guarantee Google will show the data is some kind of anti-fraud/spam analysis (thus why it doesn't wait for you to get on wifi).
This it's not an apples to apples comparison (they are only guessing the logs are for ads, but the suit doesn't appear to actually show evidence that the data is advertising related). Similarly, they extrapolate that it will continue to log that much data forever, but it may be related to the fact they are new accounts, and data usage may drop off after the account gets some history behind it.
But hey, I'll be happy to take a class action payment, I just don't see this actually going anywhere.
I didn't. When I first powered up a new Android phone, it asked for a Google login. But there's a "Later" option. I did that, and then removed the app that runs on first use, plus various other Google stuff. Installed F-Droid and Fennec. So I've never agreed to Google's terms.
Google is making it possible for applications that show ads to choose to preload them. And they're not preloaded hours/days in advance -- it's a UX pattern to load them a tap before.
So that part of the suit looks like it will fall apart. As for sending telemetry, it's $1/month in data assuming you never use Wi-Fi. Doesn't seem like a particularly unreasonable cost. Especially considering most people spend the majority of their time at work/home with Wi-Fi which means the real number is more probably more like $0.25/mo.
I think a reasonable person assumes any commercial OS is checking for push notifications, syncing info (like weather), communicating analytics, checking for updates, etc. in the background. The only question is whether it's unreasonably excessive, which in this case appears not to be. (Really the only main thing is that a device shouldn't download multi-gigabyte OS updates without asking first.)
[1] https://www.blog.google/products/admob/preloading-interstiti...
How else would their phone know there are apps to be updated, notifications received, etc.? (On a computer, anti-virus updates too.) How would it know the temperature or stocks as soon as it's brought up, even when there's no cell service? It's pretty common sense.
And on iOS and Mac you prominently choose to enroll in analytics when you set up your phone, so the idea of analytics isn't a shocker either. I'm not sure if Android or Windows has the same setup choice.
General people -- even those who are highly educated and use computers all the time -- do not think about their tools. They click on defaults without thinking about them. And Apple and Google and Microsoft know this and take advantage of it.
How much is it when you need to use mobile internet (email, messages, whatever) while roaming at 1+$/MB? I currently need to use roaming for work purposes at 200€/GB - luckily no android, so should be affodable.
While I'm not saying the prices are appropriate, they are there and you can chat, email etc at an affordable price.
If you were traveling abroad, there’s a good chance you’d get screwed with International Data fees.
This is as bad as when Apple tried to keep Bluetooth on when you turned it “off.”
With it I block all relevant outgoing and incoming connections to doubleclick, google analytics, my carrier (t-mobile), app-measurements, facebook, etc... The phone attempts connection to one of these just about every second, and I block them all.
Hopefully the Librem phones will continue to mature and become my future phone.
Internet access should be a permission (like camera, mic, etc.) unfortunately in Android it isn't the case and any app can communicate with any server. With NetGuard you can decide which app can access internet or not.
What I tend to do is: install an app → block it before running it the first time → look at every connection attempt made (usually first through ipv4) → wait a bit more until apps attempt connection through different protocol (ipv6 or U) → block anything I don't like, including ads, analytics, etc → tell NetGuard to now allow the "legit" connections to be made and start using the app.
Brand new oneplus 8T and I was getting ~1 day of battery life with about 3-4 hours of use. I never enabled any google services and that was the default configuration.
I went app permissions and disabled everything that I was able to disable. The only apps that had default permissions always enabled were google services. The battery day is now ~2 days with slightly heavier use and the display running at 120Hz instead of the default 60Hz.
To achieve this, you need a mobile network supporting the standards allowing it to sleep for X number of beacon frames. There are also some things the mobile network needs to support.
The minute you install any apps, or start syncing any changing data, that 28 days goes down to 1 or 2 days...
So what did the existence of a third player with identical approach bring?
Like I said, competition with Android. Not just for consumers, but for manufacturers too.
Once you've got something like this set up the way you want it you're mostly there. The radio firmware will still be outside of your control and probably open to exploitation by the Three Letter Agencies of the world, for now there is not much that can be done about this other than to get a device with totally separate baseband processor, i.e. not integrated into the SoC. These used to be common but are as rare as hens' teeth now. There are some - e.g. the Librem 5 - but most devices come with an integrated baseband subsystem. Then again, for the purpose of circumventing the duopoly this is irrelevant so it can be ignored by all but those who also want to limit access to their devices by TLAs.
