Modifying Telegram's “People Nearby” feature to pinpoint people's homes
owlspace.xyz
owlspace.xyz
If your app really needs to have a feature like this, it needs to have aggressive rate limiting that makes it impossible to gather a statistically significant number of samples before someone changes their location.
And then, if you’re someone who is concerned about that kind of surveillance, you’re probably not someone who is sharing your location on an app like this.
1. Overlay the world with a hex grid.
2. Make "close" mean in the same grid cell, "far" mean in an adjacent grid cell, and "very far" mean somewhere else.
3. In sparsely populated areas, merge groups of 7 cells into a larger cell.
4. Add some kind of random delay to people who are moving around to reduce the information you get if you are stationary and they cross a cell boundary. The idea here is that if you are not moving and they are "close" and then they change to "far", you would know that they just crossed one of your cell's boundaries. In many places there might only be a small number of places where people cross those boundaries, and so you'd be able to narrow them down quite a bit.
This still leaves some issues with non-static positions, or temporal variation, as you noted in (4), where boundary crossings (or worse, movement near 3-cell boundaries) allow better precision. I think a good solution in this case is to also add temporal quantization (limited update rate of position), as well as some hysteresis (to avoid back-and-forth between cells for people living near borders). This way you cannot pinpoint the exact time the transition occurred (you cannot locate the person in space-time), and with hysteresis you cannot tell he is consistently near a border.
edit: Interestingly, all of those suggestions appear elsewhere in this thread! They all more or less appear forms of quantization.
Now place a device monitoring people nearby in each cell. This allows you to geotag people to the cell and monitor their movements. If you cross correlate with other tracking services (such as cell phone tracking datasets) you will be able to identify the individual pretty quickly.
For the above to work tracking does not have to be continuous. As long as a person sometimes is trackable you will accumulate information that allows for cross correlation. With intermittent tracking it would just take a lot longer.
There's no good way to return location data about other people.
If you lived on a boundary it would be very clear because your location would change very often, perhaps just by walking to the kitchen.
Which granularity: Harlem/Hell's Kitchen etc? West Harlem/East Harlem etc? Manhattan/Long Island? New York/New Jersey etc.?
Feature wise you would probably want at least something like Harlem/Hell's kitchen granularity and there are unfortunately enough people living on the borders of all of these that you could pinpoint those just from GPS inaccuracies.
Though maybe some places have political divisions with only one or two people in that would seem strange?
Basically, Tinder used to give you only the distance to a user in the UI, but the exact coordinate location of the user in their API responses. They patched it up and made it so that it only returns the distance in the API as well. And that's when it became really similar to the current Telegram situation. This was before we got our hands on this. However, reading older articles and blog posts about those "times before us" was what gave us the idea. Mostly because it seemed like their fix was not sufficient enough to prevent anyone (assuming they know basic trigonometry) from pinpointing the location just as easily, but with a few extra steps added.
Knowing the distance between you and another user, you could quickly spoof your GPS location to 3 different coordinates that would create 3 circles all intersecting in one small area. You could easily pick coordinates for those circle centers based on the change in distance to the user, so if you picked a bad coordinate for one of the circles, you can adjust and pick a better one based on the feedback you got. E.g., if the first circle center coordinate was 1 mile away, but the second one was 5 miles away, and the third one was even further away, you should probably try re-picking the 2nd and 3rd circle better, since the goal is to not move those far away, but to have them have a similar distance to the user location, just from different directions.
Shortly after, Tinder fixed it in a much smarter way. Instead of assigning each user to a precise location and reporting a distance to them in the API response, they would break up the map into a grid of roughly 1mile by 1mile squares (or maybe hexes or maybe slightly different size? I am very rusty on the actual details of their fix, but the principle is still the same), and then assign each user to one of those squares. So the API would instead give you the distance between the center of the square you are assigned to and the center of their square.
AFAIK, that last approach they used to solve the issue is still unbeaten, and it makes sense as to why, since it is logically pretty robust at its core (plus/minus minor optimizations and improvements, of course).
Wasn’t there another one that just sent out coordinates and left the distance finding to the client?
>another one that just sent out coordinates and left the distance finding to the client
That's exactly what Tinder used to do back then, they simply sent out the coordinates and left distance calculations to the client. Given that Tinder (being one of the most popular dating platforms that was also known to be one of the most "tech-forward" ones) did that, I have zero doubt that some other dating platforms could have been using similar methods for determining the distance between users around that time.
