iPhone apps can tell many things about you through the accelerometer
mysk.blog
mysk.blog
- The heart rate sensing is done on a smart watch, not a phone, and needs data from the actual heart rate sensor every couple of days [1].
- The breathing rate is determined from a phone put on the breast or the abdomen [2]. Not really a threat vector in that form.
- The audio stuff is incredibly impressive [3], but it doesn't look like they can reconstruct text with meaningful reliability, it's more about identifying the person or at least the gender of the person on the other end of the line.
The location and activity detection scenarios seem the most credible to me, but the for targeted attacks the audio reconstruction might also work. The other two don't really seem credible to me yet, but good to be aware of them.
1: https://arxiv.org/pdf/1807.04667.pdf
Android definitely does, and I assume the same research around guessing text input would apply.
Some examples:
https://www.youtube.com/watch?v=a-ImMjOrbbI
https://www.youtube.com/watch?v=gCA-0cPS1eM
They also have a bunch of research using other sensors in the phone as an input.
There's a growing number of these "computers can now predict..." articles, like "one email from you can tell your mood" or "your choice of snap filter reveals your age." Basically, in practice anything can predict anything, usually slightly better than random, so there's an infinite number of articles to write that sound shocking. If I had a bit of training data, I can easily write a script to predict everyone here's salary based on their comments using bag-of-words, and I bet I can do better than random guessing.
No. Shake gestures are handled at the OS level and you only get began/changed/ended callbacks. Raw accelerometer data requires the CoreMotion framework, and it’s a lower level API. They are definitely using it for something else.
This is also confirmed by this:
>The prompt has an option to switch this feature off. However, switching it off doesn’t stop the app from reading the accelerometer.
You can 'track' if someone glanced at notifications, doing a spaced-repetition type delay between glances.
Or maybe you want notification when you're looking at your phone (certain angle and shakeyness). Or maybe when you're on the phone (different angle).
Like 3D and 360 photos.
It's good practice to only activate the accelerometer when in use because it uses up battery.
[1]: https://product.tdk.com/en/search/sensor/mortion-inertial/im...
The idea is that a bot farm with thousands of phones on racks won't have some signature that the accelerometer should see when the screen is tapped (for example, when typing a message or hitting a like button).
I happen to believe this theory.
[1] https://www.impactplus.com/blog/facebooks-using-2fa-phone-nu...
Overall I find the article interesting but this quote is borderline tinfoily. Given the amount of noise in the accelerometer data and signal s much closer to the sensor than the bus itself - such as body movements, it would be hardly precise. Moreover the cost of doing all that research and computation as well as data transfer would hardly pay off.
No. This is not at all the question. A possible privacy breach is a serious issue, regardless of whether there is a working POC. If this data is somehow compromised, a stalker could get your identity just by following you a few minutes on the street.
I don't think it would require significant bandwidth; the data is just integers which can be collected, compressed and uploaded asynchronously (as part of another heavy upload such as someone sending a picture). The analysis part could be similar to how Shazam works, but that can be done on the server side so on-device performance isn't a concern.
Orientation? Is the phone in your hand? Your pocket? Your purse? Front seat / back seat?
By way of comparison I worked on some automatic breaklights that trigger when an accelerometer detects you slowing down (bikes, skateboards, scooters). It turned out to be way more complicated that we expected. Hitting potholes, naturally slowing when you go uphill, taking a turn.
This is the equivalence principle of general relativity, no less.
Make no mistake that MEMs sensors are really very good.
I was trying to wire something together to track what vehicles were travelling down my forest road and left the room with the data streaming, and came back to be impressed.
As a layman I think you can just sum all axis for each person, overlay the resulting track with everyone else's and try to find a position where enough peaks correlate (constrained within a 5 minute timeframe from the on-device timestamp to account for clock drift while limiting the search space) and that should work well enough.
I'm sure the sociopaths working for Facebook will have a smarter way of doing this that's even more accurate.
I don't believe the data is precise enough to do much that could be nefarious.
