After updating my toothbrush firmware, I got a prompt on my phone asking for it to track my location.
Why does my toothbrush need to know my location constantly?
This is because Bluetooth _could_ be used to determine a user's location by using beacons and constantly scanning or whatever.
But this has led to nothing but endless confusion for users (and constantly gets highlighted as suspicious in online forums), so they really need to come up with better wording. Like "This app is requesting Bluetooth permissions, which _could_ be used to determine your location".
I have no idea why google bundled those together, instead of treating them as separate things alltogether.
No, they need to come up with a better way of communication that doesn't involve leaking permission.
Generally speaking, if you want wireless communication, you'll need some way of uniquely identifying each participant in the wireless space. Data aggregators can then drive around on the streets and associate device IDs with physical addresses.
A bluetooth communications setup (or future alternative) will want to be able to know what device IDs are around it. (You want to connect to your wireless toothbrush - not your neighbors). A malicious developer can then use that access to the ID list, compare it against databases of known ID locations, and get a really good guesstimate of your location.
Luckily the toothbrush works perfectly without the App or any Bluetooth connection at all, wouldn't have even noticed it had Bluetooth if I hadn't looked at the packaging.
My treadmill was a bit different: While unpacking and building, I saw what was probably 8 or 9 notices claiming that the treadmill is "locked", has to be unlocked by registering it with iFit, and will not work otherwise. It was everywhere: On the packaging, as a piece of paper inside, in the manual, on the treadmill itself... New York Times had an article mentioning you just have to hold down the "iFit" button for 20 or 30 seconds, and that unlocked it permanently. Without having to pair with anything. Weird world.
https://android.stackexchange.com/questions/160479/why-do-i-...
IMO this is counterintuitive for users. It would be like telling people on windows “This app wants to wipe your C drive” every time an app asks for admin permissions - it could wipe your C drive, but that’s not what it’s asking for. IMO the permissions should be separate, but the approval modal should note that info about leaking location.
Well the flip side is that they don't warn the users enough, and they get roasted by the media for "not sufficiently warning the users" or "being complicit in user tracking" or whatever.
Ubuntu installed Debian's popcon as a default package from 2006-2018, although apparently it was not configured to send data upstream.
I mean sure I guess.
I'm pretty skeptical that this is really occuring though. I mean, to what end?
As someone who runs an online game we have text logs of user actions, yes. They sit there because it's useful debugging info. A server crash happens and we look at the logs of what the user was doing at the time. An exploit is reported and we look at the logs of what the user doing the exploit did so we can fix it. Etc etc.
I really don't know what nafarious thing people imagine is really occuring.
Unregulated anticheat software retaining user clipboard contents, sending/uploading arbitrary files, all window titles, all processes and computer and username, and any other IPs on LAN and ARP cache, sending in plaintext across country borders, ignoring GDPR/CCPA/etc.
If you are detected to be a reverse engineer based on running processes or otherwise, even if it has nothing to do with the game, expect significantly more surveillance too, up to and including literal streaming shellcode running from the server at the highest privilege level at any time, none of which you can control.
But are you actually suggesting that the games are keeping data from this activity and using it some bad way?
You kind of dodged the actual part where something evil actually happens.
On a naive surface level of this, it's a game, not your banking account. How much is really at stake here?
Imagine if games like Mass Effect phoned home about the choices you took. You can build up a pretty complete psychological profile of someone based on their gameplay.
If anything, you'll be dumped into big buckets like "buys lots of cosmetic items", "usually makes good choices first", "likes to try breaking aspects of games", etc