I've been using AOSP-derived distributions for as long as I've been using Android - close to 10 years - and have never found reason to regret my choice. LineageOS has OTA updates just like vendor distributions, the user experience is that of 'clean Android' - no bloatware.
googlemaps-enable:
#!/data/data/com.termux/files/usr/bin/sh
exec sudo pm enable com.google.android.apps.maps
exit 0
googlemaps-disable: #!/data/data/com.termux/files/usr/bin/sh
exec sudo pm disable com.google.android.apps.maps
exit 0
Yes, you need root (and sudo) to do this.Linux for mobile is also not an alternative. Since there are so many apps missing it can't be compared with Android and iOS. Well at least for me this includes some banking apps that make my life just so much easier.
The only real options right now are the Android forks like LineageOS I think.
Power users just disable the Telemetry service.
Start > Run > services.msc. Right-click on "Collected User Experiences and Telemetry". Stop the service and change startup-type to Disabled.
Or you can use windows group policy editor. (which every IT department uses)
Start > Run > gpedit.msc Computer Configuration> Administrative Templates> Windows Components> Data collection and Preview Builds
Allow Telemetry > Disabled.
Now, please do educate me on how to disable telemetry on MacOS Big Sur without third party software.
Its definitely easy. EDIT: or is this sarcasm ? difficult to tell.
"By configuring this setting in Windows 10, end users will not be able to opt into a higher level of telemetry collection than you have set for your organization." (Plus some clarification of how broadly this applies.)
That doesn't disable telemetry. It just stops individuals enabling more telemetry than you already had enabled.
There's no lower bar that you could set.
Overall I agree it's silly we even need to do this.
I don't remember the specifics, but do I know that with WM I used less than 10Mb a month roaming abroad, without doing anything special. I was just using a dedicated email address so I might send email if needed, but not receive all the crap and attached files I usually get.
I was shocked when I moved to IOS and couldn't make it consume less than 20x as much per month.
I can think of one, but in the opposite way: how Google removed the Exchange integration service from Android.
And then of course, you have both Google flirting with Android apps on Chromebooks, and the new M1 Macs being able to run iOS apps, when Universal Windows Apps were a thing over five years ago.
They've all had this a little while, but Microsoft was ahead of the game on being able to allow/deny individual permissions to given apps before either Apple or Google was as well.
I mean, Microsoft didn't have the market capture, but their platform was technologically in 2015 where their competitors are in 2020.
The long term vision is exactly what you said, convinance & security of a smartphone with, for those who wish, the openness and power of a computer
Download a cert from offending Google servers, and blacklist it in Android.
The TLS library on the Android will then block it
Just keep in mind that Google may have a sizable pool of certificates in use across their various servers, and they may rotate them on whatever schedule they like. Keeping up could become a chore.
It wasnt as much as alluded to in the complaint, but essentially many apps that you may not suspect, including messaging, send small amount of data to Google whether on Wifi or Mobile data. Power users can always disable it, but would not have known until you see the complaint like this.
One more thing: While the system apps do take up, even the apps which do not have permission to run in background use some amount of data. I have apps like amazon prime, Dominos, etc. which I have not opened in months (and restricted background activity) and yet they used some amount of data. If one good thing comes out of this, maybe they should restrict background activity until explicitly specified. (I do understand some of them would be for showing push notifications, but that can be handled differently)
I'm curious about the exact breakdown of data. How much of this is because it was a brand new phone?
Amazing.
Looking forward to that $1/month I'll get if it goes class action though...
The cause is always glass half empty isn't it?
I'm running LineageOS 17 (android 10) + OpenGApps-Pico, am logged into a google account and have turned off as much as I can find in the settings - am curious if my phone is still sending+receiving what they describe.
If you can clearly identify exactly how much data is consumed, and you have a service plan that tells you exactly how much that data cost to use then the damages are precisely computable. So a judge can turn around and just award these people $4.72 in damages or whatever and case closed?
What is the angle here, or is it just another "google-is-evil-but-i-still-want-to-use-their-services-for-free" thing?
1) Companies can make a lot of money skimming $1 each off of 100 million people.
2) Federal enforcement agencies don't have time or energy for that. We can outsource that to private firms
3) Private law firms can file class action suits, and companies are forced into agreements where they pay damages AND often need to change behavior
It kinda sorta works too, in that companies stop doing the bad things. Lawyers collect the lion's share of the money, but few consumers care about a $1 payout. Judges approve deals to make sure they're equitable to the class.
It sorta doesn't work, since settlements are negotiated by lawyers who don't really care about anything other than getting paid. Few actually care about the class they're representing. Judges are former lawyers, and part of the corrupt culture. So in many cases, the changes in behavior are less than one might hope for.
(Or conversely, the payout to the lawyers should be the same form as the payout to consumers. Good luck spending $100 million Wells Fargo Free Checking Account buckz).
So I'm not entirely sure what your iPhone advertisement is supposed to support here.
They either 1) need your personal-data to fund the services or 2) they don't need it and shouldn't have it. I don't see a 3rd where they need your personal-data only if you can pay for it. It gets really interesting where the IF is just giving them more of your personal-data.