Also trying to matching two phones (without location info) that have the same highly imprecise vibration is not worth the effort on the server side.
An example would be the Facebook app icon with notification count or the Mail app with unread emails count. This counter is updated based on background processing of Fb or email notifications.
There is also the "allow background activity" permission though, which I'm not sure the bounds of, but you can disable it
Background activity on iOS is severely restricted and mostly relegated to finishing a long or regular upload or download.
Unless you are a phone communication app — and a reason why you may see voice added to apps.
Their product - in production - was to map establishments such as stores and provide data about what the clients were looking at. Did you walk past the mens' shirts and turn your body? Noted. Did you stop at the condoms? Noted. This was all done with the accelerometer, if the user had a "compatible app" installed. A lot of apps carried their technology from what I understand.
I actually thought that this was a well-known use of our devices' accelerometer until I read the responses in this thread.
maybe it worked in tandem with reading the strength of wifi access points or tried to use GPS (this might not work well indoors)
I am confused how "surreptitiously" could be used in this context. Were you spying on him?
Or skip physical hardware altogether.
As for the click farms - I would not be surprised if the next step will be gimbal mounts that mimic an actual human's movement...
And given that who ever I am with might have Facebook on her phone, and it might be on my bed also...
That's pretty creepy.
After reading TFA it sure sounds like they do.
Or hell, use developer tools to simulate it.
It's all an arms race, but the click farms have the advantage.
I'd love to be able to flick a switch and just disable everything. I'm paranoid about my devices listening to me without my permission. The only issue is that for such a feature to be useful it probably couldn't disconnect everything, wifi and mobile data would probably need to remain software switches for example.
https://puri.sm/products/librem-5
https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
https://wiki.pine64.org/wiki/File:Pinephone_backside.png
Wish the hardware was better.
;)
So you shouldn't give your phone to anyone you do not trust?
(Also, AFAIK, you can simply reinstall all software yourself.)
Yes, a significantly advanced adversary can always get your communications if they want, but every time someone does choose the more secure option it raises the bar for them.
"FBI is comming for me, but I have my HDD encrypted..." Well, how well did HDD encryption serve that guy who the FBI just pulled the turned on/unlocked notebook from before he noticed what's going on and was able to react? He might just as well not bothered, when he knew "FBI" is in his threat model, and didn't account for this obvious attack in any real way.
If you had instead written something along the lines of "for those who have mighty adversaries and who actually need this for their own security, one should be aware that things like hardware switches only go so far" and then an explanation.
Instead you wrote it in a way that I and probably a lot of others took to mean: even hardware switches doesn't matter.
I have a Pinephone. Those switches are very tiny and probably not designed for everyday switching, even if you connect them to larger ones.
Same here, the hardware is really underwhelming.
Well I have good news for you
https://www.pine64.org/2021/10/15/october-update-introducing...
Sadly, the camera is still a potato, relatively speaking, compared to ie Pixel 6 Pro or S21 Ultra.
And the camera is pretty much the main criteria of choosing a phone for me, because I like the outdoors a lot, and I take many photos (and I can't get myself to carry around a 'real' camera - or getting into that whole topic.)
I normally go for budget smart phones in the range of $100 - $200. I'd pay more for something with decent build quality and a privacy focus, but $1,199 is a little pricey for me.
This is false: The phone has no suspend mode yet, and its battery life is 10+ hours. After it's implemented, it will be on pair with an Android: https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque....
> you can't even easily update the modem firmware
This is also false: You can upgrade the firmware. https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...
> The PinePhone, while not secure either, provides basically the exact same thing at a fraction of the cost
This is not the exact thing at all. Apart from huge differences in the performance [0], Pine64 does not develop any software and most Pinephone users are using Phosh developed by Purism. Linux phones can't be sustainable without professional developers, just with volunteers.
Also, both phones are more secure than Android, depending on what you understand by "security": https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...
[0] https://source.puri.sm/Librem5/community-wiki/-/wikis/Freque...
https://pine64.com/product/pinephone-beta-edition-linux-smar...