I discovered a "secure" and "private" dating app, that just sent the location of the users directly through the API, and then it was up to the clients to do the calculation: http://kaspergrubbe.com/teazr-a-secure-dating-app-with-secur...
Also they used to send your raw birth date over the wire (in order to display your age to other users, calculated on the frontend) until I told them to stop.
Of course this is exactly what people are going to do with that kind of feature. Sharing of location data is such an obvious thing to get exploited. It is part of the human base instinct is to take any new thing to the worst places it can go. There are certain aspects that the first question should be how can this get exploited for uses other than how we want to use it. If nobody in the room can come up with a way, then you need different people in the room.
That's not something you want to hear from the developer of a "secure" service...
https://techcrunch.com/2014/02/20/problem-in-tinder-dating-a...
I am, however, curious about how people on HN talk about Fitbit, so I subscribe to HNWatcher alerts. Unfortunately, I only got an alert about this comment a week later.
If I did officially speak for Fitbit, this reply would be more diplomatic.
Personally, I'm losing patience with this lie being casually repeated so many times.
If you would even bother to read the article you yourself linked to, you'd see that it was Strava that revealed this information, not Fitbit. Fitbit's role in the story was to display the "Are you sure?" message when soldiers explicitly chose to share their Fitbit data with Strava.
There is no excuse for saying Fitbit did the revealing. If you were serious about privacy and security, you'd be careful about accusing the right party.
As always, it feels like this "discovery", at least for the headline (which, let's be honest, it's what most people read anyway) is based on glancing over the fact that this feature is opt-in, and that 99,999% of Telegram users do not use it. There's nothing in the headline indicating whether this is a critical data leak or simply expected behavior.
Sure, it definitely falls under unexpected usage of the data, but at the end of the day, the data was shared willfully through user action.
> If you’ve never heard of this feature and you suddenly feel the urge to delete your Telegram account forever, let me stress something very important: “People Nearby” is opt-in. By default, no one can see how far away you are on Telegram. You’ll only ever end up in other people’s lists by pressing the “Make Myself Visible” button. If you choose to try it out, remember to disable it once you’re done.
So it's opt-in, even if you don't tell people what it does when you click that button?
The headline is totally accurate - "Modifying Telegram's “People Nearby” feature to pinpoint people's homes"
> 99,999% of Telegram users do not use it.
Given I can see many people around me this is not true, unless the population is around me is orders of magnitude bigger than it is.
In the context of a city, I guess it makes sense that this is fairly anonymous.
In my moderately more rural part of the world, where owning a home is much more common, a person's house is part of the public record, and very easy to look up.
Granted that doesn't work for people renting, but the number of people renting instead of owning drops pretty dramatically once you start looking at demographics older than 25-30 around here.
This way, your actual location as fuzzy as how randomly you pick cells and the size of cells. You are also introducing a skew that the other party cannot compensate for. It’s your secret and by not repeatedly recalculating it, you aren’t vulnerable to the other party calculating the mean cell.
So if each cell is say 1 mile across and you pick randomly from say a 3 by 3 grid around your cell, then your location can only be localized to within a 3x3 mile square.
The tradeoff is that near isn’t so near but the tradeoff can at least be tuned by cell randomness and nearness. If you want to be more private, pick randomly from a larger number of nearby cells. If you want to know more people, widen the circle that you define to be near. Most people probably want defaults.
One difficulty may be when there are cells that are less likely to be populated. It may make sense to chop up the world into varying size cells based on a combination of area and population density.
It seems like those are two incompatible / conflicting things.
I think on Android such questions are only about energy preservation, e.g. low-resolution data can be provided via WiFi information, while more precise can require GPS. And if there happens to be more precise information available at the same time (e.g. you use Google Maps), then the app will receive that.
I haven't seen such a dialog, though, so I'm uncertain if it reflects the regular Android location precision system.
Now, the app's behavior when denied that permission (i.e., whether you will be allowed to use Tinder at all if you deny location permissions) are up to the developer.
[0] https://developer.android.com/training/location/permissions
Does the author mean "for the sake of people's safety don't sell them kitchen knives"?
This feature is intended for organizing outdoor events. And it proved itself quite useful, for example, during Hong Kong protests.