It really isn't:
The i.MX 8M Quad is better than the Allwinner A64: 30% faster CPU clock speed, 140% faster RAM standard, 140% 21 better OpenGL performance, USB 3.0 and support for higher resolution cameras.
https://forums.puri.sm/t/comparing-specs-of-upcoming-linux-p...
"Your devices" aren't listening to you. What is listening to you is hostile third party software that you've been goaded into running on your devices (whether by javascript, apps, chipset, or as part of the OS), that has been insufficiently sandboxed. Hardware switches are just mitigations for an insecure OS that violates its fiduciary duty to the user, and a less good solution than having those capabilities built right into the OS. If sensor switches became popular, then hostile apps could just refuse to work when those sensors were off - just as hostile apps will refuse to work if you do not grant them requested permissions. Whereas a real user-representing OS would allow one to designate that an app should receive synthetic data for any sensor - eg set a fixed "GPS location" and then add some plausible sounding noise so that an app couldn't tell it apart from a stationary phone.
But what is really needed for sustainable user privacy is user-representing software that talks to adversarial counterparties solely through well-defined protocols. This isn't necessarily workable for new innovations, but for all well established technologies (messaging, pictures, video chat, social networking, message boards, etc) there should be Free clients that interoperate with the proprietary systems. Much has been said about "breaking up" Big Tech to constrain their power, but mandating such interoperability would be a much better approach to antitrust.
all the perks of dorm room living! I guess someone really wanted that feature when they were first building the company.
Until they'll make toilets open space.
At the cost of privacy and peace of mind? No.
It's been a pretty good measure of my progress in recovery post-surgery. She had no idea this even existed, and then had a second patient point it out to her just a week or two later. I imagine Android has similar features (or 3rd party apps can be installed to do so).
It's wild what new data can be used for fingerprinting. [1] describes using magnetic signals to fingerprint a device. [2] describes identifying inputted text from CPU interrupt data.
I wouldn't be surprised if health data can also be used to fingerprint users, even across devices. I wonder what lower level runtime information (e.g. CPU interrupt data) is available to apps.
[1] https://dl.acm.org/doi/abs/10.1145/3319535.3339810 [2] https://www.repository.cam.ac.uk/handle/1810/254306
https://grapheneos.org/features
"Sensors permission toggle: disallow access to all other sensors not covered by existing Android permissions (Camera, Microphone, Body Sensors, Activity Recognition) including an accelerometer, gyroscope, compass, barometer, thermometer and any other sensors present on a given device. To avoid breaking compatibility with Android apps, the added permission is enabled by default."
In fact they’ve already done this on the web: the DeviceMotion API is behind a permission prompt. I’m surprised the same isn’t the case for apps.
Google was basically responsible for locking down the DeviceMotion API.
Edit: Both the desktop and mobile browsers.
Motion Sensor: Allow (default)In fact, Facebook may actually be doing this now, after the recent actions taken to nerf advertisers (yay).
Apple seems to track the accelerometer data in the background. (Why health app can tell you about steps and stairs...)
But beyond that data leakage is an interesting problem.
10 years ago I started working at a company that did home power monitoring. We used my bosses house to test. When he went on vacation you could clearly see it in the power use. The daily rhythms of a home (laundry on wed, out late on certain nights ), when they cooked. It all had become very apparent under the guise of just monitoring how much power you were using. We switched to selling to businesses shortly after which was much better. Though those that wanted to generate as much as they used and monitored it were interesting and provided good feedback on the product.
Our Big Boss's said his wife got a little aggravated with him, when he noted she had come in early (you can keep your toys just don't talk to me about it), and he noted his house cleaners operated by turning on all the lights in his house, and turning them off only when finished cleaning a room...
Its a weird world, and the data you put out there might say more than you think.
Its not just overall electricity use over time, but by doing high frequency spectral analysis, they can identify the type of load, eg. your washing machine is running, or your oven is on.
My favorite trick is turning on the spectrum histogram history graph and placing the phone on a computer with a spinning HDD - you can trivially determine the RPM of the HDD from the spike in the graph just by eye.
I'm using a OnePlus 6t and mine goes to 200hz.
[1]: https://www.ifixit.com/Guide/MacBook+Pro+14-Inch+2021+Chip+I...
Usually GPS devices assume you just maintain speed, which for most tunnels works out.
Maybe they could just reduce the sensitivity slightly to prevent things like speech recognition working (though I am skeptical of that working in the real world)
What kinds of motions and reactions would that be, beyond rotations (which are a much higher-level API than raw accelerometer data)?
https://developer.mozilla.org/en-US/docs/Web/API/DeviceMotio...
Originally it wasn’t behind a permission prompt so you could do the little design flourishes the OP described. But now you have to request access. Orientation change events (i.e. portrait to landscape) remains accessible without permissions, though.
And what flourishes are those?
https://www.idownloadblog.com/2013/06/28/ios-7-parallax-effe...
I’m not trying to make out that it’s a crucial feature or anything but it’s a useful case study in permission gating things: it’s small enough that you’d never trigger a permission prompt to ask to do it, so you just don’t instead, and lose a class of nice subtle design flourish.
It has a few limitations/features. I don’t think it necessarily always runs at the screen refresh rate. It will also “self level” after a while. So if the user rotates their device and this causes a UI effect, if they hold their phone still the effect will reset after a few seconds.
https://developer.apple.com/documentation/uikit/uimotioneffe...
IDGAF about your design. I want my privacy.
I just think this so massively overblown - especially for a web page that has soooooo many other ways to track you.
https://www.wired.com/2011/10/iphone-keylogger-spying/
"The accelerometers in many smartphones could be used to decipher what you type into your PC keyboard. "
0. https://www.analog.com/en/technical-articles/mems-gyroscope-...
How do I stop this?
Windows: https://support.microsoft.com/en-us/windows/turn-on-app-perm...
macOS: https://support.apple.com/guide/mac-help/control-access-to-t...
iPhone: https://www.knowyourmobile.com/user-guides/how-to-stop-your-...
Android: https://www.lifewire.com/turn-off-microphone-on-android-5184...
TV: tape over the microphones and disable wifi (as some will connect to any open wifi nearby without informing you)
Assistants: not possible, simply don't use Alexa, Hey Google, Cortana, etc.
Browsers: Go into "Privacy" settings of your browers, generally you can select "always deny" with exceptions where you need them.
Other: security cameras (e.g. Nest), doorbells, etc. there is little you can do as you have opted-in to being recorded.
---
Microphone use in advertising has been openly marketed by adtech companies for over 10 years. For example, beginning in 2012 Shazam listens for commercials around you and then faciliates concurrently displaying the same advert on your personal device to make sure you saw it. Disabling "always listen" in Shazam might mitigate this. https://www.marketingweek.com/shazam-that-ad/
Listening services can make elite money, so they're common now in places you don't suspect. One big earner is linking a commercial heard (TV, Spotify, movie theater, etc.) to a purchase made, so listeners keep a record that you heard something. For example, they can confirm a "convertion" (payout) if your phone's bluetooth/wifi/etc IDs show's up at Gap store after seeing a Gap ad on TV -- even better if it's linked to your Mastercard/VISA data showing a purchase. That data could be the difference between an adtech company (e.g. Google, AT&T, Adobe, Meta, Amazon) getting paid $0.001 vs $10 for placing an ad in front of you.
Edit: legibility, typo
I am disabled and don't move around a ton. When I do walk, I often have a limp. But I don't have MS.
Facebook is constantly serving me ads about MS.
https://developer.android.com/guide/topics/sensors/sensors_o...
If I remember correctly, it might be necessary to declare the capability in a manifest, but there's certainly no prompt, nor a way to opt-out of an app reading motion data in the settings.
https://developer.mozilla.org/en-US/docs/Web/API/Gyroscope
To use this sensor, the user must grant permission to the 'gyroscope' device sensor through the Permissions API.